The AI landscape your organization is navigating today is not the same one it was navigating six months ago. 

New models are entering the market. AI agents are moving from generating content to taking action. Regulations are evolving across states and countries. And employees, contractors, agencies and partners have access to an expanding ecosystem of AI tools, whether your organization has approved them or not. 

Yet many AI policies have barely changed. 

Some organizations still do not have one. Others created a policy when generative AI first entered the workplace, approved a handful of tools, established basic data protections and moved on. 

But AI has not moved on. 

AI governance cannot be a document organizations write once and file away. It has to be a living practice. 

The tools you approve are only part of the picture 

A few years ago, AI policies could focus largely on which LLMs employees could use and what information they could share with them. 

Today, the choices are more complicated. 

Employees can access closed models, where the underlying model weights remain proprietary, as well as open-weight models, where those weights can be downloaded, modified or run in other environments. 

They can use models developed in the United States or elsewhere, operating under different terms, safeguards, data practices and regulatory environments. And they do not necessarily need their employer to give them access. 

You cannot govern AI based only on the tools your organization has purchased. You also have to account for the tools people can access. 

That extends beyond employees. 

An agency may create content for your organization using a model you would not permit internally. A consultant could put sensitive information into an unapproved tool. A vendor could deploy an AI agent that interacts directly with your customers. 

Their AI choices can quickly become your data, reputation and trust issue. 

Your AI standards cannot stop at your organizational boundaries. 

The rules are moving, too 

The technology is changing quickly. Regulation is trying to catch up. 

In the United States, 29 states now regulate AI-generated deepfakes in elections, with different rules and disclosure requirements. Those laws are already being tested as AI-generated campaign ads enter real elections. 

Organizations outside politics should pay attention too. 

The lesson is not about campaign advertising. It is about what happens when technology moves faster than consistent standards can emerge. The same AI-generated content can face different expectations depending on where it appears, who created it and who sees it. 

The EU is moving further on disclosure. Transparency provisions of the EU AI Act took effect August 2, including requirements related to marking certain AI-generated content and disclosing deepfakes and some AI-generated public-interest content. For organizations operating in, serving or otherwise falling within the scope of the EU, those requirements matter. 

Technology companies are adapting, too. Anthropic recently announced machine-readable marking for Claude models launched in the EU on or after August 2, including imperceptible watermarks in generated text and provenance metadata for supported files. 

That raises a bigger question: 

What happens when the technology itself begins disclosing AI use before your organization has decided what its own disclosure standards should be? 

Disclosure is not about labeling every use of AI. It is about deciding when AI involvement is meaningful to the person receiving, relying on or being affected by the outcome. 

Policy provides the standard. Disclosure makes that standard visible. 

And when done intentionally, disclosure becomes more than a compliance mechanism. It becomes a trust mechanism. 

AI is no longer just generating. It is acting. 

There is another reason policies written even a year ago may no longer be enough. 

AI agents can do more than answer a question or draft a document. They can navigate systems, access information, make choices and take action. 

We are already seeing what that can look like. 

An experimental OpenAI agent evaluating cybersecurity capabilities autonomously accessed external services, including Hugging Face systems, after discovering exposed credentials. 

More recently, an AI agent in Australia was given a seemingly simple goal: secure a spot in a gym class. It found a vulnerability in the booking system and manipulated the waitlist, ultimately removing another member. 

Today, it is a gym class and a mild frustration. Tomorrow, the action could be much more consequential. 

Research is pointing in the same direction. Anthropic’s recent agentic alignment experiments found that frontier models placed in simulated scenarios could take unintended actions in pursuit of assigned goals, including changing code, assisting fraud and encouraging the disclosure of confidential information. 

The point is not that organizations should stop using agents. It is that the responsibilities we are giving AI are changing. Our policies need to change with them. 

A policy that tells employees what data they can put into an LLM may say nothing about what authority they can give an AI agent. Organizations now need to consider what systems agents can access, what actions they can take, what requires human approval and where human ownership must remain. 

Those are governance questions now. 

AI governance needs an owner, but not another silo 

There is another challenge: many organizations still do not have a clearly defined owner for AI governance. 

They need one. But ownership cannot mean handing AI governance to Legal, IT, HR or another function and assuming the problem is solved. 

Each function sees a different part of the picture. Legal sees regulatory exposure, while IT and security see systems, access and data. HR sees workforce implications. Communications sees reputation and stakeholder trust. Business leaders see workflows and outcomes. And employees see what is actually happening in the work. 

No one function sees the whole picture. 

Effective governance requires those perspectives to come together. Someone needs to own the process, but that ownership should break down silos, not create another one. 

Organizations need a cross-functional feedback loop that surfaces new tools, changing use cases, employee questions, emerging risks, regulatory developments and what teams are learning in practice. A policy cannot stay current if the people responsible for it do not know what is changing. 

A living policy requires a living practice 

At HDAI, we recommend reviewing AI policies at least quarterly, with additional reviews when significant changes in technology, regulation, organizational use or risk require them. 

But quarterly review is only part of the answer. The policy also has to live in the work between those reviews. 

That is one reason we developed the 4 Ds of Shared AI Practice™

  • Data: What can, and cannot, be shared with or accessed by AI. 
  • Documents: How AI-supported information and work should be structured, stored and shared. 
  • Decisions: Where human ownership and accountability must remain. 
  • Dialogue: How teams communicate, learn and adapt together. 

The goal is not to create more rules. It is to give people enough shared structure to make responsible choices when the answer is not already written in a policy. 

That is what living governance looks like. 

Policy provides the backbone.  

Shared practice brings it into the work.  

Disclosure makes important standards visible.  

Regular review keeps all three connected to reality. 

Organizations cannot anticipate every new model, regulation or capability. 

They can create the structure that allows them to respond when those things change. 

And increasingly, that is the responsibility of AI leadership: not trying to predict every development, but creating enough clarity, communication and shared accountability that people do not have to navigate each new development on their own. 


Remember, AI won’t take your job. Someone who knows how to use AI will. Upskilling your team today, ensures success tomorrow. Custom in-person and virtual trainings are available. If you’re looking for something more top-level to jump start your team’s interest in AI, we offer one-hour Lunch-and-LearnsIf you’re planning your next company offsite, our half-day workshops are as fun as they are informational. And, of course, we offer AI consulting and GEO strategies. Whatever your needs, we are your partner in AI success.

Read more: AI Governance Cannot Stand Still When AI Doesn’t 

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading