AI Governance Review: Why Most Organisations Have No Real Visibility

Table of Contents

If you asked the leadership team of a typical mid-sized organisation to list every AI tool currently in use across the business, most could not do it accurately. Some would have a partial picture. Most would be missing significant portions of their actual AI footprint. A few would be working almost entirely from assumption.

That is not a criticism. It is a structural reality created by how AI adoption has happened. Unlike previous technology waves, AI has not arrived primarily through procurement decisions, IT deployments, or budget approvals. It has spread through individual choices made at every level of the organisation – staff finding useful tools, product updates silently enabling AI features, suppliers integrating AI into the platforms organisations already use. Governance was not in the room for most of those decisions.

This is exactly the gap an AI governance review is designed to close. The result is that most organisations are trying to manage risk they cannot fully see, and the gap between what leadership believes is in use and what is actually in use is often larger than anyone expects. It is also the same gap that drives most shadow AI risk – the two are different ways of describing the same underlying problem.

Why traditional discovery methods fail an AI governance review

IT asset inventories were designed for a world where software required installation, licences, and deployment. They are largely useless for discovering browser-based AI tools, embedded SaaS features, or AI capabilities that have been quietly added to existing platforms through product updates.

Network monitoring can surface some AI-related traffic, but the volume, variety, and encryption of modern SaaS platforms makes it impractical as a primary discovery mechanism for most organisations. You might detect traffic to known AI endpoints if you know what to look for. You will not reliably detect AI features embedded within SaaS platforms you are already using, or tools accessed from personal devices.

Asking managers what tools their teams use is the most common approach and the least reliable. Self-reporting consistently surfaces the approved and obvious tools. It rarely surfaces the browser extensions installed without IT involvement, the personal accounts being used for work tasks, the AI features inside existing platforms that teams have started using because they appeared in a menu one day, or the tools that staff quietly kept using after someone in leadership expressed concern about them.

The result is that most AI discovery exercises based on self-reporting produce a list that the organisation finds reassuring, but which does not reflect operational reality.

The three layers an AI governance review needs to cover

Thinking about AI visibility in terms of three distinct layers helps clarify why the problem is harder than it looks.

The first layer is direct tooling – tools that staff have actively sought out and started using. ChatGPT, Claude, Gemini, Perplexity, Notion AI, Grammarly, and a long tail of more specialised tools. This is the layer organisations tend to have the most partial visibility of, because at least some of these tools are visible in browser history or have been mentioned in internal conversations.

The second layer is embedded AI – capabilities built into existing platforms that became active through product updates rather than explicit adoption decisions. Microsoft 365 Copilot features that appeared through licensing changes. AI-powered features in Salesforce, HubSpot, Zendesk, Slack, Google Workspace, and dozens of other platforms. AI summarisation in document management tools. AI-powered search in knowledge bases. Many organisations are actively using AI features they never consciously chose to adopt, in platforms they have already integrated deeply into their operations.

The third layer is supplier-side AI – where organisational data is being processed through AI systems controlled entirely by third parties, without any direct action on the organisation’s part. A supplier updates their platform to use AI for processing the data you send them. A cloud service adds AI analysis of usage patterns. A professional services firm starts using AI tools internally to service your account. These are the hardest to discover, the least visible, and often the most difficult to govern because the organisation has the least direct control.

What incomplete visibility costs you

Operating without genuine visibility creates several distinct problems, and they compound over time.

It makes meaningful risk assessment impossible. You cannot assess the risk of tools you do not know about. You cannot review supplier terms for suppliers you have not identified. You cannot determine whether your data handling practices comply with UK GDPR, contractual obligations, or sector-specific regulations if you do not know where your data is actually going. The NCSC’s guidance on AI and cyber security makes the same point from a board perspective – you cannot govern what you cannot see.

It makes policy largely ineffective. An AI acceptable use policy written without an honest understanding of what tools are in use will inevitably have gaps. It will cover the tools leadership was aware of and miss the ones they were not. Staff following the policy in good faith may still be creating exposure that the policy was never written to address.

It creates accountability problems when something goes wrong. If an incident occurs involving AI-related data exposure or misuse, the first question any external party will ask is what you knew and when. An organisation that cannot demonstrate it understood its own AI footprint is in a significantly worse position than one that can show it had a clear picture and proportionate controls in place.

What a genuine AI governance review requires

Getting a reliable picture of your organisation’s AI footprint requires a structured approach that combines several sources of evidence rather than relying on any single method.

Staff interviews, conducted properly, surface the tools in active use far more effectively than surveys or self-reporting forms. The key is asking about workflows and tasks rather than tools – people often do not think to mention a tool they use every day because it has become invisible to them.

Platform and licence review identifies AI features that are enabled or available within existing tools. This is often where the embedded AI layer becomes visible for the first time.

Supplier and contract review – at least for significant suppliers – identifies where data processing agreements may need to be revisited in light of AI features that were not part of the original commercial relationship.

The output should be a clear, current inventory that supports governance decisions: what is in use, what data it touches, what the supplier relationships look like, where the gaps are, and what the priority actions are. Once you have that picture, it is worth understanding how AI governance maturity is assessed so you know what to build next. That picture does not stay current on its own, which is why ongoing visibility – the focus of our Continuous AI Assurance service – is a governance requirement rather than a one-off exercise.

Black Chili’s AI Exposure Review provides a structured, independent AI governance review of your organisation’s actual AI usage – across all three layers of exposure.

If you are not sure what AI tools are in use inside your organisation, an AI Exposure Review gives you a clear, independent picture - what is being used, what data it touches, and where the real risks are.

Related Posts