I don’t answer my phone anymore unless I recognize the number.
I have a separate email address for shopping and another one for websites I don’t entirely trust. Like many people, I’ve received enough breach notifications over the years that monitoring my credit has become less of an occasional precaution and more of a routine.
What’s interesting isn’t that I do those things. It’s that I don’t remember deciding to.
Somewhere along the way, those small choices stopped feeling like choices at all. I suspect many of you had the same reaction while reading this. You probably do some version of those things too. We rarely wake up one morning and permanently change our behavior. More often, we make one small adjustment because it seems practical. Then another. Eventually those adjustments become habits, and after enough time we forget there was ever a decision to make.
I’ve been wondering if that’s simply the life cycle of innovation.
At first we talk endlessly about the technology itself. We debate whether it’s safe, whether it’s useful, and whether it will change everything. Then, almost without noticing, the conversation shifts. We stop talking about the technology and start talking about what it helps us accomplish.
That feels like where we are heading with artificial intelligence.
A few years ago, organizations were asking whether they should use AI. Today, the conversation is usually about which tools to adopt, where to integrate them, and how much time they might save. Recent nonprofit benchmark studies found that 92% of nonprofits report using AI in some capacity, while nearly half have no formal AI governance policy.
That doesn’t surprise me. If anything, I think it’s exactly what history would predict. We’ve always been faster at adopting useful tools than deciding how they should be used.
What Changes After the Novelty Wears Off?
Can we blame the internet for spam? Or was spam simply what happened when enough people found a way to exploit a useful technology? When did we become so suspicious of links in our inbox? When did our phones stop being primarily for phone calls? And when did a video meeting become so ordinary that we no longer think twice about it?
None of those developments were part of some grand plan. Each was our response to the unintended consequences of the innovation before it. AI is following the same pattern.
AI is not uniquely dangerous. Like every tool before it, it has the potential to improve lives or cause harm. And, as we’ve always done, we’ll respond. People are wonderfully adaptable. We solve problems, develop new habits, and eventually stop noticing the habits we’ve built.
But occasionally it’s worth asking whether we’ve become comfortable with something before we’ve become intentional about it.
I don’t think the challenge with AI is the technology itself. I think it’s that we’re gradually trusting it with more responsibility without always noticing where that line has moved. One day it’s summarizing meeting notes. Then it’s drafting client communications. Then it’s helping analyze financial reports or answer employee questions. None of those decisions feels particularly significant on its own. Over time, though, they begin changing how an organization works, often without anyone intentionally deciding that they should.
So What Is Governance Really For?
When people hear the word governance, they often imagine bureaucracy. More approvals. More policies. More meetings.
I’ve never thought of it that way. Governance is simply the process of deciding, ahead of time, how you’ll make important decisions before you’re forced to make them under pressure.
Every organization already has governance around finances, hiring, legal compliance, cybersecurity, and privacy. Those frameworks don’t exist because leaders distrust their employees. They exist because thoughtful organizations know that consistency matters, especially when the stakes are high.
AI deserves that same level of intentionality because it’s quickly becoming something we rely on.
Who Owns the Decision?
One assumption seems to follow every major technological shift: if the work becomes easier, responsibility somehow becomes smaller. It doesn’t.
- If AI drafts a donor email that contains inaccurate information, the organization is still accountable.
- If confidential information is entered into a public AI platform, the organization owns the consequences.
- If an AI tool recommends something that creates bias or exposes sensitive data, leadership doesn’t get to point at the software.
Technology changes who performs the task. It never changes who owns the decision or who is accountable for the consequences.
I think that’s one of the reasons social media companies have faced so much scrutiny from Congress. We began experiencing the unintended consequences of bad actors, trolls, misinformation, and automated accounts at a scale no one had fully anticipated. Society eventually reached a point where simply accepting those consequences no longer felt reasonable.
When we can’t address the problem through governance, regulation, or changes by the companies themselves, we adapt. We change our own behavior to reduce the risk. We spend less time on a platform. We stop posting. We turn off notifications. We become more skeptical of what we read.
That doesn’t mean the technology no longer has value. It means we’re constantly deciding what level of risk we’re willing to accept. And when a company doesn’t establish clear boundaries or take responsibility for the consequences, people eventually create boundaries of their own.
The same will be true for AI.
Every organization has to decide where those boundaries belong. What should AI be trusted to do? What should always require human judgment? Who is accountable when something goes wrong?
That’s why AI governance isn’t really about software. It’s about leadership.
What Does Good AI Governance Look Like?
Good governance doesn’t begin with a fifty-page policy manual. It begins with clarity by answering questions before they become problems.
Questions like:
- Which AI tools has our organization approved?
- What information should never be entered into an AI platform?
- When should a person always review AI-generated work?
- Who evaluates new AI tools before they’re adopted?
- How do we verify AI-generated content before it reaches partners, clients, or the public?
- How do we respond when AI gets something wrong?
Those questions don’t slow innovation. They make innovation sustainable.
If AI governance sounds intimidating, it doesn’t have to be. Most organizations don’t need another a hundred-page policy manual. They simply need to become more intentional about the decisions they’re already making. That usually starts with a few practical conversations.
Becoming More Intentional
If you’ve made it this far, you might be wondering what this looks like in practice. Here are five places to start so that it feels less abstract for you and your team.
Inventory your AI.
You can’t govern what you don’t know exists. Ask your staff what AI tools they’re already using. The answers will almost certainly be more varied than you expect.
Define your data boundaries.
Be clear about what information is appropriate to share with AI tools and what should never leave your organization. User information, financial records, legal documents, and sensitive employee or client data all deserve careful consideration.
Keep humans in the loop.
AI can make work faster. It shouldn’t replace human judgment where trust, ethics, or important decisions are involved. Decide where people should always have the final say.
Write a practical policy.
Don’t write a policy that sits unread in a shared drive. Write one that helps employees make good decisions during an ordinary Tuesday afternoon.
Review it regularly.
Technology will continue to change. So will your organization. Governance should be treated as an ongoing conversation, not a one-time project.
The Conversation We Should Be Having
I don’t think the question is whether organizations should use AI. For most organizations, that question has already been answered. The better questions is: “How will AI change human behavior?” History proves it eventually will as it starts to become ubiquitous. That’s not a technical question, and yet, it impacts how we implement tools and processes today that will serve us for decades to come.
Technology has always changed human behavior. Email did. Smartphones did. Social media did. Remote work did. AI will too. What worries me isn’t the pace of innovation, but rather our pace of understanding the potential impacts.
One day, AI won’t be the shiny new emerging technology. By then, it will simply be another tool we use every day. Some of us may already be at that place. My hope is that we’ve been just as thoughtful about what we’ve trusted it to do as we’ve been excited about what it makes possible.