
In most companies, the decision to start using an AI tool is made by the person who discovers it, not by the person who should be approving it. Someone comes across an application in a demo, tries it, sees its potential and, within a few days, is using it with real company data. When there is no clear and straightforward way to request approval, people simply start using the tool. Putting a proper process in place is what separates a company that knows which AI tools it is using from one that only discovers what has been in use when something goes wrong.
Why the absence of a process creates more risk than AI itself
When there is no approval process, every tool that enters the organisation does so without anyone having checked what data it processes, where those data are stored, what the provider’s contract says or what safeguards it offers. The result is a silent accumulation of risks that the organisation may not even have identified, simply because it does not know what tools are being used.
The problem also feeds on itself. If the only official way to introduce a tool is slow, bureaucratic or non-existent, teams will bypass it out of sheer necessity. Unauthorised use then becomes the norm. The most effective way to reduce this kind of shadow use is not to impose stricter bans, but to offer an alternative that is so straightforward and agile that bypassing it is no longer worth it.
What does a process that people actually use look like?
An approval process works when it is fast, clear and proportionate to the level of risk.
Fast means that requesting a tool review takes no more than a short form and that the response arrives within days, not weeks. A process that takes a month simply encourages people to bypass it.
Clear means that everyone knows who to contact and what information they need to provide.
And proportionate to the risk means that you do not examine a tool that does not process sensitive data with the same level of scrutiny as one that will handle customer information. The first may be approved almost immediately; the second warrants closer review. A process that treats every tool in exactly the same way will only end up being slow for low-risk cases and superficial where scrutiny actually matters.
What should you look at during the assessment?
When assessing an AI tool, there are several questions that should always be answered.
- What data will it process, and how sensitive are they? This becomes much easier to determine if the organisation already has a data classification system in place.
- Where will those data be processed and stored, and will they leave the European Union?
- What does the provider’s contract say about the use of the information, particularly whether it may be used to train its models, and does the provider offer a data processing agreement that complies with the GDPR?
- Who within the organisation will be responsible for the tool once it has been approved? This is not a technical interrogation. It is the minimum information needed to understand what the organisation is committing to when it says yes.
Who decides, and how is it documented?
A process requires someone to have the authority to say yes or no, and for that decision to be recorded. You do not necessarily need a dedicated committee. In many organisations, a designated person — often in IT or compliance — can centralise requests and make decisions, escalating only the cases that carry greater risk.
What matters is recording which tool has been adopted, for what purpose, under what conditions and who approved it.
This documentation is not bureaucracy. It is what allows an organisation to demonstrate due diligence if, one day, a client, an auditor or a data protection authority asks why a particular tool was being used.
It also means maintaining an active, searchable catalogue of approved applications, rather than relying on knowledge that exists only in someone’s head.
Frequently asked questions
How can I prevent my team from using AI tools without authorisation?
Offer an approval process that is so agile that bypassing it is not worth the effort: a short form and a response within a few days. Unauthorised use tends to grow when the official route is slow or does not exist. The solution is therefore not simply to prohibit more forcefully, but to make authorised use easier.
What should I assess before approving an AI tool?
What data it will process and how sensitive they are; where those data will be stored and whether they will leave the EU; what the provider’s contract says about the use of those data; whether it offers a data processing agreement that complies with the GDPR; and who will be responsible for the tool within the organisation.
Do I need a committee to approve AI tools?
Not necessarily. In many organisations, a designated person — typically within IT or compliance — can centralise requests and escalate only the highest-risk cases. What matters is that someone has the authority to make the decision and that each decision is properly documented.