Your AI controls exist. Do they run?
A control that nothing runs is a document, and a check that runs on a narrow scope reports green on everything it never looked at. A test for your own AI controls.
Published · Every number is ours, measured on our own operation.
The AI policy is written and signed. It lists the approved assistants, says which data must never be pasted into anything else, and names a review that checks people are following it. Leadership announced it, and the audit file has a section for it. When someone asks whether AI use is under control, the answer points to that file.
The file shows that the controls exist. Whether any of them run is a separate question, and the file has no way to answer it.
A control nobody runs is a document
Take the rule that client data never goes into an unapproved AI app. Something has to enforce it, such as a filter on traffic leaving the network or a browser setting pushed to managed laptops. If nothing does, the rule is a sentence in a PDF. It still appears on the controls list and still counts toward the compliance score, because the list records that the control was written. It has no column for the date anything last ran it.
The quarterly review of who can use which AI service has the same weakness. If it lives as a calendar reminder for one person, it runs when that person remembers and stops when they change roles. Nothing announces that it stopped.
Green on everything it never looked at
The second gap is harder to see, because the control does run. Picture a monitoring rule that reads the admin console of the approved assistant every night and reports no policy violations. The report is accurate. It also says nothing about personal accounts or unapproved apps, because neither shows up in the console it reads, and those are where unsanctioned use goes.
A report like that can do more harm than a missing one. Without it, the gap stays open. A green report closes the question, and nobody goes back to reopen a question that already has an answer on file.
If you report AI risk to leadership, that green line is what reaches them, with nothing attached to say how much of the business it covers.
Where we found both
The software that runs our own operation carries its own automated tests. When we counted them, there were 458, and a search for whatever ran them turned up nothing on a schedule. They ran when someone remembered to run them. A governance change turned two of them red, and for a full day every status check that did run kept reporting green, because none of those checks looked at the tests. A routine review caught it by hand.
The fix was a scheduled check that runs every test it can find. Three days later someone asked what, exactly, it was finding, and the answer was that it began its search in one folder and stopped there. Outside that folder sat the tests for the spend-reporting tool, and the tests for the connector designed to run inside a customer's own systems, the one piece a customer would actually touch. Widening the search took the count from 485 tests to 557, all passing, none of them new. The check had been reporting green on a scope nobody had questioned.
Both gaps closed the same way. Something on a schedule now runs the tests, and it names any tool that has no tests at all. There are probably more blind spots like these in checks that currently report green, and the habit that finds them is asking each check what it cannot see.
Run this against your own controls
Take your list of AI controls, including the lines in the policy that read like rules. For each one, write down:
- What runs it. A named system, or a named person's recurring task. A policy document does not run anything.
- How often it ran. Take the dates from the control's own logs or records. The schedule someone intended does not count.
- What sits outside it. The accounts, devices, apps and data it never sees. Ask whoever owns the control to name them, and write "unknown" if nobody can.
A control with nothing in the first column is a document. A control with an empty third column has not been asked the question yet, and its green result covers an area nobody has measured.
The finished list is the answer to give leadership when they ask whether AI use is under control: which controls run, and where each one stops looking. Read how we approach governing the AI your people already use.