← All Articles
Strategic

Your AI Policy Is Not a Control

A policy says what people should do. Governance shows what they actually did: what went in, what came out, and who reviewed it.

KE
Brian Stack
September 22, 2026
7 min read

Most companies have answered the AI question with a document: an acceptable use policy, a list of approved tools, a paragraph in the employee handbook. The document says what people should do. It does not see what they actually do.

That gap is where AI risk lives.

Risk runs in both directions

AI risk runs two ways: what goes in, and what comes out.

What goes in. Every prompt is a data transfer. When an engineer pastes a drawing, a contract clause or a customer email into a chatbot, that information has left the building. In 2023, Samsung restricted generative AI tools after engineers pasted internal source code into ChatGPT. Nobody was malicious. They were trying to work faster.

For defense contractors the stakes are specific. If the information is Covered Defense Information, DFARS 252.204-7012 already governs where it can go. A cloud service that stores, processes or transmits it must meet the FedRAMP Moderate baseline or equivalent. A consumer AI tool doesn't become compliant because someone needed an answer by Friday. The obligation didn't change when AI arrived. What changed is how many ways there are to break it.

What comes out. The risk people talk about less is what AI produces and the organization then releases under its own name. In 2023, attorneys in Mata v. Avianca were sanctioned for filing a brief that cited cases ChatGPT had invented. In 2025, Deloitte refunded part of its fee to the Australian government after a report it delivered was found to contain fabricated references produced with AI assistance. Neither was a security breach. Both damaged reputations, and the name on the document paid the price.

Why policy alone fails

A policy states intent. Governance is being able to show what happened.

Four questions most leadership teams can't answer today:

  1. Which AI tools are our people actually using?
  2. What company data left our boundary that shouldn't have?
  3. Which work products that left the company this quarter were drafted by AI, and who reviewed them?
  4. What are we spending on AI, and on what?

The only question most teams can answer is the last, and only because it shows up on an invoice. If the other answers live only in people's heads, the organization isn't governing AI. It's hoping.

What governance looks like

AI governance isn't a ban and it isn't a PDF. It's a set of controls that run at the point of use:

  • Permission: who can use which models, for which kinds of work.
  • Protection: limits on what data can go in, enforced by the system rather than by someone remembering a training slide.
  • Provenance: a record of what AI produced, what a person reviewed and what was released. This is the control that protects reputation.
  • Price: spend tied to use and value, not a surprise at month end.

Each of these should produce evidence. A control is only real if you can show it working to whoever asks: a customer, a prime, a board or an auditor. These four planes are the core of the Stehrling AI Governance Model, which we have published openly.

The Defense Industrial Base learned this lesson with NIST SP 800-171. Writing the SSP was never the point. What matters is running it and being able to prove it. Organizations that treated compliance as a one-time document found out that signing an affirmation is a legal statement. AI is heading the same way. The first time an AI-generated error reaches a customer or an agency, nobody will ask whether you had a policy. They'll ask what you did to stop it.

The choice isn't whether to use AI

Organizations are stuck between two fears: the risk of using AI and the risk of falling behind by not using it. Bans don't work, because people route around them and the usage moves where nobody can see it. Allowing AI with no controls trades a productivity gain for an exposure nobody has measured.

The way through is a sanctioned environment good enough that people want to use it, with controls built in rather than bolted on. Make the right way the easy way, and make it visible.

Use AI. Keep your reputation. The two goals don't conflict, and governance is what lets you do both.

Want to know where your organization stands?

Take our 3-minute Readiness Check and get an instant gap summary based on your environment.

Start Readiness Check →

An independent firm focused exclusively on NIST 800-171 compliance for defense contractors and the DIB.

Fredericksburg, VA