The question that opens most conversations about AI in government is whether the institution should adopt it. That is the wrong question. The institution already has. The question is whether it knows.
Generative AI tools are free, reachable through a browser and extraordinarily useful for tasks every civil servant performs: summarising, drafting, translating, organising. No security policy prevented this, because the adoption went through no procurement, no installation and no service desk. It happened through a browser tab.
The result is a situation that repeats itself in organisation after organisation: meaningful use, real productivity, and no institutional visibility over what is being pasted into a service the organisation never contracted.
Governance does not begin by prohibiting
The instinctive reaction is to block. It fails for two reasons. The first is practical: blocking pushes use onto personal phones, where the organisation loses all visibility. The second is strategic: blocking a productivity tool without offering an approved alternative turns the technology function into the obstacle rather than the enabler.
Every organisation that raises awareness of AI widens, in the same movement, its exposure surface. That is not an argument against awareness. It is an argument for doing it alongside the policy.
The sequence that works
- Measure before regulating. Without knowing who uses it, how often and for what, any rule will be written in the dark and obeyed in the dark.
- Offer the approved route before closing the open one. A contracted corporate model first, restriction second.
- Separate by the nature of the data, not by the tool. The useful rule distinguishes public data from sensitive data, and civil servants understand and can apply that.
- Name an owner for every meaningful use. An agent in production without an owner is institutional risk with no address.
- Measure again. Governance without recurring measurement is a statement of intent.
What an AI policy has to answer
An institutional artificial intelligence policy does not need to be long. It needs to answer, clearly enough to guide day-to-day decisions: which tools are approved and for what purpose; what may be entered into an open tool and what is strictly prohibited; when human oversight is mandatory before any effect on third parties; who approves a new use case; and how the organisation records and reviews what is already running.
Five answers. Most organisations have none of them written down, and are nonetheless discussing which platform to buy.
From pilot to org chart
There is a stage almost nobody has reached yet, and it defines the next level: treating agents as part of the structure of work. If an agent performs a step in a process, someone answers for the outcome of that step. It has a performance indicator, a periodic review and a decommissioning criterion, exactly like any other component of the operation.
This is not an administrative metaphor. It is the condition for AI adoption to survive its first serious audit. Organisations that get there will have built genuine governance. The rest will have built dependency.