---
title: "AI Governance Can't Be Phase Two: Why We Shipped Blue Border's AI Controls on Day One"
date: 2026-09-16T06:36:00Z
modified: 2026-09-11T18:36:23Z
permalink: "https://www.venn.com/blog/ai-governance-cant-be-phase-two/"
type: blog
status: publish
excerpt: ""
wpid: 7606
featured_image: "https://www.venn.com/wp-content/uploads/2026/09/Chris-Johnson-AI-Launch.png"
timestamp: 2026-09-11T18:36:23Z
tags: []
---

A little over three years ago, I wrote about how COVID created fertile ground for a [revolution](https://www.venn.com/wp-content/uploads/wp-mfa-exports/blog/work-life-setting-boundaries-for-remote-work.md) in how we got work done. Companies adopted remote work policies and moved to a BYOD model, first out of necessity, then by choice, and many are still working out the balance between governance and privacy.

Now a new revolution – or evolution – is taking place, and its impacts will be wider reaching and far more profound than the last.

AI is being woven into nearly every platform we use, and the conversation at most companies has already moved well past “should we adopt it?” The question now is whether governance can keep up with how fast adoption is moving.

That’s a more complex and nuanced problem to solve than it sounds. The same tools that have promised to multiply output are also a far more capable exfiltration point for proprietary, sensitive data than BYOD ever was.

At Venn, we’ve talked to many organizations that are deliberately pumping the brakes on adoption, unwilling to move forward until they have some real control for AI tooling. Broadly speaking, plenty of companies have written acceptable-use policies, but those are woefully inadequate on their own.

Regardless of what’s written in those policies, 47% of employees are already using their personal AI tools at work, according to Netscope’s 2026 Cloud and Threat Report. That’s pretty alarming, but it makes perfect sense given that only 38% of organizations have some semblance of an AI policy in the first place (ISACA, 2026). And even when a policy does exist, it doesn’t mean there are real technical controls in place to back it up. Cyberhaven’s 2026 research found that 58% of Claude users and 60% of Perplexity users are accessing those tools through personal accounts for work purposes, whether there was a policy in place or not.

A written policy is a memo that folks will skim once and forget. It’s not a guardrail.

Let’s be honest here. When was the last time you referred back to the employee handbook for anything? Adopting AI in the workplace without basic technical controls in place isn’t just risky; it might be borderline unethical.

So what does a guardrail actually look like if a policy by itself isn’t akin to one?

For some companies, it looks like “phase two” of their adoption plan. Something that was implemented months after the initial rollout, and possibly only after an “incident” forced their hand.

It’s honestly not surprising. Many organizations, like people, tend to only change when subjected to enough pain. Unfortunately, we’ve heard this same story many times when folks came to us looking to secure personal devices for work – in response to a breach or data security incident. That gap between “phase one” and “phase two” in an AI adoption plan is exactly the space where “[Shadow AI](https://www.venn.com/wp-content/uploads/wp-mfa-exports/knowledge/shadow-ai.md)” dwells.

We didn’t want that same gap in our own AI story. So when we added support for Claude’s desktop app inside Blue Border (ChatGPT and Codex coming soon!), we didn’t ship the integration with a roadmap plan to implement controls in the future. We shipped it with the right technical controls from the get-go.

Claude runs isolated inside the company-controlled secure enclave, where tenant restrictions ensure that employees and contractors alike are only using authorized accounts linked to their organization. We also extended tenant restrictions to ChatGPT alongside the restrictions we already had in place for Copilot and Gemini. We’re also rolling out our new AI access policy that blocks more that 400 AI-related sites and apps, so that organizations can close off access to the proliferation of tools that they would never approve for use alongside work.

This was purposefully done in the initial release, rather than in a follow up. Controls were shipped with the announcement, on day one, because every day that passes between adoption and policy implementation is a day proprietary and sensitive data are exposed through tooling no one vetted.

If your organization is planning, and hopefully it is, to adopt AI, your plan must include basic controls like the ones described here.

AI is going to continue to evolve and so will the work of securing it. New models, new agents, new harnesses. The tools will continue to change and the guardrails we place around them will have to keep pace, not lag months behind. The risk is too great.