The Question

Every enterprise that has been through a cybersecurity audit in the last five years has an AI acceptable use policy. Most of those policies are sitting in a SharePoint folder, acknowledged by employees via checkbox during annual compliance training, and functionally ignored the remaining 364 days of the year. The policy exists. The compliance record shows it was reviewed. The behavior it was written to govern has not changed.

This is not a failure of intent — it is a failure of policy design. Enterprise AI governance policy is typically written by security or legal teams for an audience of auditors, not for the engineers, analysts, and business unit employees who are the actual subjects of the policy. The language is precise but abstract. The prohibitions are clear but the alternatives are not. The consequences are either absent or so severe that managers decline to enforce them against otherwise valuable employees making reasonable business decisions with the tools available to them.

The Samsung incident in 2023 is the reference case. Samsung engineers used ChatGPT to debug proprietary source code and summarize internal meeting notes. Samsung almost certainly had data handling policies that would have prohibited this behavior if employees had understood what they were doing in policy terms. They did not understand it that way — they understood it as using a productivity tool to get work done faster. The gap between how the policy defined the behavior and how employees understood the behavior is the gap that AI governance policy design must close.

An AI governance policy that employees don't follow is not a governance control — it is documentation of the organization's intention to govern AI, which is a different and weaker thing.


Why This Matters Now

The Samsung incident established the pattern, but the scale of the problem has grown significantly since 2023. Enterprise AI tool adoption has accelerated through 2024 and 2025, with generative AI embedded in productivity suites (Microsoft 365 Copilot, Google Workspace Duet AI), development tools (GitHub Copilot, Cursor, Codeium), customer-facing applications, and standalone tools that employees adopt without IT provisioning.

Gartner estimated in 2025 that over 60% of enterprise AI tool usage occurs through tools that were not formally approved by IT. The EU AI Act's transparency and documentation requirements apply to AI system operators regardless of whether those systems were formally sanctioned by the organization — meaning that ungoverned AI tool usage creates regulatory exposure that a policy nobody follows does not mitigate.

The FTC's 2024 enforcement actions included cases where companies' AI acceptable use policies were presented as evidence of governance maturity, and the FTC found that the policies described governance controls that were not operationally implemented. Policy documentation without behavioral change does not establish a compliance defense; in some cases it creates additional liability by demonstrating awareness of risk without action.

CISA's 2025 AI Security guidance introduced the concept of "policy-behavior gap" as a specific risk category in AI governance assessments — recognizing that the gap between written policy and actual employee behavior is itself a measurable and addressable governance failure. Organizations conducting EU AI Act readiness assessments in 2025–2026 are finding that the policy-behavior gap is frequently the largest single compliance gap they have, ahead of technical control gaps and vendor due diligence gaps.


What the CURVE™ Data Shows

The 2026 Stackcurve AI Governance CURVE™ Report evaluated vendors against criteria that included policy delivery mechanisms — specifically, whether governance platforms support embedding policy at the point of AI tool use rather than only in standalone policy documents.

Vendors with the strongest scores on policy operationalization included Forcepoint ONE (which supports AI usage policy enforcement at the network and application layer), Microsoft Purview (which embeds data handling guidance in Copilot interactions), and Nightfall AI (which delivers real-time policy guidance at the point of sensitive data input into AI tools). Vendors that support only document-based policy management scored lower on this criterion.

The report also evaluated the governance advisory services category against their capacity to support business unit participation in policy drafting — the single most reliable predictor of policy adoption. Firms that staffed policy engagements with mixed technical and business teams consistently produced policies with higher reported adoption rates than firms that produced policy from security or legal teams alone.

The shadow AI discovery category — vendors including Netskope, Zscaler, and Lookout that provide CASB-based visibility into unsanctioned AI tool usage — was evaluated as a prerequisite for effective policy enforcement, since policy compliance cannot be measured without visibility into actual behavior.

The full vendor rankings are in the 2026 Stackcurve AI Governance CURVE™ Report — free to download.


The Gap Most Buyers Miss

Most enterprises treat AI governance policy as a document problem — write the policy, get it acknowledged, archive the acknowledgment. The enterprises building governance programs that actually change behavior treat it as a behavior change problem, which requires different tools and different design principles.

Specificity is not optional

"Protect sensitive data when using AI tools" is not a policy. It is an aspiration. Employees cannot comply with aspirations because aspirations do not tell them what to do in specific situations. "Do not submit source code, customer PII, healthcare records, non-public financial information, or attorney-client privileged materials to AI tools not on the approved list" is a policy. Employees can apply it to specific decisions.

The test for policy specificity: can an employee read the policy and make a binary decision about a specific action they are about to take? If the answer requires interpretation, the policy is underspecified.

Proximity beats documentation

Policy delivered at the point of action is more effective than policy delivered in annual training. The most effective AI governance policy implementations embed guidance directly in the AI tools employees use — system prompts that remind users of data handling restrictions before they submit a query, usage screens that display the approved use cases for a specific tool, browser extensions that flag when a user is attempting to submit sensitive data to an unsanctioned AI service.

If the only place your AI governance policy lives is a document in a policy portal, employees will encounter the policy during compliance training and nowhere else.

Prohibition without alternative is an invitation to bypass

Every prohibition in an AI governance policy needs an approved alternative. "You cannot use ChatGPT to summarize customer call recordings" requires a follow-on sentence: "Here is the approved tool for call recording summarization." Employees who are prohibited from using a tool they find effective and offered no alternative will either use the prohibited tool anyway or stop using AI assistance entirely — both of which represent governance failures.

Consequence clarity

Policies without stated consequences are aspirational documents. Employees and managers apply judgment about whether enforcement is likely, and policies with no stated consequences are typically assessed as unenforceable. Clear consequence statements — the specific HR or disciplinary process that applies to policy violations — are required for policy to function as a governance control. This is one reason HR membership in the AI governance committee is non-optional: HR must own the consequence framework for AI policy violations, and HR cannot own what it was not consulted in designing.


Questions Your Buying Team Should Be Asking

1. Have business unit employees — not just legal, security, and IT — participated in drafting our AI governance policy?

If the answer is no, your policy almost certainly contains prohibitions that are operationally impractical and use case descriptions that do not match how employees are actually using AI tools. Convene a working group with representatives from the business units with the highest AI tool usage and review the policy against their actual workflows. Expect to find significant mismatches. Revise before re-publishing.

2. Where does an employee encounter our AI governance policy in the course of a normal working day?

If the only answer is "during annual compliance training," you have a proximity problem. Identify the three highest-risk AI use behaviors your policy is trying to govern and find the technical mechanisms to embed policy guidance at the point of those behaviors. This may require CASB configuration, Microsoft Purview policy, GitHub Copilot policy settings, or AI platform system prompts.

3. For every prohibition in our AI governance policy, is there an approved alternative specified?

Audit your policy against this criterion. Every prohibition that lacks an approved alternative is a prohibition employees will route around when they have legitimate business needs. Closing this gap requires the approved tool register to be complete and current — which requires the AI governance committee to maintain and publish it.

4. What is our review cadence for the approved AI tool register, and was it updated in the last 90 days?

AI capabilities and enterprise AI tool offerings change significantly on a quarterly basis. An approved tool register that was last updated at annual policy review is likely to be materially out of date. Quarterly review is the minimum for the approved tool register even if the policy document itself is reviewed annually.

5. Do we have visibility into whether employees are following our AI governance policy, or do we only know about violations when they cause incidents?

Effective policy requires measurable compliance. CASB-based shadow AI monitoring, DLP monitoring for sensitive data submission to AI tools, and periodic employee surveys on AI tool usage are the three primary mechanisms for measuring policy compliance. If the answer to this question is "we find out about violations when they cause incidents," you have a monitoring gap that makes policy enforcement reactive rather than preventive.


The Stackcurve Take

AI governance policy design is one of the few areas where the quality of the output depends almost entirely on the process used to create it, not on the technical sophistication of the team creating it. A policy written by the most experienced security team in the industry, without business unit input, will be bypassed. A policy written with business unit input, embedded at the point of action, with approved alternatives for every prohibition and clear consequence statements, will change behavior — regardless of how technically sophisticated the team that wrote it was.

The Samsung incident is now the most widely cited example of AI governance policy failure. What is less discussed is that Samsung's response — temporarily banning the use of generative AI tools entirely — is itself a governance policy that addresses the symptom while leaving the root cause unexamined. Banning tools employees find useful does not close the gap between policy and behavior; it creates a new gap between official policy and the unofficial tool usage that continues under the surface.

The 2026 Stackcurve AI Governance CURVE™ Report covers policy operationalization platforms, shadow AI discovery tools, and the policy design frameworks that enterprises are using to close the gap between written governance policy and actual employee behavior. Download it free →


← Back to Research Library

Stackcurve Advisory Briefs are independent research. No vendor pays for placement, tier assignment, or editorial influence. The CURVE™ methodology is disclosed in full at stackcurve.net/research/methodology.