Retail is a sector in which AI takes root at two levels at once. On one side are the large, visible systems: inventory forecasting, price optimization, recommendation engines on the webshop, chatbots in customer service. These are usually known to IT and procurement, because they were purchased and implemented somewhere. On the other side is a much more diffuse landscape: individual employees on the shop floor, in marketing or in purchasing who use an AI tool to write product descriptions, answer customer questions, generate campaign images or scrape competitor prices. This second layer is usually larger than the first, simply because the threshold for trying a free or cheap tool is low and the effect is immediately noticeable: a faster ad text, a faster response to a complaint.
On top of that, retail often works with many temporary and flexible employees, spread across multiple locations or channels. This makes it harder to have a single central overview of who uses which tools, and why. A head office may have a clear policy for the systems it has purchased itself, while at store level or within a webshop team AI applications emerge that are registered nowhere. The ratio between what has been centrally approved and what has arisen locally is usually skewed in this sector: the number of officially procured systems is limited, while the number of individual applications that employees have started using themselves is usually much larger.
The term shadow AI sounds technical, but in retail it is practical: it is the tool a marketing employee uses to generate social media posts, the chatbot a customer service team has configured itself, or the AI model deployed to analyze reviews without this ever having been reviewed by IT or legal affairs. This rarely happens out of carelessness. It happens because the tools are accessible, because the pressure for speed is high, and because no one has explicitly said it is not allowed.
The IT list of approved software therefore gives an incomplete picture. Anyone who wants a complete picture has to ask the people themselves. That only works if the question is asked without consequences. As soon as employees suspect that reporting AI use will lead to a correction or a ban, the information disappears from view again and use shifts to private devices or personal accounts. An inventory that starts by ruling out accountability produces a different kind of answer than an audit that starts by looking for violations.
An AI tool that rewrites product descriptions has a different impact than a system that automatically adjusts prices based on demand and competition, or a tool that uses customer data to make recommendations. In retail, classification by role and risk level is therefore important: is it a supporting tool, a system that prepares decisions, or a system that independently makes decisions directly affecting customers, such as dynamic pricing or automated rejection of returns? This classification determines what level of oversight and documentation makes sense, and which systems require the attention of management or risk management and which can be handled within a team.
Retail organizations usually already have risk structures in place for matters such as product safety, privacy legislation around customer data, or financial control over pricing. AI governance does not need to be a new, separate process alongside those structures. It works better when the inventory of AI use is linked to existing risk categories, so that a system that processes customer data goes through the same channel as other privacy-sensitive processes, and a pricing algorithm follows the same line as other commercially sensitive decisions. Current regulation around AI systems is changing; the precise obligations and deadlines are described elsewhere. What matters here is the mechanism: knowing what is running, knowing who uses it, and knowing how risky it is before there is an external reason to find out.
The challenges differ per sector, even though the underlying mechanism is comparable. Anyone who wants to compare how this plays out in a sector with a lot of customer contact and flexible labor will find that in the description of AI governance in hospitality, while a sector with strong supply chain dependencies and physical processes is covered in the analysis of AI governance in the agricultural sector. For organizations that develop or procure a lot of software themselves, the overview of AI governance in the ICT sector is relevant, and anyone dealing with strongly regulated customer data can make the comparison with AI governance in financial services.
An inventory of AI use shows what is running and who is using it, but does not yet answer the question of what that means for the way the work itself is organized. In retail, where tasks are often routine and well-defined — from answering customer questions to writing product texts — that follow-up question is a real one. The work scan from FTE TO AI calculates per task which part of the work can be taken over by AI, based on the tasks as they are actually carried out. Where the Responsible AI Scan maps out what is happening and under which risk level that falls, the work scan offers the perspective of the organization of the work: which tasks lend themselves to being taken over, and to what extent.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.