re-ai-gov Join the waiting list

Kennisbank

A new process on top doesn't work

The assumption that usually doesn't hold

Many governance initiatives start with a new process: a form, an approval step, a committee that must assess AI use before it can begin. The assumption is that employees will follow this process because it exists. In practice, that rarely happens. Someone who can do a task faster with a tool they found themselves doesn't ask permission from a committee whose agenda they don't know and whose turnaround time they can't estimate. They use the tool and stay quiet about it.

That is not unwillingness. It is a rational response to a process that sits alongside the work instead of inside it. A second process demands time, produces uncertainty about the outcome, and offers no visible benefit to whoever follows it. The odds that it gets ignored are then greater than the odds that it gets followed.

What emerges when the process is ignored

The result is not that no AI gets used. The result is that AI gets used out of sight of whoever is responsible. The IT list of approved tools then remains a description of what was once requested, not of what is being used. Between those two lists a considerable gap can exist, and no one who only looks at the approved list can see that gap.

This directly touches on the question of who is responsible when an AI application makes a mistake. An executive who wants to be able to assign liability needs to know which system influenced a decision. If that system was never registered because the registration procedure was skipped, that basis is missing at the moment it is needed.

Why asking works better than checking

The method we use does not start with an approval process but with an inventory that asks rather than checks. The difference is small in form and large in effect. An employee who is asked what they use and for what, without this having any consequences for them personally, has no reason to withhold the answer. An employee who knows that an honest answer could lead to a ban or a correction has every reason to adjust the answer.

This is a vulnerable point in the method, and we would rather name it than hide it. An inventory without repercussions produces a more honest picture than an audit with consequences, but it offers no guarantee that every instance of use will be reported. Someone using a tool they suspect is problematic can still stay quiet, even without a direct threat. The inventory lowers the threshold for reporting; it does not remove that threshold entirely. What the method does offer is a greater chance of a complete picture than a process that already suggests punishment upfront.

How this connects to what already exists

A second process gets ignored. An addition to an existing process has a better chance of surviving. That is why we classify AI use by role and risk level within the risk structure an organization already uses, rather than placing a new structure alongside it. What gets classified as high risk ends up in the same place as other high risks within the existing risk register. That also means that the question of how often reclassification should happen does not require a new calendar but fits into the existing cycle of risk assessment.

This connection does not solve everything. An AI register that was compiled once becomes outdated as soon as someone starts using a new tool without reporting it. That is why the question of how an AI register stays current is just as important as the initial inventory. A register that is not maintained again becomes, over time, merely a description of the past.

What oversight can and cannot solve

Oversight of AI use is often presented as a technical matter: a system that monitors, a dashboard that reports. But oversight that works starts with people who understand why reporting is worthwhile and who know what happens to their answer. That is a question about behavior, not only about technology, and it connects to what human oversight in practice means on the work floor, and to what AI literacy for employees concretely entails. Without that understanding, every process, however well designed, remains a form people fill in because they have to, not because it delivers something.

What this does not guarantee

This approach does not provide complete certainty that all AI applications will be found. It lowers the threshold for reporting and connects to existing structures, but an organization inventorying for the first time must reckon with the fact that part of its usage will remain invisible, even though that part is usually smaller after a careful inventory than before it.

From inventory to insight into the work itself

An inventory of AI use shows what is running and who is using it, but it says nothing yet about how much of the underlying work can actually be taken over by AI. That question lies a step further and is answered by the work scan from FTE TO AI, which calculates per task which portion of the work can be taken over. Once an organization knows which tools are being used within it, that scan can be used to examine what that use means for how the work itself is organized.

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.