re-ai-gov Join the waiting list

Kennisbank

AI risk for the CIO: the list you have is not the list that counts

The question you're actually asking

You have a list of approved AI tools. The question is not whether that list is accurate, but whether it still means anything. An employee who speeds up a task with a chatbot that isn't on the list doesn't report it as an incident. They don't report it because it doesn't feel like an incident. So the answer you shouldn't accept is "we have an AI policy and an approved list" — because that sentence says nothing about what happens outside that list, and that is probably the largest part.

What you stand to lose

As CIO, you are the one who has to explain why an AI incident wasn't known earlier, while the rest of the organization assumes IT has oversight. That oversight exists for systems that were procured. It does not exist for the add-on a team installed itself, the trial version someone activated, or the model that came along through a customer service tool. The risk for you is not that AI is being used — that happens regardless — but that you find out about it last, at the moment it has already gone wrong.

What you stand to gain

An inventory that is accurate changes your position. Instead of reacting to incidents you didn't see coming, you can indicate in advance where the risks lie and why. That is also the basis for having the conversation within the organization with the General Counsel, who looks at the same shadow AI from a different perspective, and with the risk manager, who wants to fit it into the existing risk structure rather than setting up a separate track alongside it.

Why the IT list is not reality

The IT list records what has been procured and approved. Shadow AI arises where those two steps are skipped: an employee finds a tool, uses it, and reports nothing because there seems to be nothing to report. That is not negligence — it is the consequence of a procurement process that was not designed to keep track of what people pick up themselves. The larger the organization and the more independently teams work, the larger the gap between the list and reality can be. How small that gap is depends on how much freedom teams have to choose their own tools and how visible that behavior already is — there is no figure for this, only the direction.

Why asking only works without repercussions

The only way to know what is actually running is to ask the people who use it. That only works if the answer does not lead to a consequence for the person giving it. If you ask "do you use AI tools that haven't been approved" in a tone that resembles a performance review, you get the answer the IT list already gave: no. If you ask it separate from any repercussions, with the goal of understanding rather than correcting, a picture emerges that does match practice. That distinction — asking without consequences versus asking with consequences — is the difference between an inventory that is worth something and an exercise that tells no one anything.

Classification is the second problem

A list of tools in use is a starting point, not an end point. Not every AI application carries the same risk. A tool that rewrites text for internal use is different from a tool that helps decide on a customer acceptance or a personnel assessment. Classifying by role — what does the system do — and by risk level — what is the impact if it goes wrong — is necessary to know where you should focus your attention. Without classification, every AI application looks the same in a report, and that is exactly the picture that doesn't help get a board on board.

Connecting to what is already in place

As CIO, you probably already have a risk framework for IT systems, information security, and suppliers. AI governance works better when it connects to that structure than when it becomes a separate framework alongside it. That is also what the compliance officer and the AI program lead run into: too many separate AI initiatives that don't talk to each other, while the board expects precisely one coherent answer to the question of what is going on and what is being done about it.

The sector makes a difference

What shadow AI means differs by sector. In construction it plays out differently than in the installation industry, and it's worth looking at how AI governance takes shape in construction or what that looks like in the installation industry before assuming that one approach fits everywhere.

The current state of affairs

The Responsible AI Scan that produces this — inventory, classification, a governance set that connects to your existing structure — is under construction. Anyone who wants to get started with this now can sign up for the waiting list; there is not yet a ready-made product to offer, and we would rather state that honestly than promise something that doesn't exist yet.

The question that comes next

Once you know which AI is being used and with what risk, the follow-up question naturally arises: which part of the work itself could be a task for AI, and which part could not. That is a different question from risk management — it concerns capacity, not exposure — and the work scan from FTE TO AI calculates that per task, so that you not only know what is already running, but also where AI could actually take over the work itself.

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.