- An AI acceptable use policy alone isn’t enough. Auditors expect controls to be enforced in real time.
- Five core controls can help you prove AI governance, even without a dedicated security team: Discovery, Classification, Authentication, Governance, and Auditability.
- Frameworks like SOC 2, HIPAA, GDPR, ISO 27001, ISO 42001, NIST AI RMF, and the EU AI Act all require some form of access governance evidence.
- The biggest blind spots for small to mid-sized teams are personal AI accounts and shared credentials, which undermine user attribution.
- If you've just begun discussions on governing AI access, start with this guide: Allow, Warn, Block: A Practical AI Governance Model for Lean Teams. Then, return to this article to build controls that pass auditor scrutiny.
|
This guide explains:
|
|
About the expert in this article: Andreas Welsch
Andreas Welsch is the Founder & Chief AI Strategist at Intelligence Briefing and the best-selling author of two books, the AI Leadership Handbook and The HUMAN Agentic AI Edge.
For over two decades, Andreas has advised Fortune 500 leaders on AI value realization and led enterprise-AI integrations at scale. In this article, he applies enterprise AI governance to help smaller orgs with lean IT resources navigate compliance.
Outside of work, Andreas is an Adjunct Professor at West Chester University of Pennsylvania and serves on the Editorial Board of the Journal of AI, Robotics, and Workplace Automation.
He’s also a frequent keynote speaker and has been named a LinkedIn Top Voice, a Top 10 Thought Leader in AI and Agentic AI, and a Top 30 AI Leader. Andreas has been featured on CIO.com, VentureBeat, Forbes, & CNBC. |
What’s the difference between an AI governance policy and AI governance controls?
- Which tool was accessed and by whom
- The date of access
- Which credentials were used
- The type of authentication (SSO versus username/password)
- When an employee logs in to an AI tool with a personal Gmail on a corporate device, attribution is unclear.
- When three employees share access to an AI writing platform, you can't tell an auditor who accessed what, when, or how.
|
Which compliance frameworks will ask for AI governance evidence?
If your employees use AI tools to process PII, corporate, or regulated data, auditors will look for:
SOC 2: Logical access controls & user accountability
HIPAA: Authentication, access control, audit controls
GDPR: Records of tools processing personal data
ISO 27001: Asset inventory, monitoring & access controls
NIST AI RMF: AI inventory, governance, and risk management
EU AI Act: Logging, monitoring, and risk-based oversight
ISO/IEC 42001: AI management system controls
The common thread: Access governance (inventory, authentication, monitoring, and audit evidence).
|
At minimum, what AI governance controls should you prioritize?
|
Control
|
What it does
|
Core compliance need it addresses
|
|
#1 Discovery
|
Identifies every AI tool in use, whether accessed with corporate or personal credentials
|
AI tool inventory
|
|
#2 Classification
|
Assigns risk tiers to AI tools
|
Risk-based classification of assets (formal risk classification categories are required for EU AI Act compliance)
|
|
#3 Authentication
|
Links AI access to specific, authenticated users
|
User-level accountability
|
|
#4 Governance
|
Enforces access policies in real-time, at login
|
Controlled access to regulated data
|
|
#5 Auditability
|
Produces evidence (logs, records, and reports) to demonstrate controls are working
|
Compliance evidence on demand
|
Control #1 (Discovery): What counts as an AI tool for compliance purposes?
|
Type of AI tool
|
Examples
|
How employees are typically accessing it
|
Main business risk
|
|
Chatbots
|
Perplexity, Claude, ChatGPT, Gemini, Microsoft Copilot
|
Often accessed with personal email credentials; corporate SSO available on paid tiers
|
Data leakage & policy violations
|
|
Writing assistants
|
Grammarly, Jasper, copy.ai
|
Often accessed with personal emails
|
Exposure of confidential material, language that creates liability
|
|
Code-writing assistants
|
Base44, Replit, Cursor, GitHub Copilot
|
Mix of personal and corporate credentials; team API key common
|
Insecure code generation, intellectual property or open-source license conflicts
|
|
Meeting and note assistants
|
Otter, Fireflies, BlueDot
|
Personal emails almost always used
|
Exposure of confidential conversations
|
|
HR & recruiting tools
|
Beam AI, hireEZ, Eightfold AI, Harver
|
Corporate credentials but may not be SSO-protected
|
Hiring bias & legal exposure
|
|
Design generators
|
Canva, Adobe Firefly
|
Often accessed with personal emails
|
Accidental uploads of unreleased assets, designs mimic copyrighted elements or trademarked styles
|
|
Analytics and business intelligence (BI) tools
|
Microsoft 365 Copilot, Gemini in Google Sheets, AI in Tableau
|
Usually accessed with corporate credentials
|
Exposure of financial or operational data, bad decisions due to flawed analytics
|
|
|
Perplexity Comet, Opera Neon, Gemini Auto Browse, Samsung Browser for Windows
|
Often accessed with personal credentials, bypassing corporate controls
|
Unauthorized actions, credential exposure
|
|
[Visibility] starts with a clear and actionable AI governance policy that employees can actually understand and apply in their day-to-day work. It should outline what tools are approved, what types of data can be used, and when additional review is required. Without this clarity, employees will make decisions on their own, often without fully understanding the implications ~ Andreas Welsch, founder and Chief AI Strategist, Intelligence Briefing
|
Control 2 (Classification): How do you decide which AI tools to allow, warn, or block?
|
Classification made easy for lean teams
Andreas Welsch, founder & Chief AI Strategist at Intelligence Briefing, recommends:
The answers inform whether an app is ranked a low, high, or unacceptable risk.
As Andreas puts it, “Keeping the online form lean and review timeline short demonstrates an organization is taking governance seriously without putting up hurdles to innovation.”
|
- Allow (for approved apps)
- Warn (accessible with a policy reminder at login)
- Block (restricted at the point of access)
Control 3 (Authentication): Why is authentication an AI governance compliance control?
- Which employees are authorized to use the account
- The business reason for shared rather than individual access
- The review frequency (quarterly is defensible for most frameworks)
- Any access changes made since the last review
Control 4 (Governance): How do you enforce AI access policy at the point of access?
|
If the review requires several rounds, drags on for multiple weeks or months, and the final answer is “the risk is too high,” the process becomes a burden rather than an effective governance tool. Users will look for ways to sidestep the process, which will further diminish security and governance ~ Andreas Welsch, founder and Chief AI Strategist at Intelligence Briefing
|
- When an employee tries to access a tool classified as Block, they see a “block” screen in the browser with a customized message directing them to an approved alternative.
- When a tool is classified as Warn, they see a policy reminder before proceeding.
- Which tools are currently at each tier
- Which have changed their security posture or terms since the last review
- Whether any access rights have changed
- For a quarterly review template, use three columns: Tool, Current Tier, and Change Since Last Review.
- Add a fourth column if any access rights changed, to account for who made the changes, when, and why.
Control 5 (Auditability): What evidence does an auditor actually need for AI governance?
|
Framework
|
What an auditor needs
|
How LastPass produces it
|
|
SOC 2 CC6.1–CC6.3
|
Evidence logical access controls are applied consistently and operate effectively
|
Admin console reporting surfaces risky app activity and authentication gaps by severity
|
|
HIPAA §164.308–164.312
|
Evidence of access governance, user accountability, audit controls, strong authentication for systems that may process ePHI
|
SaaS Monitoring user logins (via personal or corporate credentials), SaaS Protect enforcement logs, MFA authentication assurance *
*for protecting workstations, Active Directory, & on-prem LDAP services*
|
|
GDPR Articles 28–30
|
Visibility into AI/SaaS apps used for processing personal data & support for maintaining DPAs (data processing agreements) and ROPAs (record of processing activities)
|
SaaS Monitoring surfaces AI & SaaS apps that may process personal data, helping validate DPA coverage & improve ROPA accuracy)
|
|
ISO 27001 A.5.9 & A.8.16
|
Discovery, inventory, access attribution, and monitoring of AI-enabled SaaS apps
|
SaaS Monitoring live inventory; access attribution records via admin audit trail
|
|
NIST AI RMF GOVERN 1.6, MAP 4.1/4.2
|
Inventory lifecycle management; ongoing monitoring, user attribution, & governance of third-party AI systems
|
Govern 1.6: SaaS Monitoring inventory of AI-enabled apps
Govern 4.1/4.2: SaaS Monitoring inventory of open-source third-party AI systems
|
|
The EU AI Act Article 4 & Article 26
|
Evidence measures exist to inform staff of AI governance policies; access monitored and attributable for high-risk AI systems (e.g. HR screening or hiring tools)
|
Article 4: SaaS Protect exportable Warn and Block logs for reinforcing AI access literacy
Article 26: SaaS Monitoring login-level access attribution for high-risk AI tools; SaaS Protect for access policy enforcement *
*Note: Art. 26(6) requires retaining direct operational logs of the AI system itself. These must be exported from the AI tool's own admin console*
|
|
ISO/IEC 42001 Clause 7.5
|
Inventories, monitoring & access governance records supporting an AI Management System (AIMS)
|
SaaS Monitoring inventory of AI-related SaaS apps; SaaS Protect exportable governance and audit logs retained as documented information within an AIMS
|
- An AI tool inventory record
- Named-user access records
- MFA enforcement records
- AI classification decisions
- Allow/Warn/Block enforcement records
- Access review documentation
- Audit logs covering the review period
|
Quick self-check: If you can answer yes to all three, your controls are in good shape.
Discovery and authentication are where lean IT teams are most exposed. Both are addressable without enterprise-scale tools.
|
How does LastPass provide the AI governance controls you need to prove compliance?
- AI app discovery in the browser
- Enforced security policies at login
- Evidence that controls are working consistently and effectively
|
LastPass Capability
|
AI Governance Control
|
Governance Outcome
|
Evidence Artifact
|
|
Discovery
|
Continuous AI/SaaS tool inventory, accessed with either personal or corporate credentials
|
Discovered Apps export
| |
|
Classification + Governance
|
Allow/Warn/Block enforcement at login based on risk tier
|
Allow, Block and Warn logs
| |
|
SSO + MFA
|
Authentication
|
Identity-based access to AI tools with enforcement evidence
|
MFA enforcement records
|
|
Shared access management (vault)
|
Authentication
|
Controlled, user-attributable access to shared AI accounts
|
Access attribution records
|
|
Security dashboard
|
Auditability
|
On-demand compliance evidence across all five controls
|
Exportable access & authentication reports
|

