By Ts. Lukas J. Tan | 16 September 2026

Why I Am Paying More Attention to Practical AI Governance

Whenever I learn a new technology, I rarely stop at understanding what it is or watching other people demonstrate what it can do. I have always preferred to use technology myself, push it into real work, test its limits, connect it with other tools, and see how far it can actually go. Sometimes this approach creates efficiency. Sometimes it exposes weaknesses. But more importantly, when you use something deeply enough, you begin to notice things that are difficult to see from the outside.

Artificial intelligence has been no different for me. Over the past few years, AI has gradually become part of how I think, write, research, analyse information, develop software, communicate and operate a business. I have watched tasks that once required hours become tasks that can be completed in minutes. Research can be accelerated. Documents can be analysed almost immediately. Software can be developed faster. Ideas can be explored from multiple directions without assembling a large team. An individual equipped with the right AI tools can now perform work that would once have required several different skills or people.

I am excited by that development. I want AI to become more capable, not less. I want businesses to discover how much more productive they can become when AI is used properly.

Yet the deeper I use AI, the more I find myself thinking about something other than productivity.

Everyone talks about how fast AI is becoming. What concerns me is not simply that AI is fast. What concerns me is the possibility that AI is becoming faster than our ability to control what we are doing with it.

This difference matters.

For decades, computing technology has continued to accelerate. Moore’s Law became one of the best-known descriptions of how rapidly computing capability developed over time. Every generation of technology has given us greater processing power, greater connectivity and faster access to information. AI is adding something different to that acceleration because computers are no longer only storing and processing information. Increasingly capable AI systems are now participating directly in knowledge work: interpreting information, generating content, writing software, analysing documents and supporting decisions.

Consider something as ordinary as preparing a business proposal. In the traditional workflow, someone gathers information, thinks about the problem, prepares a draft, reviews it, makes corrections, discusses it with colleagues and eventually sends it to the customer. That process may take several hours or even several days. Today, an employee can provide AI with some information and receive a professionally written proposal within minutes.

That sounds entirely positive until we look at what happened to the control process.

The speed of generation increased dramatically, but did the speed and quality of human review increase at the same rate? The employee can generate faster, copy faster, analyse faster, upload faster and send faster. But management still has to review, approve, protect, verify and take responsibility.

This is what I increasingly see as the governance gap.

The issue is not that AI is doing something wrong simply because it is fast. The issue is that our organisational controls may still have been designed for a much slower world.

There are much larger debates about what happens if increasingly autonomous AI systems eventually exceed meaningful human control. Some people talk about AI controlling humanity or even posing an existential threat. I do not think anyone can state with certainty today how those scenarios will develop. They deserve serious research and discussion, but we do not have to travel that far into the future to understand why governance matters.

There is a much simpler question that every business can ask today:

Can your company control the AI that is already being used inside your company?

That question is no longer theoretical.

The Employee Leaves. What Happens to the AI?

One of the simplest examples is something that almost every business owner understands: employee turnover.

Imagine an employee who uses AI every day for company work. Perhaps the employee works in marketing, sales, administration, software development or management. The company pays the employee’s salary. The employee works with company customers and company information. Over time, AI becomes deeply integrated into that person’s workflow.

The employee may use AI to analyse customers, develop proposals, write reports, create marketing campaigns, solve technical problems, develop software, summarise meetings, research competitors and structure ideas. After one or two years, the AI environment may contain hundreds or thousands of conversations. Inside those conversations may be prompts, templates, customer context, project knowledge, instructions, research, workflows and many small pieces of organisational knowledge accumulated through daily work.

Then the employee resigns.

Most established companies already know what to do next. The laptop is returned. The company email account is disabled. CRM access is removed. Cloud storage permissions are revoked. Internal systems are locked. The employee exit checklist is completed.

But what happens if all that AI work was performed using the employee’s personal AI account?

Who owns the account? Who controls the conversation history? Where are the prompts? Where are the custom instructions and workflows? Can the company retain the knowledge that was created during employment? Can another employee continue the work?

Suddenly, what initially looked like an AI productivity issue becomes an ownership and business continuity issue.

The employee leaves, and potentially part of the company’s working knowledge leaves as well.

This is why I have increasingly returned to one very simple principle:

Keep Personal Personal. Keep Company Company.

This is not an entirely new management idea. Businesses went through similar transitions with email. We learned why company communication should not depend entirely on an employee’s personal Gmail account. We developed company servers, company databases, company cloud storage, company accounting systems and company-managed access because organisations eventually understood that business information needed ownership and continuity.

AI requires us to revisit the same principle in a new environment.

If an AI account is being used substantially for company work, management should at least know whose account it is, who controls it, what happens to access when the employee leaves, and how important organisational knowledge will be retained.

The Question Is Not Only Whose Account. It Is What Goes Inside.

Account ownership is only the beginning.

The more useful AI becomes, the more context we tend to give it. If we want AI to prepare a better proposal, we provide information about the customer. If we want AI to analyse a contract, we upload the contract. If we want it to understand a technical problem, we may provide source code. If we want it to analyse a business situation, we may give it meeting notes, financial information or internal strategy.

This creates an uncomfortable relationship between usefulness and governance.

The more context we give AI, the more useful it can become. But the more information we give AI, the clearer our information boundaries need to become.

What are employees currently putting into AI systems?

Customer information? Contracts? Internal meeting minutes? Financial information? Employee information? Source code? Business plans? Confidential documents? Strategic discussions?

The correct answer is not simply to declare that every AI platform is unsafe, nor is it reasonable to assume that every AI service handles information in exactly the same way. Different tools, subscriptions, enterprise environments and configurations can provide different levels of data control.

For management, however, there is an even more basic question.

Has the company itself decided what employees are allowed to put into AI?

If one employee thinks a customer contract is acceptable, another thinks it is prohibited, and a third has never considered the question, then the problem is not necessarily the AI platform. The organisation itself has not established the boundary.

If employees have to guess the boundary, management has not defined one.

That is a governance issue.

AI Wrote It. But Who Approved It?

There is another side to AI Governance that has less to do with what goes into AI and more to do with what comes out.

Imagine an AI system preparing a sales proposal. The proposal is beautifully written. It sounds professional, confident and complete. Somewhere in the document, however, the AI states that the project can be delivered within 30 days. The company’s actual operational capability requires 60 days.

The salesperson reads the document quickly, trusts the quality of the writing and sends it to the customer.

The customer accepts the proposal.

Now there is a problem.

Who is responsible?

The company cannot realistically resolve the customer dispute simply by saying, “The AI wrote it.”

AI can draft. AI can suggest. AI can analyse. AI can recommend. But the organisation still needs to establish who reviews important outputs, who approves them and who remains accountable for the decisions and commitments that follow.

This does not mean every AI-generated sentence needs to pass through three levels of management. That would defeat much of the productivity AI creates. Governance should be proportional to impact.

A brainstorming idea for an internal discussion may require only a light review. A customer proposal, financial analysis, contractual statement, engineering recommendation or other high-impact output deserves much stronger human verification.

The principle is straightforward:

The greater the potential consequence, the stronger the human review should be.

That is how governance supports speed rather than destroys it.

AI Amplifies What You Already Have

The more I think about these issues, the more they return me to another principle that has shaped my view of AI:

AI amplifies what you already have.

If an organisation already has clear processes, disciplined information management, responsible employees and clear ownership, AI can amplify those strengths. Good people become more productive. Good processes become faster. Knowledge becomes easier to use. Small teams can accomplish significantly more.

But amplification works in both directions.

If access is messy, AI can make messy access operate faster. If information management is poor, employees can move information outside the organisation faster. If accountability is unclear, decisions can be produced and acted upon faster without anyone knowing exactly who owns the consequence. If the underlying process is broken, automating it does not necessarily repair it. Sometimes it simply allows the broken process to operate at greater speed.

This is why I do not see AI Governance as an attempt to stop AI adoption.

Quite the opposite.

I want businesses to use AI aggressively where it creates value. But if we want to accelerate, we also need to improve the steering, the brakes and the rules of the road.

Practical AI Governance, particularly for SMEs, does not have to begin with a hundred-page document. It can begin with a few very practical areas: Account and Access, Data and Privacy, People and AI Usage, Output and Accountability, and Governance and Continuity.

From there, management can begin asking straightforward questions.

Which AI tools are actually being used inside our company? Are employees using company-managed accounts or personal accounts? What information are they putting into those systems? Do employees understand what should not be uploaded? Which AI-generated outputs require human review? Who remains accountable for the final result? Who oversees AI usage? And when an employee leaves, what happens to the company’s AI-related knowledge?

These are not futuristic questions.

They are operational questions that companies can ask today.

Before Governing the Future, Understand the Present

My growing interest in AI Governance does not come from wanting to become pessimistic about AI. It comes from the opposite direction. I have used AI deeply enough to appreciate just how powerful it is becoming.

I still want AI to become faster. I still want businesses to use more of it. I still believe that AI can dramatically amplify what individuals, SMEs and larger organisations are capable of accomplishing.

But the faster technology becomes, the more important it is that our ability to govern its use develops alongside it.

We cannot continuously upgrade the engine while ignoring the steering wheel and the brakes.

For that reason, I think the question business owners should ask is changing.

A few years ago, the question might have been:

“Should our company use AI?”

Then it became:

“How can our company use AI?”

Today, I think there is another question that deserves equal attention:

“Do we actually know how AI is being used inside our company, and are we still in control of it?”

Before we worry about governing some distant future in which AI becomes extraordinarily powerful, perhaps we should first understand what is happening inside our organisations right now.

That is where practical AI Governance begins.

Not with fear.

Not with banning technology.

Not necessarily with complicated regulation.

It begins with visibility.

Know which tools are being used. Know whose accounts they are. Know what information is going inside. Know what important outputs require review. Know who is responsible. Know what happens when people leave.

Once management can answer those questions, governance becomes something practical rather than abstract.

And if management cannot answer them yet, that does not mean the company has failed.

It simply means it is time to start looking.

A Practical Starting Point

At OPERION, we have developed a Practical AI Governance Readiness Assessment to help businesses begin that process. The assessment looks at five practical areas: Account & Access, Data & Privacy, People & AI Usage, Output & Accountability, and Governance & Continuity.

It is not a certification. It is not an audit, and it is not a legal opinion or declaration of regulatory compliance. Its purpose is much simpler: to help management see what is happening today, identify areas that may deserve attention and decide what should be examined next.

Businesses that want to understand their situation more deeply can also invite OPERION to conduct a complimentary preliminary AI Governance assessment with their management team. The objective is not to arrive with a predetermined solution. It is to understand the existing environment first.

I believe strongly in one sequence:

Assessment first. Prescription second.

AI will continue to develop. It will become more capable, more integrated into everyday work and, very likely, much faster.

We should embrace the opportunity.

But as we accelerate, we should make sure our governance can accelerate with it.

Because AI amplifies what you already have.

The question is whether we understand what we are allowing it to amplify.

Ts. Lukas J. Tan
Founder & CEO, OPERION Ecommerce & Software Sdn Bhd
Practical AI Governance | Digitalisation | AI & Business Systems