AI Strategy & Governance · · 7 min read

What Happens When Your Approved Software Adds AI?

What happens when approved software gains new AI capabilities? Learn how organizations can adapt technology governance as cloud platforms continue to evolve.

Red Swiss Army knife with multiple tools extended
Photo by Patrick / Unsplash

Intro

Five years ago, an organization could maintain a list of approved software and reasonably assume that it understood what those applications did. Today, the software may stay the same while its capabilities change substantially.

AI is increasingly built into tools your organization already uses. 

The most obvious examples are Microsoft 365 and Google Workspace, where AI capabilities are increasingly integrated with email, documents, meetings, calendars, files, and other organizational information. But they're hardly alone. Salesforce, Zoom, DocuSign, Box, Adobe Creative Cloud, Canva, HubSpot, ServiceNow, Notion, Zendesk, Airtable, and countless other cloud platforms now incorporate AI in some form.

As a result, questions around organizational AI use are becoming more complex. AI is likely already embedded throughout the technology environment, including within platforms that were evaluated and approved long before their current AI capabilities existed.

That changes the questions organizations need to ask: What can the AI access? What can it do? Where does the information go? What controls do we have? What happens when the capability changes?

This isn't an entirely new problem. Cloud-based platforms have always evolved. Vendors routinely add integrations, introduce new data-processing capabilities, change subprocessors, modify administrative controls, and retire old functionality with very little fanfare. Salesforce releases updates several times a year; Microsoft and Google are constantly introducing new features. 

Most of these changes are routine and don't require additional scrutiny. But some are significant enough to alter the assumptions that led an organization to approve a platform in the first place.

AI hasn't created the problem of continuous product change, but it has increased the potential significance of some of those changes from a governance perspective. A feature that helps users format a document may require little additional attention. A new capability that can search across organizational files, summarize confidential meetings, analyze customer records, connect information from multiple systems, or take actions on a user's behalf warrants considerably more scrutiny.

Yet most organizations' technology governance processes were designed around products being acquired and approved, not around existing products continually acquiring materially new capabilities. 

Maintaining a separate list of "approved AI tools" may still be useful, but it is no longer enough. Organizations increasingly need governance practices that account for how the technology they already use continues to evolve after it has been approved.

When AI Is a Feature, Not a Product

Standalone AI tools are relatively easy to recognize as something that may require review. If an employee wants to begin using ChatGPT, Claude, Perplexity, or another AI platform, there is an identifiable new tool to evaluate. (See: Why Your Organization Needs an AI Policy.)

Embedded AI is different.

An employee may already have access to AI through the CRM, document management system, videoconferencing platform, creative software, project management system, or customer support platform they use every day. If AI is incorporated into a platform that's already in use, there won't necessarily be a request for a new application or an obvious moment when the organization decides to "adopt AI."

And identifying which existing platforms now include AI only gets us so far. The capabilities vary too widely for an "AI or no AI" distinction to tell business leaders much.

Instead, it is more useful to understand what a new capability actually allows people—or the technology itself—to do. For example: 

  • Create: draft, rewrite, summarize, or generate content.
  • Find and analyze: search or draw insights from organizational information.
  • Connect: work with information across different applications or sources.
  • Act: initiate tasks, update information, trigger workflows, or take other actions on a user's behalf.

These aren't rigid categories, and a single feature may span several of them. 

A tool that helps an employee improve the wording of a paragraph presents a very different set of considerations from one that can search across thousands of internal documents or take actions in a business system.

The relevant question at this point isn't "Does this platform use AI?" but "What does this new capability change about how our technology, information, and business processes work?" 

Approval Can't Be a One-Time Decision

Most organizations put the greatest scrutiny on technology when they first acquire it: Does the product meet a business need? Is it secure? How does it handle organizational information? Who should have access? Are the contract and privacy terms acceptable?

But approval represents a decision about a platform at a particular point in time. 

The challenge is developing a practical way to recognize when something has changed enough to warrant another look. That might include a platform gaining access to substantially more organizational information, connecting with additional business systems, automating decisions or actions, or using organizational data in a meaningfully different way.

The level of scrutiny should match the significance of the change. Organizations don't need to scrutinize every new feature or read every vendor release note. They need a reasonable mechanism for noticing meaningful change—and knowing what to do when it occurs. 

Someone Needs to Own What Happens After Approval

That raises a practical question: Who is responsible for noticing when an approved platform changes in an important way?

In many organizations, the answer isn't clear. 

IT may manage access and security, procurement or finance may own the vendor relationship, and legal or compliance teams may review contracts and privacy terms. A department leader may be responsible for how the platform is actually used. An AI governance group may have responsibility for AI-related policies. Depending on the organization, several of these groups may be involved—or none may have explicit responsibility once the initial purchase is complete.

Creating a separate review process for every possible concern is unlikely to help. It can lead to overlapping responsibilities, duplicated effort, and uncertainty about who actually has authority to make a decision.

A more sustainable approach starts with clear ownership of the technology itself. 

For important platforms, someone—typically the business owner of the platform—should understand why the organization uses it, what information it handles, who depends on it, and who needs to be involved when something significant changes. That owner does not need to personally evaluate every security, privacy, data, or AI question. Their role is to recognize when a change may matter and bring the right people into the conversation.

Who those people are will depend on the change. A new feature that can access sensitive employee information may require different input from one that connects a project management system to a document repository.  

What matters is having a way to flag meaningful changes and knowing who needs to be involved, when, and why.

Turning Off AI Isn't a Governance Strategy

Faced with a new AI capability, the easiest response may seem to be turning it off.

Sometimes that's the right decision. A feature may introduce risks the organization isn't prepared to manage, provide little business value, or lack the administrative controls needed for responsible use. And sometimes organizations need time to understand a new capability before making it broadly available. 

But "turn off the AI" is unlikely to be a sustainable technology strategy—and sometimes it isn't even possible.

Many embedded AI capabilities are genuinely useful. They can help employees find information, summarize lengthy documents or meetings, analyze data, automate routine work, or make better use of platforms the organization is already paying for. As these capabilities mature, some are also becoming increasingly integrated into core products rather than remaining clearly separate, optional features.  

Organizations need to be able to make intentional choices based on business value, information access, risk, and the controls available. That might mean enabling a capability for some employees but not others, restricting access to sensitive information, testing a feature with a small group before making it broadly available, or deciding that a capability should remain disabled.

The important point is that these should be organizational decisions, not decisions made by default because a vendor enabled—or disabled—a particular setting. 

AI Governance Can't Be Separated from Technology Governance

As AI becomes embedded throughout the technology environment, maintaining separate governance processes for AI and other technology becomes increasingly impractical.

AI policies and governance structures still have an important role. Organizations need shared expectations around appropriate use, accountability, human review, sensitive information, and other issues that are particularly important when AI is involved. 

But an embedded AI feature can raise several organizational questions at once. It may affect who can access information, how data is handled, which systems can communicate with one another, what employees are allowed to do, and how a business process works. Depending on the capability, the same change may have implications for security, privacy, information and data governance, compliance, vendor management, and operations. Those issues are difficult to evaluate effectively in isolation.

Organizations should look for opportunities to incorporate AI considerations into the technology governance they already have. Vendor reviews can include significant AI capabilities alongside security and privacy. Technology inventories can flag platforms with significant AI capabilities in addition to recording product names. Platform owners can understand which significant features are enabled and what information they can access. Existing policies can address AI where it intersects with data handling, security, records management, or acceptable use.

The right structure will depend on the organization. A smaller organization with a relatively straightforward technology environment will need a different approach from a large enterprise with dedicated security, privacy, procurement, legal, data governance, and technology teams. 

What's important is that responsibility doesn't fall into the gaps between those functions.

As the distinction between "software with AI" and other business software becomes less meaningful, organizations need governance that reflects how their technology environment actually works: interconnected platforms, information, people, and business processes that continue to change over time. 

Govern the Change, Not the Label

Organizations will never be able to track every feature added to every cloud platform, nor should they try. That would be unrealistic, unsustainable, and unlikely to produce better decisions. 

But "approved" can no longer mean "fully evaluated forever."

Organizations need a practical way to recognize when a change is meaningful enough to deserve attention, understand what has changed, and involve the right people in deciding what to do about it. 

AI is making this challenge much more visible, but the larger lesson extends beyond AI. Cloud technology will continue to evolve after organizations adopt it.

Good technology governance needs to evolve with it.

Keep Reading

Read next

CTA