Taming generative AI: Why it must be governed first — and differently

Rather than relying on broad AI frameworks or outright bans, organizations should govern generative AI with practical, use-focused controls.

Contributors:
Pranav Rai
AIGP
Legal Counsel
Hitachi Energy
Editor's note
The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.
As the Joker remarks in "The Dark Knight," a dog chasing a car has little idea what to do if it catches it. Something similar can be seen in the early race toward generative artificial intelligence: Enthusiasm raced ahead of any settled view on how the technology should be governed once adopted.
Generative AI slipped into the corporate world through a side entrance. One day, hardly anyone had heard of it. The next, employees everywhere were using ChatGPT to write emails, brainstorm ideas and generate code long before any policy said they could. This sudden, bottom-up adoption has left risk managers in catch-up mode. Their concern is justified. Few technologies compress as many sources of risk into a single act. One prompt can implicate transparency, bias, confidentiality, intellectual property, privacy and accuracy — often simultaneously and usually invisibly.
That imbalance is why generative AI merits priority treatment in governance. It is not the most advanced form of AI, but it is already the most widespread. Most companies are not training models of their own. They are users of systems or models built elsewhere and embedded directly into everyday tasks, often enthusiastically and sometimes unreflectively. In such circumstances, governance cannot sensibly begin with model architecture or training data. It must begin with use.
Not all AI, or generative AI, is the same
Traditional AI systems tend to perform within defined boundaries: detecting fraud, forecasting demand and optimizing logistics. Generative AI is different. It produces novel output, usually in fluent and persuasive language. The danger is not simply that it may be wrong, but that it is difficult to tell when it is.
Even within generative AI, context matters. A public chatbot used for ad hoc drafting is not the same as an enterprise generative AI model embedded in internal systems. Early agentic tools capable of taking actions rather than merely generating text raise the stakes further. Treating all of this as generic "AI" creates governance blind spots. Sensible oversight begins by recognizing that generative AI is a distinct category that warrants tailored controls.
The enterprise reality: Risk is already here
The consequences are no longer theoretical. Well-publicized incidents, from inadvertent data disclosures to regulatory intervention, have arisen from routine workplace use rather than exotic applications. Surveys suggest such cases are neither rare nor confined to the careless fringe. Generative AI risk is not a future concern awaiting scale; it is a present one.
Faced with this reality, some organizations have reached instinctively for comprehensive, enterprise‑wide AI governance frameworks. The instinct is understandable; the result is often less so. Frameworks designed around in‑house system development can become abstract or operationally heavy when the primary exposure lies in dispersed employee use of third‑party tools.
Some organizations responded by banning generative AI tools outright — an understandable attempt to contain risk, but not a sustainable strategy. Blanket bans tend to push the technology into unsanctioned channels, often labeled shadow IT, and forfeit the opportunity to shape its responsible use. In effect, they replace one unmanaged risk with another, underscoring the need for nuanced governance rather than prohibition.
Why 'comprehensive' governance can be the wrong starting point
One response is to reach immediately for a full, enterprise-wide AI governance framework. In principle, that sounds prudent. In practice, it often produces abstraction without control. Many such frameworks are designed for organizations that develop AI systems in house with defined pipelines, technical oversight and clear points of deployment.
For firms whose primary exposure is employees using third-party generative AI tools, such frameworks can become cumbersome or quietly disregarded.
A generative AI-first approach does not imply lower standards. It reflects a judgment about where risk is currently concentrated. Rather than attempting to govern every conceivable AI application at once, it prioritizes immediate points of contact between humans, data and external systems. In practice, this translates into straightforward but enforceable guardrails: clarity about which data must never be entered into public tools, expectations that AI generated outputs are reviewed before use and discipline around which tools are approved for business purposes.
Importantly, this narrow focus remains coherent with broader AI governance principles. It is risk-based governance applied where risk is currently most concentrated.
Risk does not stand still, and governance must not either
Uses that appear benign at first can migrate into more sensitive domains. Tools introduced for drafting or summarization may later be applied to personnel matters, compliance screening or internal assessments, sometimes without a deliberate decision to do so. Beginning with a narrow focus makes such transitions visible. It also helps organizations avoid drifting into uses that, for instance, the EU AI Act treats as high-risk or, in some cases, outright prohibited.
Regulators explicitly anticipate this evolution. The AI Act is structured around a risk-based lifecycle approach: Obligations do not attach to the technology itself, but to how it is used over time.
It follows that obligations shift with context. A general-purpose model may initially raise concerns chiefly for its provider, but once deployed in areas such as employment, access to services or internal oversight, it can impose significant duties on those who use it. Governance is what enables organizations to recognize when that threshold has been crossed, and to demonstrate that escalation was identified rather than reached by default.
Lightweight controls today create visibility into how tools are actually being used, allowing heavier controls to be applied later if needed. The lesson is the same as before: Momentum can outrun foresight. Early guardrails are therefore critical to ensure generative AI does not race ahead of an organization's ability to manage it.
People remain the weakest link
Overly rigid rules applied without understanding can backfire. Effective generative AI governance therefore requires a baseline of AI literacy. Employees should understand that fluent output is not a guarantee of correctness, that prompts may be retained by providers and that asking an AI to think harder does not eliminate bias or hallucination. This is not about turning staff into engineers; it is about enabling informed judgment.
Regulators recognize this, too. The AI Act explicitly expects organizations to ensure an appropriate level of AI literacy among staff involved in the use of AI systems, reflecting the view that governance cannot rely on technical controls alone. Where human judgment remains central, ignorance becomes a source of risk in its own right.
Global signals point the same way
Policy developments reinforce this differentiated treatment. China's Interim Measures for the Management of Generative AI Services impose targeted obligations on providers offering generative AI services to the public, rather than attempting to regulate AI in its entirety. Singapore has taken a similar course, updating its Model AI Governance Framework for Generative AI with guidance directed specifically at generative AI and placing emphasis on proportionality and practical risk management.
Elsewhere, restraint has been equally intentional. India has so far opted against generative AI‑specific or comprehensive AI legislation, favoring a deployment‑first approach that relies on guidance and institutional coordination while allowing governance to evolve in response to observed use and risk. Across jurisdictions, the common thread is an emphasis on use, exposure and sequencing, rather than theoretical completeness at the outset.
Start narrow, and stay in control
The lesson is that governance should follow strategy, and strategy should reflect reality. For most organizations today, generative AI is the only form of AI being used at scale. Beginning there delivers immediate risk reduction while building the institutional habits needed for broader AI governance later. Narrow does not mean shallow. It means sequencing controls to match exposure.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Pranav Rai
AIGP
Legal Counsel
Hitachi Energy



