GXA® AI Foundation Series · Part 1 of 3
Your Employees Are Already Using AI. Have You Built the Roads?
Part 1 of the GXA AI Foundation Series. George Makaye and Jason Knight cover the governance, technical, and people foundations that have to exist before a business deploys AI — and the parts leadership cannot delegate.
Watch the full session — no form, no email gate. Prefer YouTube? Open it there.
What Part 1 Covers
AI already entered your business through your employees, not through a purchase order. Part 1 of the GXA AI Foundation Series lays out the foundation that has to exist first: a governance layer (an enforced acceptable use policy, approved tools and risk tiers, human oversight on decisions AI cannot make alone), a technical layer (clean and classified data, data loss prevention, AI interaction protocols, a usable incident process), and a people layer (training before employees figure it out themselves). Leadership signs and enforces the policy, funds the infrastructure, formally accepts accountability for AI outcomes on the risk register, and mandates training. Employees cannot build that themselves.
Leadership. The leader signs and enforces AI policy, funds the infrastructure, formally accepts accountability for AI outcomes on the risk register, and mandates training. Employees use approved tools well, follow the policy, report problems, and champion AI in their departments. Drivers do not build roads.
Three layers: governance (acceptable use policy, approved tools, risk tiers, human oversight), technical (classified data, DLP and compliance monitoring, AI interaction protocols, an incident process your team will actually use), and people (training before rollout).
The session takes that question directly in the Q&A, including whether an 8-person company needs AI governance. The scale of the controls changes with headcount; the need for someone to formally own AI outcomes does not.
One question: who in your organization has formally accepted accountability for AI outcomes? If nobody can answer it, that is the first gap to close.
Session Recap
Part 1, in Writing
The village and the self-driving cars
George opens with the village he grew up in, in western Kenya: narrow paths, carts, donkeys, no road signs, and a system in perfect balance for the technology it had. Then imagine a fleet of self-driving cars arriving one ordinary morning.
That is what is happening inside most businesses right now. Neither the village nor your current processes are wrong. The problem is what happens when the tools change and the infrastructure does not.
Where things stand
Employees are not doing anything wrong. They are doing what any resourceful employee does: using ChatGPT on their phones, pasting client proposals into free AI tools, and using AI features their CRM switched on by default six months ago. The figures cited in the session:
- ✓ 75% of employees use AI for work at least weekly
- ✓ 60% do it on personal accounts with no company controls
- ✓ 1 in 3 have entered sensitive data into a free AI tool
Who builds the roads
Drivers do not build roads. The session draws a hard line between what leadership owns and what employees own.
Leadership signs and enforces AI policy, funds the infrastructure, formally accepts accountability for AI outcomes on the risk register, and mandates training. Employees use approved tools well, follow the policy, report problems, and champion AI in their departments. You cannot delegate the roads to the drivers.
The three layers of AI readiness
Governance: an acceptable use policy that defines what is allowed and what happens when it is not, a governance model covering approved tools, risk tiers, and which opportunities get pursued first, and human oversight on decisions AI is not permitted to make alone.
Technical: clean, classified, categorized data, because garbage in and garbage out is far more punishing with AI. Data loss prevention and compliance monitoring as the enforcement backstop. AI agent interaction protocols. An incident response process your team can actually use to report a problem.
People: nobody hands out driver’s licenses without driver’s ed. Train the team on how to use AI safely in your environment before they go and figure it out themselves.
The consultants selling you the car and leaving
The session also covers the AI consultancy pitch growing businesses are now fielding: $30,000 to $40,000 a month retainers scoped as “we will build cool stuff for you,” with no infrastructure, governance, or operating model behind the work.
Live Q&A
Audience questions covered in Part 1:
- ✓ Whether an 8-person company needs AI governance at all
- ✓ AI-enabled attackers and prompt injection
- ✓ What to do about staff already working on personal ChatGPT accounts
- ✓ Whether the EU AI Act reaches US businesses
- ✓ AI features bolted into SaaS tools you already pay for
In This Session
Your Presenters
George Makaye
President & CEO, GXA
CISSP-certified cybersecurity leader and GXA’s CEO. For more than two decades he has helped growing businesses use technology, security, and strategy to drive performance, and today sets the vision for GXA’s IT, security, and AI programs.
Jason Knight
AI Advisor to CEOs
Three decades building, securing, and scaling tech businesses — including a national IT firm he grew to $50M before selling. Now helps CEOs adopt AI the right way: fast where it creates value, controlled where it matters.
Your Next Step
Book a Complimentary AI Readiness Call
A 30-minute, high-level review of your licenses, spend, and data posture with GXA. You leave with a one-page AI exposure report covering your specific risks, opportunities, and the practical next step.
Prefer to talk now? Call (972) 630-3323
Questions
Part 1: Frequently Asked Questions
Who is responsible for AI governance in a small or midsize business?
Leadership. In Part 1 of the GXA AI Foundation Series, the responsibility split is explicit: the leader signs and enforces the AI policy, funds the infrastructure, formally accepts accountability for AI outcomes on the risk register, and mandates training. Employees use approved tools well, follow the policy, report problems, and champion AI in their departments. Governance cannot be delegated to the people using the tools.
What needs to be in place before a business rolls out AI?
Three layers. Governance: an enforced acceptable use policy, a governance model covering approved tools and risk tiers, and human oversight on decisions AI is not permitted to make alone. Technical: clean, classified data, data loss prevention and compliance monitoring, AI agent interaction protocols, and an incident response process the team will actually use. People: training on safe AI use in your own environment before rollout.
How many employees are already using AI without approval?
The figures cited in Part 1: 75% of employees use AI for work at least weekly, 60% do it on personal accounts with no company controls, and 1 in 3 have entered sensitive data into a free AI tool. AI arrived in most businesses through employees rather than through a purchase decision.
What should a CEO do about staff already using personal ChatGPT accounts?
It is one of the audience questions answered live in Part 1. The framing throughout the session is that employees using AI on personal accounts are behaving resourcefully, not maliciously — the fix is approved tools, a policy with consequences, and training, not a ban that pushes usage further out of sight.
Does the EU AI Act apply to US businesses?
Part 1 takes this question directly in the Q&A, alongside AI-enabled attackers, prompt injection, and the AI features vendors have switched on inside SaaS tools businesses already pay for.
Keep Going
All three sessions are free and on-demand. Policy first, then the buying decision, then running it day to day.