New AI Series · All 3 parts Watch free →

GXA® AI Foundation Series · Part 3 of 3

AI Governance for SMBs: Why You Can’t Just ‘Set It and Forget It’

Part 3 of the GXA AI Foundation Series. Jason Knight and GXA CISO Calvin Fuller cover operationalizing AI after go-live: the controls, monitoring, incident response, and review rhythm that keep an AI program accountable.

Free · No signup required Recorded August 28, 2026 | 31 min | Jason Knight & Calvin Fuller

Watch the full session — no form, no email gate. Prefer YouTube? Open it there.

What Part 3 Covers

Most companies treat AI like a project they deploy once. It is a system you operate — closer to onboarding a new team than installing software. Without controls it drifts: shadow tools multiply, costs creep, policies go unenforced, and company data ends up somewhere you cannot get it back. Part 3 of the GXA AI Foundation Series sets out four pillars for running AI after go-live: controls (approved tools with everything else disallowed, sign-in through company accounts, defined data boundaries, enforced acceptable use), monitoring (usage, cost per seat and per token, output quality spot checks, risk flags), incident response (defining what counts as an incident before one happens, who gets the call, contain first and assess second), and a review cadence (monthly operational, quarterly tool and policy, annual strategy — then retire what you no longer use).

Controls

Approved tools, with everything else disallowed. Sign-in through company accounts so usage flows through your existing security stack. Data boundaries so you know where prompts actually go. Acceptable use that is enforced, not just published.

Monitoring

How AI is being used. What it costs per seat and per token. Spot checks on output quality. Risk flags for sensitive data in prompts and unapproved tools on the network.

Incident response

Define what counts as an incident before one happens. Know who gets the call. Contain first, assess second. Document root cause from prompts, agent activity, plug-ins, and API logs.

Review cadence

Monthly operational reviews of usage and cost. Quarterly tool and policy reviews, because the platforms change weekly. Annual strategy review. Then retire what you are no longer using — the fastest way to shrink your risk footprint is fewer tools.

You leave with AI Incident Response Checklist

Session Recap

Part 3, in Writing

AI is a system you operate, not a project you deploy

Most companies treat AI like a one-time deployment. It is closer to onboarding a new team than installing software. Without controls it drifts: shadow tools multiply, costs creep, policies go unenforced, and company data ends up somewhere you cannot get it back.

Pillar 1 — Controls (your healthy habits)

  • Approved tools, with everything else disallowed
  • Sign-in through company accounts so usage flows through your existing security stack
  • Data boundaries so you know where prompts actually go
  • Acceptable use that is enforced, not just published

Pillar 2 — Monitoring (your regular checkups)

  • How AI is actually being used across the business
  • What it costs, per seat and per token
  • Spot checks on output quality
  • Risk flags for sensitive data in prompts and unapproved tools on the network

Pillar 3 — Incident response (the emergency room)

  • Define what counts as an AI incident before one happens
  • Know who gets the call
  • Contain first, assess second
  • Document root cause from prompts, agent activity, plug-ins, and API logs

Pillar 4 — Review cadence

Monthly operational reviews of usage and cost. Quarterly tool and policy reviews, because the platforms change weekly. An annual strategy review. Then retire what you are no longer using — the fastest way to shrink your risk footprint is fewer tools.

What lands on the CEO’s desk

The session sets out the six things that should reach a CEO monthly, in a format that takes 30 minutes to review, and walks through one firm’s AI process that was running $60 to $70 per session before being rebuilt to under $2.

It also draws the line between which parts of an AI program belong to your leadership team and which belong to your IT partner.

Live Q&A

The closing Q&A covers what to do Monday morning, and which standards apply today — including HIPAA, Texas HB 149, and the NIST AI Risk Management Framework.

In This Session

Your Presenters

Jason Knight, AI Advisor to CEOs

Jason Knight

AI Advisor to CEOs

Three decades building, securing, and scaling tech businesses — including a national IT firm he grew to $50M before selling. Now helps CEOs adopt AI the right way: fast where it creates value, controlled where it matters.

Calvin Fuller, Chief Information Security Officer, GXA

Calvin Fuller

Chief Information Security Officer, GXA

A CISSP-certified security leader who builds resilient, business-aligned cybersecurity programs. As a virtual CISO he translates complex security challenges into clear, actionable guidance for leadership teams.

Your Next Step

Book a Complimentary AI Readiness Call

A 30-minute, high-level review of your licenses, spend, and data posture with GXA. You leave with a one-page AI exposure report covering your specific risks, opportunities, and the practical next step.

30 minutes | No cost | No obligation | No sales pitch

Questions? Call us at (972) 630-3323

Prefer to talk now? Call (972) 630-3323

21 Years in Business | SOC 2 Type II Attested | ISO 9001 Certified | CISSP Certified Leadership

Questions

Part 3: Frequently Asked Questions

How do you manage AI after it is deployed?

Part 3 of the GXA AI Foundation Series frames it as four pillars: controls (approved tools with everything else disallowed, company-account sign-in, defined data boundaries, enforced acceptable use), monitoring (usage, cost per seat and per token, output quality spot checks, risk flags), incident response (define an incident before one happens, know who gets the call, contain first and assess second), and a review cadence of monthly operational, quarterly tool and policy, and annual strategy reviews.

What counts as an AI incident, and who handles it?

Define it before one happens. The session’s guidance is to agree what qualifies, name who gets the call, contain first and assess second, and document root cause from prompts, agent activity, plug-ins, and API logs — the same discipline as any security incident, applied to AI.

How often should a business review its AI tools and policy?

Monthly for operations — usage and cost. Quarterly for tools and policy, because the platforms change weekly. Annually for strategy. And retire what you are no longer using: the fastest way to shrink your risk footprint is fewer tools.

What should a CEO see about AI every month?

Part 3 sets out six things that should land on a CEO’s desk monthly, in a format that takes 30 minutes to review, covering how AI is being used, what it costs, and where the risk sits.

Which AI standards and regulations apply to a Texas business today?

The closing Q&A covers what applies now, including HIPAA for organisations handling protected health information, Texas HB 149, and the NIST AI Risk Management Framework as the practical reference for building an AI program.

Can AI costs be reduced after deployment?

Yes — the session walks through one firm’s AI process that was running $60 to $70 per session and was rebuilt to run for under $2, alongside monthly monitoring of cost per seat and per token so drift gets caught early.

Keep Going

All three sessions are free and on-demand. Policy first, then the buying decision, then running it day to day.