Ventures & Visionaries Podcast with Mordy Hackel

The Genie’s Out of the Bottle: A Practical AI Governance Starter for Growing Firms

AI is already inside your company. Maybe it came in through a Copilot license, a sales rep's ChatGPT tab, or a clever automation someone in operations built on a Friday afternoon. Either way, the question is no longer whether to govern AI. It's how, and how fast.

Six months ago, most businesses used AI to rewrite a document, summarize a spreadsheet, or pull some research together. Today we're asking it to do real work: remove recurring, time-consuming steps from our processes, connect systems, and act on our behalf. That's where the value is. It's also where the risk is.

Why the old guardrails aren't enough

AI agents are mission-driven. Give one a goal, access to your files, and permission to use tools, and it will pursue that goal, sometimes in ways nobody anticipated. We're dealing with a non-deterministic system interacting with our information, tools, and permissions. That's a world of unknown unknowns.

Yesterday, folder permissions, sensible file names, and a few metadata tags were (maybe) enough. Today they aren't. Two things have become critical:

  • Data classification. If you don't know which information is confidential, regulated, or client-privileged, neither does the AI.
  • Layered defenses. One set of guardrails will eventually fail. Several overlapping ones (access controls, data labels, monitoring, human approval on sensitive actions) either stop a problem or slow it down long enough for someone to notice.

Begin with the end in mind

The most common mistake I see isn't a technical one. It's starting with the tool instead of the outcome. Before you turn anything on, answer five questions:

  1. What are we trying to improve? A repetitive process? Cross-referencing information? Collecting data someone used to gather by hand? Tracking or analytics? Be specific.
  2. What's the upside? Hours saved, errors avoided, faster response to clients. Put a rough number on it.
  3. What could go wrong? Which data does it touch? Who could see the output? What happens if it's confidently wrong?
  4. What does "good" look like? Define the outcome and what "done" means before you build.
  5. Where does a human stay in the loop? Decide which actions always need a person to approve them (sending, paying, deleting, sharing externally).

Only then design the checks and fences.

A starter checklist for leadership teams

You don't need a 40-page policy to begin. For most firms of 10–200 people, this gets you most of the way:

  • Inventory: list the AI tools actually in use, including the free ones people signed up for themselves.
  • Approved tools: pick the ones you'll support, and turn on their business/enterprise data protections.
  • Classify your data: at minimum, label what's public, internal, confidential, and regulated.
  • Right-size access: AI inherits the permissions of the person using it. Clean up over-shared folders first.
  • Human approval: require sign-off for anything that sends, pays, deletes, or leaves the company.
  • Log and review: know what your AI tools are doing, and look at it monthly.
  • Train people: a 30-minute session on what's okay to paste into AI (and what isn't) prevents most incidents.
  • Revisit quarterly: the tools change every few months. Your guardrails should too.

The bottom line

The genie isn't going back in the bottle, and it shouldn't. Used well, AI takes monotonous work off your team's plate and gives them time for what humans do best. The firms that win will be the ones that adopt it deliberately: clear goals, clear boundaries, and a few layers of protection.


Mordy Hackel is the co-founder of KJ Technology, an NYC managed IT and cybersecurity firm that helps growing companies adopt AI securely, and the host of Ventures & Visionaries. Want a second set of eyes on your AI plans? Email mordy@kjtechnology.com.

For more conversations on AI and leadership, listen to our episode with Drew Donaldson on thriving in the AI economy and Nikki Barua on the agentic human.