DECISION BRIEF 14 | TRUST, RISK AND DECISION INTEGRITY | 1 SEPTEMBER 2026
AI Policy: What CEOs Should Permit, Monitor, Prohibit
A useful AI policy should not begin with a list of approved tools. It should define which data, decisions, and actions employees may expose to AI, which uses need monitoring, and which uses remain prohibited.
A blanket ban drives useful work outside visibility. Unrestricted access transfers risk to employees who cannot set enterprise risk appetite. The CEO should establish three policy zones, then delegate controls, training, and monitoring to named owners.
Decision Brief 14 | Evidence reviewed 1 September 2026 | Scope: Indonesia and Southeast Asia, informed by global evidence

Key evidence signals
The evidence supports a risk based policy, not a tool list. Unauthorized AI can increase exposure, while global and regional frameworks already expect organizations to define acceptable use, accountability, and internal controls.
| Signal | Leadership implication | Scope and limitation |
|---|---|---|
| 1 in 5 | IBM reported that one in five studied organizations experienced a breach linked to shadow AI. | The 2025 study covers organizations in a global breach research sample. It is not a prevalence estimate for all companies or for Southeast Asia. Source: IBM, 30 July 2025. |
| 37 percent | Only 37 percent of the studied organizations had policies to manage AI or detect shadow AI. | This is a global benchmark from breached organizations, not a target for one company. Source: IBM, 30 July 2025. |
| 670,000 US dollars | Organizations with high shadow AI use had average breach costs 670,000 US dollars higher than those with low or no shadow AI. | The result is an association within the study. It does not prove shadow AI alone caused the entire cost difference. Source: IBM, 30 July 2025. |
| Internal policy expected | Indonesia's Ministerial Circular Number 9 of 2023 states that relevant businesses and electronic system providers should make and apply internal policies on data and AI ethics. | The circular is ethical guidance and sector context, not a substitute for legal advice or a complete compliance program. Source: Komdigi, 19 December 2023. |
Direct answer
Permit low risk use with public or approved data. Monitor use that touches internal data, customer impact, regulated processes, or material decisions. Prohibit use involving secrets, irreversible actions, deceptive content, unapproved autonomous access, or decisions that cannot receive accountable human review.
An AI policy should follow the work, not the brand name of the tool. A consumer chatbot and an enterprise assistant can create different risks, but either can become unsafe when the user enters restricted data or relies on an answer without verification.
The decision question
What workplace AI use should a CEO permit, monitor, or prohibit?
This is a leadership question because the answer sets the company's risk appetite, speed of adoption, accountability, and operating boundaries. Technology teams can implement controls. They should not decide alone which business decisions may be delegated or which customer harms the company is prepared to accept.
Point of view
The objective of an AI policy is governed adoption. It is not maximum restriction and it is not maximum access.
The best policy makes safe use easier than hidden use. Employees should have a clear approved path for ordinary productivity, a review path for higher risk work, and an unambiguous stop line for unacceptable uses. Every exception should have an owner, a reason, an expiry date, and evidence that can be audited.
Thought process
A sound AI policy starts with data and consequences, then moves to tools and controls. This sequence protects business value while keeping accountability visible.
- Identify the work employees are trying to improve.
- Classify the data, identity, system access, and external effect involved.
- Assess whether the output can be reviewed and the action can be reversed.
- Place the use in a permitted, monitored, or prohibited zone.
- Assign a business owner and a control owner.
- Instrument approved use and review exceptions regularly.
This approach treats value creation, adoption, data readiness, workflow redesign, governance, and workforce behavior as one system. It avoids the common mistake of writing a legal policy that employees cannot apply to daily work.
The legacy assumption being challenged
A conventional AI policy assumes that IT can control use by blocking unapproved websites and applications. That assumption no longer matches how AI enters work.
AI now appears inside browsers, office software, search, customer platforms, developer tools, meeting products, file systems, and mobile applications. Employees may also connect tools through personal accounts, browser extensions, application programming interfaces, or automated workflows.
A blocked domain can reduce one access path. It cannot answer whether an employee may summarize a customer complaint, generate a board memo, evaluate a candidate, change a price, or trigger a payment. Those are policy decisions about data, judgment, and authority.
What AI changes
AI changes the speed, scale, and agency of ordinary software use. A single prompt can move sensitive context outside the company, and an agent can turn a weak answer into a business action.
Five changes matter:
- Information leaves through new routes. Prompts, uploaded files, connectors, browser history, retrieval systems, and logs can contain confidential or personal data.
- Outputs can look more certain than the evidence. Fluent language can hide missing context, weak sources, or fabricated details.
- Use spreads before procurement catches up. Employees can start with free or personal accounts before a contract, security review, or data processing agreement exists.
- Agency raises the consequence. An assistant proposes. An agent may send, buy, change, approve, or publish.
- Control must follow the workflow. A safe model can still be used in an unsafe process, while a higher risk tool may be acceptable inside a narrow, monitored workflow.
AI can help classify prompts, detect restricted data, log usage, compare outputs, and identify unusual access. It cannot set risk appetite, decide acceptable customer harm, approve exceptions, or own the consequence of a wrong business decision. Those remain human leadership responsibilities.
Why a blanket ban usually fails
A blanket AI policy can reduce visible use while increasing hidden use. It also prevents the company from learning which workflows deserve an approved alternative.
Cisco's security guidance describes shadow AI as employee use of third party AI without security oversight. The same guidance argues that blocking all AI is increasingly unrealistic because AI is being embedded across applications. Cisco is a technology vendor, so this is operational guidance rather than independent prevalence evidence. The underlying management implication remains useful: unmet demand seeks another route.
The stronger response is to pair restrictions with an approved path. If employees need summarization, drafting, coding, analysis, or search, the company should provide a controlled option for low risk work and a clear escalation route for sensitive work.
Three policy zones
The policy should divide use by consequence. A short list of tools will age quickly, while data sensitivity, decision impact, and reversibility remain durable criteria.
Zone 1: Permit
Permit use when the data is public or approved, the task has low external impact, and a person remains responsible for checking the result.
Examples include brainstorming from public information, rewriting nonconfidential text, summarizing approved internal material inside an enterprise environment, or generating a first draft that will receive normal review.
Minimum conditions:
- Use an approved account or environment.
- Do not enter restricted data.
- Check factual claims and citations.
- Keep a named human owner.
- Follow copyright, privacy, and recordkeeping requirements.
Zone 2: Monitor
Monitor use when internal data, customer impact, regulated work, material recommendations, system access, or repeated automation is involved.
These cases may create value, but they need stronger evidence and controls. Examples include customer service recommendations, contract analysis, workforce decisions, pricing support, financial forecasts, code that reaches production, or an agent that can read business systems.
Minimum conditions:
- A business owner states the expected value.
- Data and access are classified.
- The model, provider, and retention terms are reviewed.
- Human review is defined before deployment.
- Logs, evaluation, incident reporting, and rollback are available.
- The use is reassessed when the model, workflow, or consequence changes.
Zone 3: Prohibit
Prohibit use when the action creates unacceptable harm, evades accountability, exposes secrets without authorization, or cannot be reversed safely.
Examples include entering credentials or highly restricted information into an unapproved service, creating deceptive impersonation, making a final employment or credit decision without accountable review, bypassing security controls, or allowing an unapproved agent to execute payments or publish externally.
The prohibited list should be short, specific, and tied to consequences. Vague language such as use AI responsibly leaves employees to guess where the company draws the line.
Options and trade offs
The CEO has three broad policy choices. A risk based policy offers the best balance when the company can provide approved tools, named owners, and monitoring.
| Option | Strategic advantage | Material trade off | Best use |
|---|---|---|---|
| Blanket restriction | Fast rule and low initial policy complexity | Hidden use, lost learning, and weak adoption path | Temporary containment during a specific incident or when basic controls do not exist |
| Unrestricted experimentation | Fast learning and low employee friction | Data leakage, inconsistent quality, unclear accountability, and uncontrolled agents | Narrow sandbox with synthetic or public data |
| Risk based policy | Safe use can scale while higher risk work receives oversight | Requires classification, approved access, training, monitoring, and exception management | Default enterprise posture |
Decision rights
A workable AI policy requires the CEO to decide risk appetite and prohibited outcomes. Implementation belongs to a cross functional operating group with clear ownership.
- CEO decides: Risk appetite, prohibited outcomes, accountability model, and the executive owner.
- Board or risk committee oversees: Material customer, legal, financial, workforce, and reputation exposure.
- CIO and CISO instrument: Approved access, identity, data controls, logging, monitoring, and incident response.
- Legal and privacy leaders interpret: Applicable obligations, contracts, consent, records, and cross border data issues.
- CHRO equips: Training, employee guidance, disciplinary clarity, and role redesign.
- Business owner proves: Use case value, human review, output quality, and operating impact.
- Procurement verifies: Provider terms, data use, retention, audit rights, subcontractors, and exit support.
- Employees comply and report: Approved use, errors, unexpected output, and suspected exposure.
The CEO should stop a deployment when ownership is unclear, restricted data can escape, an action cannot be reversed, or no one can explain how a wrong output will be detected.
The decision threshold
Within an AI policy, a use case should move from experimentation to production only when value, data boundaries, decision rights, evidence, monitoring, and recovery are all explicit.
Use six checks:
- The business outcome and owner are named.
- Data and system permissions are classified.
- The output or action has an accountable human review.
- Quality and risk are measured on representative cases.
- Logs, incident reporting, and rollback work.
- An exception or stop authority is named.
If one check is missing, keep the use in a sandbox, narrow its permissions, or stop it. Approval should follow evidence, not enthusiasm.
A smallest credible 30 day test
Pilot the policy in one business unit before imposing it across the company. The objective is to reduce hidden use while preserving useful adoption.
Days 1 to 7: Discover real use
Survey the unit, review available access signals, and interview employees about the work they are trying to improve. Record the tool, data, workflow, frequency, owner, external effect, and reason for use. Do not begin with punishment. Hidden behavior will stay hidden if discovery feels like an investigation.
Days 8 to 14: Classify and provide alternatives
Place each use in the permitted, monitored, or prohibited zone. Provide an approved route for common low risk tasks. For higher risk work, assign a business owner, control owner, and review condition.
Days 15 to 23: Instrument the policy
Enable access controls, data protection, logging, evaluation, training, incident reporting, and a simple exception process. Test whether an employee can understand the rule without calling legal or security.
Days 24 to 30: Review evidence
Compare discovered use, migration to approved tools, blocked high risk actions, incidents, time saved, output quality, employee comprehension, and unresolved exceptions.
Success conditions:
- At least 90 percent of identified recurring use is classified.
- Common low risk work has an approved path.
- High risk access and data flows have named owners.
- Employees can classify representative scenarios correctly.
- No critical incident or uncontrolled irreversible action occurs.
Failure conditions:
- Employees move work to personal accounts or unobserved channels.
- Approved tools cannot perform the work that creates demand.
- Exceptions accumulate without owners or expiry dates.
- Monitoring collects more personal data than the risk justifies.
Stop conditions:
- Restricted data is exposed to an unapproved service.
- An AI system takes an irreversible action outside approved authority.
- The pilot creates material customer, legal, safety, or workforce harm.
Testable hypotheses
The policy should be judged by behavior and risk reduction, not by the number of pages in the document.
- Providing an approved low risk path will reduce recurring use of personal AI accounts.
- Scenario based guidance will improve employee classification accuracy more than a tool list.
- A named exception owner and expiry date will reduce permanent exceptions.
- Monitoring higher risk workflows will produce more useful control evidence than monitoring every prompt.
Implications for decision makers
The AI policy is an operating model choice. It determines how quickly useful work can scale and where accountability sits when AI fails.
For the CEO, the priority is risk appetite and decision rights. For the board, it is oversight of material exposure. For technology and security, it is visibility and control. For business leaders, it is proof of value and review quality. For employees, it is a rule that can be applied without guessing.
The policy should be reviewed when models gain new capabilities, tools add connectors or agents, a new regulation applies, an incident occurs, or a workflow moves from advice to action. A yearly review alone is too slow for a changing operating environment.
Frequently asked questions
Should a company ban public AI tools?
A company should prohibit restricted data and high impact use in unapproved public tools, but a universal ban is rarely a complete operating model. Provide an approved low risk alternative and monitor the workflows where consequence is higher.
Who should own the AI policy?
One executive should be accountable, but no single function can operate the policy alone. Technology, security, legal, privacy, HR, procurement, and business owners need explicit responsibilities.
Is a list of approved AI tools enough?
No. A tool can be acceptable for public drafting and unacceptable for restricted customer data or an irreversible action. The policy must address data, permissions, decisions, review, and recovery.
How often should the policy be reviewed?
Review it at least quarterly during rapid adoption and whenever a model, workflow, regulation, or incident changes the risk. High impact uses need continuous monitoring rather than a calendar review alone.
Evidence ledger
| Claim | Evidence | Date | Limitation |
|---|---|---|---|
| Shadow AI was linked to one in five breaches in the studied organizations, while only 37 percent had relevant policies. | IBM 2025 Cost of a Data Breach release | 30 July 2025 | Global breach research sample, not an estimate for all companies or Southeast Asia. |
| High shadow AI use was associated with 670,000 US dollars higher average breach cost. | IBM 2025 Cost of a Data Breach release | 30 July 2025 | Association does not establish a single cause. |
| Organizations should establish transparent acceptable use policies and ongoing monitoring for generative AI. | NIST AI 600 1, Generative AI Profile | 26 July 2024 | Voluntary United States framework designed for cross sector use. |
| Relevant Indonesian businesses and electronic system providers should make and apply internal policies on data and AI ethics. | Komdigi Ministerial Circular Number 9 of 2023 | 19 December 2023 | Ethical guidance, not legal advice or a complete compliance regime. |
| ASEAN has regional AI governance guides, a Responsible AI Roadmap, and an AI Safety Network. | ASEAN Digital Outlook 2026 | 5 August 2026 | Regional policy context. Implementation differs by country and sector. |
| Enterprise AI use is moving deeper into workflows. | OpenAI enterprise reports based on deidentified usage data and worker research | 12 August 2026 | Vendor and customer data may not represent all companies. |
Source notes
Evidence was reviewed on 1 September 2026. Quantitative claims are kept within their original scope. Company and vendor evidence is labelled, and no global benchmark is presented as an Indonesian prevalence estimate.
- IBM, 2025 Cost of a Data Breach release
- NIST, Generative Artificial Intelligence Profile
- NIST AI 600 1 PDF
- Komdigi, Ministerial Circular Number 9 of 2023
- ASEAN Digital Outlook 2026
- OpenAI, From assistance to execution
- Cisco, Securing AI with Cisco AI Defense
Continue Reading
Continue with the briefs that turn policy into control, workforce design, and accountable decisions.
- AI Agent Security: Three Controls Before Granting Autonomy
- AI Workforce Strategy: Redesign Tasks Before Cutting Jobs
- The CEO Decision Making Framework
- Work With Me
About the author
Antovany Reza is the founder of CEO Decision Lab. He writes about AI, digital transformation, market building, governance, and executive decision making in Southeast Asia.
Discuss the decision
If your organization is deciding what employees may do with AI, the useful question is not which tool to ban. It is which data, decisions, and actions require a clearer boundary.
Discuss an AI policy or governance decision
Language version
Baca versi Indonesia: Kebijakan AI Perusahaan: Diizinkan, Dibatasi, atau Dilarang?