Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What do organisations get wrong about ChatGPT-style AI…
Governance, Ownership & Risk

What do organisations get wrong about ChatGPT-style AI governance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: Governance, Ownership & Risk

They focus on acceptable use and content control while ignoring execution authority. That model may work for casual generative AI use, but it does not govern systems that can enrich alerts, trigger containment, or move data between tools. Governance has to follow the action path, not just the prompt.

Why teams misread ChatGPT-style governance

Organisations often treat ChatGPT-style governance as if the main problem were unsafe text, when the real issue is delegated action. A chatbot that only drafts language is one thing; a system that can query tools, enrich tickets, trigger containment, or transfer data is a different control problem. Once execution exists, governance has to cover access, approvals, logging, and downstream effects, not just acceptable use and prompt content. For a broader governance lens, NHI Management Group points practitioners to the NIST AI Risk Management Framework as a useful reference point.

Many teams also underestimate how quickly “harmless assistant” use turns into embedded workflow authority. The governance boundary moves from user wording to system permissions, integration scope, and who can authorise the action path. In practice, many security teams encounter this only after an AI workflow has already been allowed to act inside a production process, rather than during the original approval.

How governance should track action, not just output

Good governance starts by asking what the system can do, not only what it can say. If an AI tool can only draft a response, the control set may centre on content review, human approval, and acceptable-use rules. If it can take a case note, enrich it with external data, change a ticket status, or call another service, then the control boundary expands into identity, authorisation, auditability, and failure handling. That is the practical difference most organisations miss: output governance and execution governance are related, but they are not interchangeable.

For ChatGPT-style systems, the most important design choice is whether the model is advisory or operational. Advisory systems can be evaluated for accuracy, tone, and data leakage. Operational systems need stronger controls around tool permissions, step-up approval, scoped access tokens, and traceable decision paths. That is especially important when the model sits between people and systems, because the model may become a routing layer for actions the original requester never directly performs.

  • Advisory use needs review and content filtering.
  • Operational use needs permission boundaries and audit logs.
  • Cross-tool actions need clear ownership of the workflow.
  • Any data movement needs retention and classification rules.

This is also where governance documents often become stale. A policy that only bans certain prompts can look strong while leaving a connected workflow free to act with broad access. NIST’s NIST AI 600-1 Generative AI Profile is useful here because it pushes organisations to think about how generative AI is deployed and managed in context, rather than only how users phrase requests. Where that operational context is absent, the governance model breaks down as soon as the system is allowed to do more than draft text.

Where the simple chatbot model stops working

Tighter governance often increases workflow friction, requiring organisations to balance speed against control. That tradeoff is real, especially where teams want rapid automation but still need evidence that an AI action was authorised, bounded, and reviewable.

One edge case is the internal assistant that starts as a summariser and later gains tool access. The original approval may still describe it as low risk, but the operational reality has changed. At that point, the question is no longer whether the model can generate unsafe content. It is whether the system can now reach sensitive data, trigger side effects, or create an approval bypass. Another common boundary issue is mixed-use systems, where one interface supports both casual chat and privileged operations. Governance must follow the highest-risk capability, not the most common use case.

There is also an important consensus gap in the industry: many vendors and teams still describe governance in terms of prompts, guardrails, and content policy, while practitioners responsible for production systems increasingly treat execution scope as the decisive factor. NIST’s broader ai governance guidance and the EU AI Act both reinforce that oversight should reflect actual system use, accountability, and impact, not just visible output.

Where teams ignore that distinction, they end up governing the conversation while leaving the action path under-controlled.

Risk and Threat Considerations

The material risk is not merely harmful or inaccurate AI output. The greater exposure is unauthorised action through a system that is trusted to operate across tools, data sets, or workflows. Once a ChatGPT-style interface is allowed to execute, it can become a control plane for unintended data movement, privilege misuse, or automation errors with real operational consequences.

Failure mechanism: Organisations often grant broad tool access to an assistant without matching approvals, scoping, or logging to the new capability. That creates a trust boundary gap where a prompt, a malformed instruction, or a mistaken workflow design can cause the system to act beyond intended authority.

Impact: Sensitive data can be exposed, containment actions can be triggered incorrectly, tickets or cases can be altered without oversight, and the organisation may lose the ability to explain who authorised the action and why.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST AI 600-1 and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 and EU AI Act define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERN — GovernDirectly addresses AI governance, accountability, and oversight of deployed AI systems.
Recommendation — Define decision rights and accountability for each AI use case before granting operational authority.
NIST AI 600-1GenAI Profile — Generative AI ProfileFits generative AI deployment controls where output risk and operational context must both be managed.
Recommendation — Apply generative-AI-specific risk controls to the full deployment context, not just the prompt.
ISO/IEC 42001:2023A.5 — AI system managementRelevant to organisational AI management systems and governance processes for AI use.
Recommendation — Embed AI use-case governance into the organisation’s management system and review it as capabilities change.
EU AI ActArticle 9 — Risk management systemApplies to AI risk governance where system behaviour and impact require ongoing controls.
Recommendation — Maintain a documented risk-management process that follows the AI system’s actual functions and impacts.
NIST CSF 2.0GV.OC-01 — Organizational ContextRelevant for aligning AI use with organisational mission, dependencies, and business context.
Recommendation — Set AI governance based on the operational context and business purpose of each deployment.

Practitioner Guidance

What to prioritise: Classify each AI use case by execution authority before you classify it by content risk. If the system can only generate text, review, filtering, and user policy may be enough; if it can touch tools or data, treat it as an operational control issue with explicit ownership.

What to verify: Confirm the exact actions the system can take, which identities it uses, what data it can reach, and where a human must approve the next step. Many teams over-trust the visible chat interface and under-document the hidden permissions behind it.

Common mistake: Writing policy around acceptable prompts while leaving workflows, tokens, and tool permissions unchanged. That approach creates the appearance of governance without constraining the action path that actually creates risk.

Practitioner takeaway: If the AI can only talk, govern the conversation; if it can act, govern the workflow, because the control failure usually appears where execution was assumed to be “just an extension of chat.”

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org