The Holy Trinity of AI Governance: Why Leadership, HR, and IT Must Align
When people think of shadow AI, the common story is that employees sneak around policy because they want to cut corners. The on the ground truth typical is far from that. Employees rarely rebel against a clear rule. What they do instead is continue operating even if there is a vacuum of information. They'll fill in the blanks with the worst-case assumption, because leadership's public behaviour and the organization's actual, communicated policy don't line up.
I recently spoke with Dr. James Hutson on my podcast, AI Literacy for Entrepreneurs, James is Senior Professor and Director of AI-Enabled Academic Transformation at Lindenwood University in St. Charles, Missouri. He holds two PhDs - the first in art history, the second in artificial intelligence. He has published over 200 studies on AI adoption. We talked a lot about the gap between what leaders think they are conveying through their actions and what employees, educators, students, and others understand about what is allowed and what isn't from a governance perspective.
Perhaps your leadership uses AI openly and enthusiastically, in public, on record. Meanwhile no memo, no training, no manager conversation has ever clarified how that's actually permitted at every level. The safest assumption becomes: don't ask, don't tell, use it quietly if you use it at all.
This is the mechanism behind what James and others have started calling "secret cyborgs" employees quietly using AI to do their jobs faster while telling no one, because the personal risk of disclosure feels higher than the personal benefit of transparency. The organization loses twice: it doesn't get the productivity gains it could be intentionally capturing, and it has no visibility into how AI is actually being used inside its own walls.
Why This Requires Three Groups, Not One
What James calls the Holy Trinity is that AI governance only works when leadership, HR, and IT are visibly and explicitly aligned, not just internally consistent on paper, but saying the same thing publicly and consistently enough that employees actually believe it.
Leadership sets the tone and the permission. If executives use AI publicly, that signals something, whether they intend it to or not. The mistake is in using AI visibly without also saying explicitly who else is allowed to.
HR translates that permission into something an employee can act on without fear. This is the layer that's most often missing entirely in most sizes of organization. A leadership town hall doesn't tell an individual employee what happens to their performance review if they disclose that they use AI to draft all their reports when report creation is 30% of their role. Only HR can close that specific gap, and if HR hasn't said anything, the employee will assume the worst.
IT makes the permission real, or reveals the fiction points. If leadership says AI use is encouraged, but the approved tools are clunky, restricted, or don't actually support the work people need to do, employees will use unapproved tools anyway and just won't mention it. IT's job here is making the sanctioned path usable enough that people don't need a workaround.
Miss any one of the three, and the other two don't add up. Leadership enthusiasm without HR clarity produces exactly fear. HR clarity without IT capability produces compliant employees using bad tools badly or using the wrong ones for their work. IT capability without leadership visibility produces tools nobody cares about.
What Real Alignment Looks Like
Alignment doesn't require a 40-page policy signed off by everyone. It needs three things happening together, deliberately, rather than in isolation.
Leadership needs to pair visible use with visible permission. If an executive talks publicly about using an AI tool, that same communication, or one immediately following it, needs to say plainly who else can, and how.
HR needs a real answer to "what happens to me if I disclose this". Employees need to know, specifically, that using an approved AI tool for an approved purpose will not be held against them, and that answer needs to come from HR directly.
IT needs to make the approved path better than the workaround. If the sanctioned tool is worse than what people can access on their own devices, governance will lose to convenience every time. Make the right way to do it also the easy way to do it.
This is the same territory covered by the Three Fences model of AI Governance that I use with clients, data handling, output review, and access. (Read more on how to set it up here: How to Build an AI Governance Framework That Enables Speed, Not Bureaucracy)
You can hear the full conversation with Dr. James Hutson, including his read on why most AI policies go stale before the ink dries, on EP 279 of AI Literacy for Entrepreneurs.
If you want to see where your own organization's leadership, HR, and IT signals might be misaligned, the NorthLight AI Readiness Audit is a useful place to start mapping that gap. It gives you a structured picture in about 15 minutes. Run the audit now.