ITML IT Leadership Q&A Resource Center:
IT AI and Emerging Technology
Return to the main IT Leadership Knowledge Base page
Table of Contents
- How should IT prepare for AI?
- How do I create an AI governance policy?
- How do I manage shadow AI usage in my organization?
- What should IT managers know about AI risk?
- How do I train my team to use AI tools responsibly?
- Will AI replace IT jobs?
- How do I evaluate AI vendors and tools?
- What is an AI acceptable use policy and do I need one?
How should IT prepare for AI?
Preparing IT for AI requires action across several interconnected dimensions: governance and risk management, technical infrastructure and skills, organizational change management, and proactive engagement with how AI will reshape both IT’s own operations and its role supporting broader organizational AI adoption.
Establish foundational AI governance before AI adoption accelerates beyond manageable oversight, including clear policies regarding acceptable AI tool usage, a process for evaluating and approving new AI capabilities before broad deployment, and mechanisms for managing the security and data privacy risks that AI tools, particularly generative AI, can introduce if used without appropriate guardrails.
Invest in understanding your organization’s current AI usage, including likely significant “shadow AI” usage where employees are already using AI tools like ChatGPT or other generative AI services without formal IT approval or oversight. Conducting an honest assessment of actual AI usage patterns, rather than assuming formal policies alone prevent unauthorized usage, provides essential grounding for developing genuinely effective governance and support approaches.
Build technical infrastructure and data foundations that will support AI initiatives your organization pursues, recognizing that effective AI implementation typically requires solid underlying data quality, appropriate data governance, and technical infrastructure capable of supporting AI workloads, whether through cloud-based AI services or on-premises capability depending on your specific requirements.
Develop AI-related skills within your IT team, including both technical skills needed to evaluate, implement, and support AI capabilities, and broader organizational understanding of AI capabilities and limitations that helps IT provide informed guidance to business stakeholders exploring AI opportunities.
Prepare your service desk and support functions for AI-related support needs, since employees using new AI tools will likely require support and guidance, and AI-related issues may present differently than traditional technical support scenarios your team is accustomed to handling.
Engage proactively with business stakeholders exploring AI opportunities, positioning IT as a knowledgeable partner and guide rather than either an obstacle to AI adoption or a passive bystander while business units independently adopt AI capabilities without appropriate technical and risk oversight involvement.
Consider how AI might transform IT’s own operations, including opportunities for AI to improve IT service delivery through capabilities like AI-powered service desk automation, predictive infrastructure monitoring, or code generation assistance for development teams, recognizing that AI adoption within IT itself, not just support for broader organizational AI adoption, represents a significant opportunity area.
Finally, stay genuinely current with rapidly evolving AI capabilities, regulations, and best practices, since this remains an unusually fast-moving area where approaches and available capabilities are changing significantly faster than most other technology domains, requiring more frequent reassessment of your AI strategy and practices than might be typical for more mature, stable technology areas.
How do I create an AI governance policy?
Creating an effective AI governance policy requires balancing appropriate risk management with practical usability, avoiding either excessive restriction that drives AI usage underground or insufficient guidance that leaves the organization exposed to genuine AI-related risks.
Begin by establishing a cross-functional working group including representation from IT, legal, compliance, security, HR, and relevant business stakeholders, since effective AI governance requires perspectives beyond pure technical considerations, including legal and regulatory compliance, employment considerations, and genuine business use case understanding.
Define clear categories of AI usage and corresponding risk levels, distinguishing between lower-risk usage, such as using approved generative AI tools for drafting or brainstorming assistance, and higher-risk usage, such as AI systems making consequential decisions affecting customers or employees, or AI usage involving sensitive data. Different risk categories should have correspondingly different levels of required oversight and approval.
Establish clear data handling guidelines specific to AI tools, addressing what types of organizational data can and cannot be input into AI systems, particularly third-party AI services where data handling and retention practices may not meet your organization’s security and privacy requirements. This is often one of the most immediately practical and important elements of AI governance policy, given genuine risk of sensitive data exposure through inappropriate AI tool usage.
Define an approval process for new AI tool adoption, providing clear guidance on how business units or individuals should request approval for new AI capabilities they want to use, along with reasonable timelines and criteria for evaluation, avoiding either an overly bureaucratic process that drives unauthorized usage or insufficient oversight that allows unvetted tools into your environment.
Address AI-specific risk areas explicitly, including guidance on verifying AI-generated content accuracy given known tendencies toward confident-sounding but incorrect outputs, appropriate human oversight requirements for consequential AI-assisted decisions, and intellectual property considerations regarding AI-generated content.
Incorporate relevant regulatory requirements applicable to your industry and geography, recognizing that AI regulation is evolving rapidly and your policy will likely require regular updates as new requirements, such as the EU AI Act or emerging U.S. state regulations, take effect or as your understanding of applicable requirements matures.
Provide practical training and communication to ensure employees genuinely understand and can apply the policy, rather than creating a comprehensive document that sits unused and unread. Clear, accessible guidance, perhaps supplemented with specific examples relevant to common use cases, tends to be more effective than lengthy, legally dense policy documents that employees are unlikely to genuinely internalize.
Finally, establish a regular review cadence for your AI governance policy, recognizing that this remains a rapidly evolving area where both AI capabilities and regulatory requirements are changing quickly, requiring more frequent policy review and updates than might be typical for more stable, mature governance domains.
How do I manage shadow AI usage in my organization?
Managing shadow AI usage, the unauthorized or unmanaged use of AI tools by employees without formal IT approval or oversight, requires a combination of understanding current usage patterns, providing appropriate approved alternatives, and creating governance that guides rather than simply prohibits AI adoption.
Begin by honestly assessing the scope of current shadow AI usage within your organization, recognizing that some level of unauthorized AI tool usage is extremely likely given the accessibility and genuine usefulness of tools like generative AI chatbots. Understanding actual usage patterns, potentially through anonymous surveys or network monitoring where appropriate and legally permissible, provides essential grounding for developing effective governance rather than assuming formal policy alone has prevented unauthorized usage.
Recognize that shadow AI usage often reflects genuine unmet organizational needs, meaning employees are using unauthorized tools because they provide real value that approved alternatives don’t currently offer. Rather than purely focusing on prohibition, understanding what specific needs shadow AI usage is addressing helps inform more effective approved alternatives or governance approaches that address underlying needs rather than simply blocking access without providing viable alternatives.
Provide clearly approved, well-supported AI tool alternatives that meet legitimate business needs while maintaining appropriate security and data governance standards. When employees have access to genuinely useful, approved AI capabilities, the incentive to seek unauthorized alternatives diminishes considerably compared to situations where no approved options exist for legitimate AI-assisted work.
Implement appropriate technical controls where feasible, such as data loss prevention tools that can help identify when sensitive data might be shared with unauthorized AI services, though recognize that purely technical controls alone rarely fully prevent shadow AI usage, particularly for tools accessed through personal devices or accounts outside direct IT technical control.
Focus governance communication on genuine risk education rather than purely restrictive messaging, helping employees understand specific risks associated with unauthorized AI usage, such as potential data exposure or intellectual property concerns, rather than simply prohibiting usage without adequately explaining the underlying rationale. Employees who genuinely understand risks are often more likely to comply with governance guidance than those who perceive restrictions as arbitrary or poorly justified.
Create accessible channels for employees to request approval for new AI tools they’ve found valuable, ensuring your approval process is genuinely responsive rather than so slow or bureaucratic that employees continue using unauthorized alternatives simply because seeking approval feels impractical or unlikely to yield timely results.
Finally, monitor and iterate on your approach over time, recognizing that shadow AI management is an ongoing challenge requiring continuous attention rather than a problem solved through a single policy announcement or initial technical control implementation. Regular reassessment of usage patterns, employee feedback, and emerging AI tool landscape changes helps ensure your governance approach remains genuinely effective and responsive to evolving organizational needs and risks.
What should IT managers know about AI risk?
IT managers should understand several distinct categories of AI-related risk to provide appropriately informed leadership and guidance as their organizations increasingly adopt AI capabilities, recognizing that AI risk differs meaningfully from traditional IT risk in several important respects.
Data privacy and security risk represents one of the most immediate concerns, particularly regarding what organizational data might be exposed through AI tool usage, especially third-party AI services where data handling, retention, and potential usage for model training may not meet organizational security and privacy requirements. Understanding specific data handling practices of AI tools your organization uses or is considering, rather than assuming standard data protection practices automatically apply, is essential for informed risk management.
Accuracy and reliability risk deserves particular attention, given AI systems, especially generative AI, can produce confident-sounding but factually incorrect outputs, sometimes called “hallucinations.” IT managers should understand appropriate use cases where this risk is manageable through human review and verification, versus higher-risk applications where AI-generated inaccuracy could have significant consequences without adequate human oversight.
Bias and fairness risk is particularly important for AI systems influencing consequential decisions affecting individuals, such as hiring, credit, or performance evaluation applications, where AI systems can inadvertently perpetuate or amplify biases present in training data, potentially creating legal and ethical exposure if not carefully managed and monitored.
Intellectual property risk requires understanding, both regarding potential exposure if AI tools are trained on or incorporate copyrighted material inappropriately, and regarding ownership and usage rights for AI-generated content your organization creates using various AI tools, an area where legal precedent and regulatory guidance continues evolving.
Vendor and third-party risk takes on particular importance for AI capabilities, since many organizations access AI functionality through embedded features in purchased software or dedicated AI service providers, requiring appropriate due diligence regarding these vendors’ AI-specific practices, security measures, and data handling approaches.
Regulatory compliance risk is rapidly evolving, with new AI-specific regulations emerging across various jurisdictions that may impose specific requirements depending on your industry, geography, and specific AI use cases, requiring ongoing attention to a regulatory landscape that continues developing rapidly.
Operational dependency risk deserves consideration as organizations increasingly rely on AI capabilities for various functions, creating potential business continuity concerns if AI services experience outages, significant changes, or discontinuation, similar to but sometimes more acute than traditional vendor dependency risks given the rapidly evolving AI vendor landscape.
Finally, IT managers should recognize that AI risk management requires genuine cross-functional collaboration with legal, compliance, security, and business stakeholders, rather than treating AI risk as a purely technical concern that IT alone can adequately address, given the genuinely multidisciplinary nature of AI-related risks spanning technical, legal, ethical, and business dimensions.
How do I train my team to use AI tools responsibly?
Training your team to use AI tools responsibly requires combining practical skill-building with genuine risk awareness, ensuring team members understand both how to effectively leverage AI capabilities and the specific risks and appropriate boundaries for AI usage within your organizational context.
Begin with clear communication of your organization’s AI governance policy and rationale, ensuring team members understand not just what’s permitted or prohibited, but genuinely understand the underlying reasoning, such as specific data privacy concerns or accuracy risks, which tends to produce more genuine compliance than purely rule-based communication without adequate context or explanation.
Provide hands-on training with your organization’s approved AI tools, helping team members develop genuine practical skill in using these tools effectively for relevant use cases. Simply providing access to AI tools without adequate training often results in either underutilization, where team members don’t leverage genuinely valuable capabilities, or misuse, where team members use tools ineffectively or inappropriately due to inadequate understanding of proper usage.
Address common AI limitations explicitly through concrete examples relevant to your team’s actual work, helping team members develop practical intuition for when AI outputs require careful verification versus when they can be reasonably trusted with lighter review. Abstract discussion of AI limitations often proves less effective than working through specific, relevant examples that team members can directly relate to their actual job responsibilities.
Establish clear guidelines for appropriate human oversight and verification, particularly for AI-assisted work with meaningful consequences if errors occur. This might include specific verification requirements for AI-generated content used in customer-facing communications, financial calculations, or technical documentation, versus more relaxed oversight for lower-stakes internal brainstorming or drafting assistance.
Create a culture of open discussion about AI usage, encouraging team members to share both successes and challenges they encounter using AI tools, rather than creating an environment where team members feel reluctant to discuss AI usage due to excessive restriction or judgment. This open dialogue helps surface both genuine best practices worth sharing broadly and potential misuse or risk areas requiring additional guidance or training.
Provide ongoing education as AI capabilities and organizational policies evolve, recognizing that both the underlying AI technology and your organization’s governance approach will likely continue evolving significantly, requiring periodic refresher training and updated guidance rather than a single onboarding training session assumed to remain sufficient indefinitely.
Model responsible AI usage yourself as a leader, demonstrating appropriate verification practices and thoughtful application of AI tools in your own work, since team members often take cues from observed leadership behavior regarding genuinely expected practices, beyond what formal policy documents alone communicate.
Finally, create accessible channels for team members to ask questions or seek guidance about specific AI usage scenarios that may not be clearly addressed by existing policy, ensuring ongoing support rather than assuming initial training adequately addresses every situation team members might encounter as they increasingly incorporate AI tools into their daily work.
Will AI replace IT jobs?
The question of whether AI will replace IT jobs requires nuanced consideration, since evidence increasingly suggests AI is more likely to transform IT roles substantially rather than eliminate them entirely, though the nature and extent of this transformation will likely vary considerably across different IT specializations and roles.
Certain IT tasks, particularly those involving routine, repetitive, well-defined work, such as basic tier-one help desk support, routine code generation for common patterns, or standard infrastructure provisioning, are likely to see significant AI-driven automation, potentially reducing the total human effort required for these specific tasks considerably. This doesn’t necessarily mean complete elimination of associated roles, but likely means these roles will require different skills, focusing more on handling exceptions, providing oversight, and managing AI systems rather than performing the routine tasks themselves.
More complex, judgment-intensive IT work, including strategic planning, complex problem-solving, nuanced stakeholder communication, and situations requiring genuine creativity or contextual understanding beyond current AI capabilities, seems considerably less susceptible to full automation, at least based on current AI capability trajectories, though this could evolve as AI capabilities continue advancing.
Historical technology transitions provide relevant, if imperfect, precedent, as previous waves of IT automation, from mainframe to client-server computing, and more recently to cloud computing, have consistently transformed rather than eliminated IT roles, typically shifting required skills toward higher-level design, strategy, and oversight functions while automating more routine implementation and operational tasks.
New IT roles will likely emerge specifically focused on AI implementation, governance, and oversight, similar to how cloud computing’s rise created substantial new specialized roles around cloud architecture and operations that didn’t previously exist in the same form. IT professionals who develop genuine AI-related skills, including both technical implementation capability and broader organizational AI governance and strategy understanding, are likely to find significant new career opportunities even as some traditional task categories become increasingly automated.
The overall volume of IT work may not necessarily decrease even as specific tasks become automated, since organizations often expand their technology ambitions and complexity as automation increases efficiency, a pattern historically observed across many previous waves of IT automation and productivity improvement.
For IT managers, the practical implication is preparing your team for meaningful skill evolution rather than either dismissing AI’s transformative potential or assuming wholesale job elimination. Proactively investing in AI-related skill development, helping your team understand how their specific roles are likely to evolve, and fostering genuine adaptability and continuous learning mindset within your team will likely serve your organization and team members better than either complacency or excessive alarm about AI’s employment implications.
How do I evaluate AI vendors and tools?
Evaluating AI vendors and tools requires assessing several dimensions beyond typical software vendor evaluation criteria, given AI-specific considerations around data handling, accuracy, and rapidly evolving vendor capabilities that traditional vendor assessment frameworks may not adequately address.
Assess data handling and privacy practices with particular rigor, understanding specifically how the vendor handles data you input into their AI systems, including whether your data might be used for training their models, how long data is retained, and what security measures protect this data. This is often more critical for AI tools than traditional software, given the potential for sensitive organizational data exposure through AI system interactions.
Evaluate accuracy and reliability for your specific intended use cases, recognizing that AI system performance can vary considerably depending on the specific task and context, meaning generic vendor claims about accuracy may not reliably predict performance for your particular use case. Conducting genuine pilot testing with realistic scenarios relevant to your intended usage provides much more reliable insight than relying purely on vendor marketing claims or generic benchmark performance.
Consider transparency and explainability, particularly for higher-stakes use cases where understanding how the AI system reaches its outputs or recommendations matters significantly. Some AI vendors provide meaningfully more transparency into their systems’ reasoning or decision-making factors than others, which may be an important evaluation criterion depending on your specific use case and regulatory requirements.
Assess vendor stability and viability, given the rapidly evolving and sometimes volatile AI vendor landscape, where some AI-focused vendors may face significant business viability questions or rapid capability or pricing changes compared to more established software categories. Understanding vendor funding, market position, and business model sustainability provides important risk context beyond pure technical capability assessment.
Evaluate integration capabilities and technical requirements, ensuring the AI tool can appropriately integrate with your existing technology environment and that your infrastructure can support any specific technical requirements, such as computational resources for certain AI workloads.
Consider bias and fairness testing, particularly for AI tools involved in consequential decisions affecting individuals, seeking vendor transparency about their bias testing and mitigation practices, and where appropriate, conducting your own testing relevant to your specific population and use case rather than relying purely on vendor claims.
Review regulatory compliance support, understanding how the vendor helps you meet relevant regulatory requirements applicable to your industry and use case, including relevant certifications, compliance documentation, or specific features designed to support regulatory compliance obligations.
Finally, negotiate appropriate contractual protections specific to AI usage, including clear data handling and usage rights provisions, appropriate liability and indemnification terms addressing AI-specific risks, and reasonable flexibility given the rapidly evolving AI landscape, potentially including shorter contract terms or clear exit provisions given genuine uncertainty about how specific AI vendors and their offerings will evolve over coming years.
What is an AI acceptable use policy and do I need one?
An AI acceptable use policy is a formal document that defines how employees within an organization may and may not use artificial intelligence tools and services, providing clear guidance on approved tools, appropriate use cases, data handling requirements, and specific prohibited or restricted usage scenarios. Given the rapid proliferation of accessible AI tools, particularly generative AI, most organizations genuinely need some form of formal AI acceptable use policy rather than relying purely on general IT policies that predate widespread AI tool availability.
The policy typically addresses several key areas: which specific AI tools and services are approved for organizational use, what types of organizational data can and cannot be shared with AI systems, particularly third-party services where data handling practices may not meet organizational security standards, and what level of human review or verification is required for different categories of AI-assisted work.
Without a clear acceptable use policy, organizations face several genuine risks, including potential data privacy or security breaches through inappropriate data sharing with AI tools, inconsistent or ad hoc decision-making about which AI tools are acceptable to use, and potential legal or compliance exposure if AI usage violates relevant regulations without organizational awareness or appropriate governance.
Developing an effective policy requires balancing appropriate risk management with practical usability, since overly restrictive policies often drive unauthorized “shadow AI” usage as employees seek to leverage genuinely valuable AI capabilities despite formal restrictions, while insufficient guidance leaves the organization exposed to preventable risks.
The policy should be developed collaboratively across IT, legal, compliance, HR, and relevant business stakeholders, rather than created purely by IT in isolation, given the genuinely cross-functional nature of AI-related risks and considerations spanning technical, legal, and business dimensions.
Effective communication and training supporting the policy matter as much as the policy document itself, ensuring employees genuinely understand not just the specific rules but the underlying rationale, which tends to produce more genuine compliance than policy documents that exist primarily for compliance documentation purposes without meaningful employee engagement or understanding.
Given the rapidly evolving AI landscape, both in terms of available capabilities and regulatory requirements, an effective AI acceptable use policy requires regular review and updating, likely more frequently than typical for other IT policies, to remain genuinely relevant and effective as both AI technology and organizational usage patterns continue evolving significantly.
For organizations that haven’t yet developed a formal AI acceptable use policy, doing so should generally be considered a near-term priority given the significant likelihood that employees are already using various AI tools, whether formally sanctioned or not, creating genuine risk exposure that a well-developed acceptable use policy can help meaningfully address and manage.
Thinking of becoming an IT Managers? Click here to take our free IT Management Assessment!