H Handrail Lesson ~7 min read
Advanced · Levels 3–4 — locked, not relevant to your firm yet

Keeping Control as AI Scales

As your team moves from using AI as a helper to letting it act more independently, new risks appear that have nothing to do with the technology breaking — they come from growth itself. This module covers three things every cautious organization needs before scaling up: staying compliant and able to show your work, stopping unapproved tools from creeping in, and keeping a human hand on the off-switch for anything AI does on its own.

In one line

Most AI mistakes people worry about — a leaked file, an embarrassing email, a bad decision — happen at small scale, one person, one tool, one moment. But once AI use grows across a team, a new kind of risk shows up: nobody can see the whole picture anymore. Five people might be using five different AI tools nobody signed off on. Nobody can say what data went where. An AI agent might have sent forty emails overnight and nobody checked a single one. This isn't a hypothetical for the future — it's what happens naturally the moment a helpful tool starts working well and word spreads. The good news: none of this requires being technical. It requires the same kind of basic controls you already use for petty cash, keys, or who can sign a contract — a list of what's approved, a record of what happened, and someone who can always pull the plug.

The short version — what to remember
  • Risk doesn't scale evenly with AI use — it changes shape as more tools, people, and autonomous actions enter the picture, so controls need to grow alongside adoption, not after a problem appears.
  • Shadow AI (unapproved tools people quietly adopt) is solved with one simple document: an approved-tool list, checked before new tools touch real work or client data.
  • A basic usage log and a record of staff AI training turns 'can you show us you're using AI responsibly?' from a scary question into a five-minute answer — and increasingly maps to real obligations like the EU AI Act's Article 4 literacy requirement.
  • Once AI starts acting on its own (booking, sending, updating records) rather than just suggesting, the rule 'AI advises, human decides' has to be built into the tool as a pause point, not just followed in spirit.
  • Every autonomous process needs one named person who can hit stop immediately, and a default rule that irreversible actions (send, pay, publish, delete) wait for a human look first.
A real (anonymized) example

A 12-person property management firm set up an AI assistant to handle routine tenant renewal notices — drafting and sending emails about upcoming lease renewals and rent adjustments. It worked well for weeks, so the office manager let it run overnight without checking each message, to save time. One night, a spreadsheet formatting error fed the AI the wrong rent figures for an entire building, and it sent 34 tenants a renewal notice with incorrect amounts — some far too high, some far too low — before anyone saw it the next morning. The fix wasn't to stop using AI: it was to add a pause point (all outgoing tenant emails queue for a five-minute human glance before sending, no exceptions), name one person who could kill the overnight send job, and log every batch that goes out. The same task, with the same AI tool, now runs safely because a human is still the one who decides — just at the moment right before something goes out the door, instead of drafting every message by hand.

Reflect

A few open questions — nothing to trip on

These are to think through, not a test — there's no score and no wrong answer. Jot a line if it helps, then open the note to see what a careful answer usually considers. Nothing is saved or shown to your admin.

Question 1 of 4

Why does risk increase specifically as AI use spreads across a team, not just as a single tool improves?

See what a careful answer considers

A careful answer usually lands on: Because more tools and more people mean nobody has the full overview anymore, and mistakes can compound at scale before anyone notices. The technology doesn't get worse — the visibility does. With scattered tools and users, nobody can see the whole picture, so a small mistake can multiply many times before it's caught.

Question 2 of 4

What is 'shadow AI'?

See what a careful answer considers

A careful answer usually lands on: AI tools being used in the business that leadership hasn't reviewed or approved. Shadow AI is simply unapproved tool use — usually well-intentioned, but risky because nobody has checked what happens to the data typed into that tool.

Question 3 of 4

What's the simplest fix for shadow AI and tool sprawl?

See what a careful answer considers

A careful answer usually lands on: A one-page approved-tool list, with new tools checked before real use. A short, visible list of what's approved — and a habit of checking new tools before they touch real data — closes most of the gap without needing any technical setup.

Question 4 of 4

When an AI agent can take autonomous actions (like sending emails or updating records), what guardrail matters most before it's given a wider leash?

See what a careful answer considers

A careful answer usually lands on: A named person with a working stop-switch, and a pause before irreversible actions like sending or deleting. The core rule 'AI advises, human decides' still applies to agents — it just has to be built in as a pause point before anything hard to undo, plus a real person who can stop the process immediately.

Read the full written lesson (~7 min)

Why Growing Use Changes the Risk

When one person uses one AI tool to draft an email, the risk is small and easy to see. But as AI use spreads through a team — more people, more tools, more tasks handed over — the risk doesn't just add up, it changes shape.

  • You lose the overview. Nobody set out to lose track, but with five people each trying different tools for different jobs, no single person can say anymore what AI is being used for, where, or with what data.
  • Mistakes compound. One wrong email is a fix. A hundred wrong emails sent overnight by an AI tool that was quietly automating a task is a crisis.
  • Some AI starts acting, not just suggesting. Early on, AI writes a draft and a person sends it. Later, an AI tool might send it itself, book something, update a record, or reply to a customer — with a person only checking in occasionally, or not at all. That's a different level of risk, and it needs a different level of control.

This module is about the controls for that later stage — not because your organization has necessarily reached it, but because it's much easier to put guardrails up before you need them than after something has already gone wrong.

Shadow AI: The Tools You Don't Know About

"Shadow AI" simply means AI tools being used in the business that leadership doesn't know about and hasn't approved. It's not usually anyone acting badly — it's someone trying to be helpful and efficient, and grabbing whichever free tool solved their problem fastest.

The risk isn't the enthusiasm. It's that unapproved tools mean nobody has checked: does this tool keep our data? Does it train on what we type into it? Can it be trusted with a client's name, a medical detail, an account number? Every new tool is a new place your information can end up, and without a list, you simply won't know how many of those places exist.

The fix is simple and doesn't require technical skill: an approved-tool list. One page, one list — the AI tools your organization has actually looked at and said yes to, and a plain instruction that new tools get a quick check before anyone uses them for real work. It's the same habit as approving a new supplier before you pay their invoice.

Your Paper Trail: Records, Logging, and Compliance

If a client, an auditor, or a regulator ever asked "which of your decisions involved AI, and how do you know it was used responsibly?" — could you answer in five minutes? For most non-technical organizations today, the honest answer is no. That's the gap this section closes.

Two ideas do almost all the work here:

  • Logging simply means keeping a basic record of what AI tools were used for, when, and by whom — even a shared spreadsheet row per significant use is enough at your size. You're not trying to record everything; you're trying to be able to reconstruct what happened if you ever need to.
  • Records and training obligations are becoming a real, not theoretical, requirement. The EU AI Act, for example, includes a duty (Article 4) for organizations to ensure staff have a reasonable level of AI literacy before using it in the business — and regulators, insurers, and larger clients are increasingly asking to see that an organization takes AI use seriously, not just that it uses AI. Being able to show "here's our tool list, here's our training record, here's our logging" turns a vague worry into a simple, presentable answer.

None of this needs a compliance department. A shared folder with three things in it — your approved-tool list, a simple usage log, and a record of who's completed this training — covers the vast majority of what anyone will ever ask to see.

When AI Starts Acting on Its Own: The Human Stop-Switch

The newest and least familiar risk comes from AI "agents" — tools that don't just answer a question but carry out a chain of actions on their own: reading messages, updating a record, replying to a customer, booking something, moving files. This is Level 4 use: AI doing, not just advising.

This can be genuinely useful — but it removes the safety net of a human reading everything before it happens. The core rule that keeps this safe is unchanged from everything else in this course: AI advises, a human decides — and for anything an agent can do that would be hard to undo (send, pay, publish, delete, promise), that rule has to be built into the tool itself, not just hoped for.

In practice this means three guardrails:

  • A visible pause point. Before an agent takes an action that talks to a customer, spends money, or changes a record permanently, it should stop and show a person what it's about to do — not just log it afterward.
  • A real off-switch. Someone in your organization must be able to stop an autonomous process immediately, without needing IT support or a vendor call. If you can't say who that person is and how they'd do it today, that's the first gap to close.
  • A limited leash to start. New autonomous use should start on low-stakes tasks with a human checking every output, and only earn more independence once it's proven reliable — the same way you'd bring a new employee up to speed.

Four Guardrails You Can Set Up This Week

You don't need a policy binder. You need four short, concrete things, written down and actually followed:

  1. An approved-tool list. One page. What's allowed, what needs sign-off first, who to ask.
  2. A simple usage log. One row per significant use — what tool, what for, who, when. A spreadsheet is enough.
  3. A named person with the stop-switch. One name, written down, who can halt any automated or agentic process today, without waiting on anyone else.
  4. A rule that autonomous actions pause before anything irreversible. Sending, paying, publishing, deleting, or promising something to a customer always gets a human look first, until you've deliberately decided otherwise for a specific, low-risk task.

These four things won't make your organization technical. They'll make it the kind of organization that can say, calmly and honestly, "yes, we use AI — and yes, we control it."

This lesson is written and reviewed by named humans. Content current as of 21 July 2026. See the Trust Center for our review process and AI-assistance disclosure.