visibus
Back to the blog

visibus Blog

A request, a directive, a training video - and then ChatGPT. Why that isn't AI governance. Allowed isn't protected.

Fabian Schmid

by Fabian Schmid · June 21, 2026 · 6 min read

A conversation last week left me rattled. The person I was talking to works at a company that takes its IT security genuinely seriously - clear policies, and ones that are actually enforced. I wanted to know how they handle AI there. The answer was surprising, and somehow not, because it wasn't the first time I'd heard it: anyone who wants to use AI submits a request, signs a directive, and watches a training video. After that, they're allowed to use personal AI tools like ChatGPT for work.

Read that last sentence again. The outcome of this entire formal process is official permission to do company work through a personal AI account.

The person I spoke with saw no problem with it. On the contrary - from his point of view, AI was "handled." There's a request, a signature, a training. On paper, everything's clean.

And that is exactly the problem.

A Signature Is Not a Safeguard

The directive says, of course: "Do not upload company data." That sounds like a safeguard. But it isn't. It's a request with a signature.

A rule whose observance depends on every employee, under time pressure, resisting the easiest path every single time is not a safeguard - it's a hope. And we know that hope is misplaced: the 2025 KPMG study shows for Switzerland that more than half of AI users admit to using AI against company policy - for instance, by entering sensitive data into freely accessible tools. Not because there are no rules, but despite the rules.

The temptation is simply too great. The AI is one tab away, the tool is genuinely good, and the deadline is closing in. Have it quickly summarize a candidate's application file. Review an IT architecture diagram. Scan a vendor contract for critical clauses. The moment that noticeably lightens the workload, a sentence in a signed directive loses all its force.

The Difference Between a Rule and a Measure

Here lies the flawed thinking that runs through so many companies: the one gets mistaken for the other.

A rule says what you should do. A measure makes sure the wrong thing can't happen in the first place. A speed limit sign is a rule. A speed bump in the road is a measure. One appeals to discipline; the other works without it.

A request plus a directive plus a training video is a speed limit sign. It creates the reassuring feeling that the matter is settled - and that feeling is exactly what's dangerous. Because it shuts down the more important question before it's even asked: What actually happens to our data, technically, when someone enters it?

What Actually Happens

The moment confidential data lands in a personal account, the following happens - often without anyone noticing:

  • The data leaves the building, uncontrolled. Candidate records, contract clauses, internal architecture - typed into a personal account, often under free-tier terms where the inputs are analyzed to improve the model.
  • No one sees it. You don't know who's using which tool, what data ends up there, or what comes back. There's no point at which it would ever come to light.
  • You can't prove anything. If a data protection incident occurs, you can neither show what happened nor that you took adequate precautions.

And that is exactly what data protection law demands. The revised Swiss Federal Act on Data Protection (FADP) provides for fines of up to CHF 250,000 for intentional violations - and levied against the responsible individual, not some anonymous company account. A directive that forbids uploading yet officially clears access to a personal account protects you, in that moment, not one bit.

Why the Well-Meant Directive Actually Backfires

There's one more point that often gets overlooked. A directive that explicitly permits personal AI accounts shifts the risk from "tolerated" to "approved."

Before, secretly using a personal tool was a gray area - not pretty, but at least not signed off on by the company. With formal permission, the company has explicitly authorized the outflow of data into uncontrolled accounts. "Someone didn't follow the rules" becomes "we officially set it up this way." That isn't less delicate - it's more.

What a Real Official Path Looks Like

In our post on Shadow AI, Luba already made the point: the answer to uncontrolled AI use isn't a ban, but an official path that's better than the secret one. That still holds - with one important refinement: an official path that merely says "use your personal account, but be careful" is not an official path. It's the same gap with a letterhead.

A real official path differs on a single, decisive point: protection doesn't hinge on how employees behave - it's built in technically. That's exactly what we built visibus Chat for:

  • One controlled access point instead of dozens of personal accounts. People get the tool they want anyway - but in one place, under your control.
  • An extra layer for especially sensitive data - the finishing touch. Your data is protected before that already: it runs in a controlled, contractually governed environment and never lands in uncontrolled accounts in the first place. Anyone working with especially sensitive data, or who simply wants an added layer of protection, can switch on automatic anonymization on top - names, addresses, and bank details are detected and replaced before a request ever leaves your instance, without having to fall back on purely local models. It kicks in automatically: no one has to remember it - and no one can forget it.
  • The instance sits in the EU or Switzerland. History and documents stay with you, not on personal US accounts under real names.
  • You see what's going on. Usage, budget, and rules come together in one place - and if it ever comes to it, you can prove you took precautions.

My point isn't that the request and the training are bad. They aren't - they're just half of it. The other half is an environment where the wrong thing technically never gets out in the first place.

The Test for Any AI Rule

If you ask your AI policy only one question, make it this: Does our protection depend on every employee doing the right thing under pressure - or does it hold even when that, for once, doesn't happen?

A directive depends on discipline. A technical mechanism does not.

"Allowed simply isn't protected."

If you want to see what an official AI access point looks like when it isn't built on hope - write to us. A conversation, not a sales funnel.

Your free AI check

In the AI check, we look together at where controlled AI delivers the most value in your company: which tasks and departments benefit right away, which models fit, and what level of data protection you need. You walk away with a clear assessment - no strings attached.

Free and non-binding. An open conversation, no sales pressure.