AI
AI adoption fails when governance comes too late
Many organizations have moved past the question of whether AI can create value.
The harder question now is whether they can govern AI responsibly while still moving fast enough to remain competitive.
That means deploying AI across teams, customers, and data types in ways that are secure, explainable, and aligned with regulatory expectations.
It is relatively easy to run a pilot, give employees access to a tool, or publish a policy. The difficult part is making AI work safely and consistently in real workflows and customer deliveries.
In practice, responsible AI adoption requires more than enthusiasm. It needs a practical structure for how AI is approved, used, challenged, escalated, and improved over time. This is what makes AI adoption a governance discipline, not just a technology rollout.
“Governance only works when it is close to the day-to-day decisions teams make, because that is where unclear rules can turn into risky shortcuts. At NNIT, we design governance so people can use AI safely, ask questions early, and escalate when something is not understood.”
Emma Skovsted-Andersen, AI Governance Lead, NNIT.
If the safe option is difficult, people will choose another one
One of the most underestimated risks in AI adoption is Shadow AI: the use of tools outside the organization’s approved frameworks. Employees rarely do it to “create risk”. They do it to solve real problems faster: summarizing documents, improve text, generate code, analyze information or save time on repetitive work.
The problem begins when that use happens outside the approved route, where basic questions become difficult to answer: what data was entered, where it was processed, whether customer or personal data was exposed, whether output was reviewed, and who is accountable if something goes wrong.
So restriction alone will not work. If the approved path is unclear, impractical, or too slow, employees will look for alternatives. The task is to make the safe and approved way the easiest way to work.
This is also becoming a regulatory issue. With the EU AI Act applying in phases, organizations will need a clearer view of where AI is used, what risks different use cases create, and how responsibilities are documented.
Approved tools are necessary, but they are not enough
At NNIT, we support responsible adoption through approved AI tools, including Alera and Lumina. This gives employees practical alternatives to open, unmanaged tools and helps ensure AI use fits regulated industries, customer data, and critical business processes.
But approved tools do not solve adoption by themselves. A tool can be approved and still be used poorly. People still need guidance on what information they may enter, which tasks are suitable for AI support, when human review is required, and when a use case needs additional assessment.
This is why NNIT also provides governance and developer guidance that is specific enough to be useful: “Use AI responsibly” is not enough. People need examples, boundaries, and escalation paths.
Governance has to be close to the work (and explainable by design)
NNIT has organized its AI work centrally around a dedicated AI Center of Excellence (CoE). This gives a common direction for responsible AI across business areas, legal considerations, security, IT, and internal tools, so AI becomes a controlled and practical part of how we work, not just a technical possibility.
It also matters for software development, where AI tools are increasingly becoming part of everyday work. As a supplier, NNIT must be able to explain and document how AI is used in customer-related work, how customer data is protected, and how consultants and developers operate within approved frameworks. That requires secure technical setups, clear internal guidance and, in relevant contexts, EU-hosted models, where customer data, prompts, and outputs are not used to train foundation models.
Good intentions are not enough. The core of AI governance is making sure responsible AI use can be trusted, repeated and explained in practice.
The goal is trust that scales
The organizations that succeed with AI will not necessarily be the ones that adopt the most tools the fastest. They will be the ones that customers, employees, regulators, and society are willing to trust. That requires technical capability, but also discipline: clear ownership, approved tools, practical guidance, continuous training, documentation that can withstand scrutiny, and a culture where people ask questions early, before issues become difficult to correct.