AI is already in your company, even if you haven’t formally implemented it: your employees are using it to write reports or prepare files. How can you identify these uses and manage them without stifling innovation? In an opinion piece for *Le Monde Informatique*, Xavier Brunschwig, CEO of Elit-Technologies, outlines the key elements of AI governance: identifying use cases, protecting data, and supporting teams.
Interview conducted by Olivier Coredo for the "Carte Blanche" column in *Le Monde Informatique*, 2026. "Shadow AI" refers to the professional use of artificial intelligence tools without sufficient validation or oversight by the company. Identifying these uses makes it possible to regulate them while supporting innovation.
Five Takeaways from the Interview
1. Start with actual usage
Employees can already use AI tools to prepare files, write reports, or get answers, even if their company hasn’t formally adopted them. As Xavier Brunschwig puts it: “Companies don’t necessarily know whether AI has already been implemented organically and structurally. Yet employees […] already have access to AI tools.” For him, the first step is to become aware of these uses in order to master them.
2. Establish a general framework rather than a rule for each tool
Xavier Brunschwig advises against a blanket ban: users can circumvent restrictions, particularly when using a mobile connection. He recommends establishing a common framework to guide usage, rather than adding security rules to every new tool.
It also confirms that there is no single right answer when it comes to choosing an AI. The goal is also to offer employees solutions that are more useful than those they could use on their own, taking into account their business needs and company data.
3. Conduct an audit, establish a policy, and then oversee it
“The first thing […] is to observe,” explains Xavier Brunschwig. The interview draws a parallel between this approach and cybersecurity: observing what is happening before deciding on protective measures. He describes an audit of usage patterns and data flows to identify potentially exposed data and define an appropriate policy.
The charter then specifies permitted uses and the limits that must be observed. It applies to both employees and executives. In the interview, he draws a parallel between this approach and the objectives of the AI Act, the European regulation on artificial intelligence: to identify the tools used, the work performed, and the documents produced with AI.
Once the policy has been defined, he recommends relying on monitoring platforms developed by software vendors. These platforms recognize AI-related uses and enforce the established rules: authorizing one tool, blocking another, and monitoring incoming and outgoing data.
4. Choose solutions based on the data
A sales representative who submits a set of specifications to an AI, or an HR professional who shares salary information with it, may expose confidential or personal data. These examples illustrate the importance of specifying what data can be used and under what circumstances.
For sensitive data or data subject to contractual obligations, Xavier Brunschwig suggests considering whether it can be moved outside the company’s environment. He also emphasizes the importance of maintaining control over the information that creates the company’s value. This consideration may steer the decision toward private AI solutions, tailored to data control requirements.
5. Support teams through training
Attempts at impersonation can take the form of fake videos or messages using a cloned voice. Xavier Brunschwig recommends training employees to recognize these situations and take the appropriate actions, just as they would with fraudulent emails.
Take Action with Elit-Technologies
Want to know where to start when it comes to managing AI in your company? AI Readiness, the first step in our “AI Maîtrisée” methodology, maps out the AI tools used by your teams and the data they handle to help you define your priorities.
Frequently Asked Questions
“Waiting until you’re under attack to strengthen your cybersecurity is like waiting until there’s a fire to install
to install smoke detectors.”
Companies need to move from a reactive to a proactive approach:
- Advanced monitoring and detection: Use AI to analyze
suspicious behavior in real time. - Automated incident response to limit the impact of attacks.
- Ongoing team training: 95% of cyberattacks succeed by exploiting
human error.
Frequently Asked Questions About AI Governance
How Can Generative AI Be Managed in an SME or Mid-Sized Company?
In his interview with *Le Monde Informatique*, Xavier Brunschwig recommends starting by observing usage patterns, then defining a policy and relying on monitoring tools. Training supports this process.
How can you tell which AI tools teams are using?
Xavier Brunschwig recommends starting with an audit of usage patterns and data flows. This approach helps identify the tools being used and assess which data may be at risk of exposure, so that appropriate rules and protective measures can then be defined.
Should we choose a single AI system for the entire company?
Not necessarily. Xavier Brunschwig points out that there is no single answer. Business needs and data sensitivity guide the choice of solutions; a comprehensive framework helps support their use.