One Page Before Your Team Sends Another AI Draft

Your sales rep opens Gmail. Gemini offers to draft a follow-up to a prospect. She accepts, edits two words, and sends it. Your support lead does the same in Outlook. Your account manager uses ChatGPT in a separate tab. None of these workflows are documented. No one agreed on what a good AI-assisted email looks like, who approves it, or when a human needs to rewrite it entirely. The output leaving your company right now reflects three different standards, or no standard at all.
This is not a technology adoption problem. IDC's research on generative AI strategy identifies the barrier as use-case translation — the step between having access to a model and specifying what it does, who checks it, and what good looks like. Firms across G7 countries and Brazil report struggling not with model access but with translating AI use cases into concrete processes with clear roles and oversight. The tool is in the building. The process isn't.
What shadow AI actually costs you
IDC uses the term "shadow AI" for what your team is doing in those Gmail and Outlook sidebars: using AI tools inside informal, undocumented flows. The research identifies three specific failure modes from this pattern. Output quality is uneven because each person applies their own standard. Responsibility is unclear because no one was assigned to review. Oversight gets bypassed because the workflow never required it.
The cost isn't dramatic. No one sends a catastrophic email on day one. The cost accumulates in small ways: a prospect gets a tone that doesn't match your brand, a support reply misrepresents your refund policy, a partner receives a draft that was never meant to go out. Each event is recoverable. The pattern isn't.
The one-page fix, and what it does not fix
IDC's use-case translation guidance points to four components a documented AI workflow needs: the input source, the human reviewer, the output standard, and the approval trigger. For an email drafting workflow, that looks like this.
Input source: the AI receives the thread history and the rep's bullet-point notes. Output standard: the draft matches your brand voice guide and contains no claims about pricing or timelines the rep hasn't verified. Reviewer: the rep reviews before sending; any email to a new enterprise prospect goes to the account lead. Approval trigger: emails referencing contract terms require manager sign-off before sending.
One page. One workflow. The document does not replace your AI policy, your data ethics review, or your infrastructure decisions. IDC's intelligence architecture framing treats data, models, and workflows as a coordinated unit — the one-pager touches only the workflow layer. It won't catch a reviewer who rubber-stamps output they lack the skill to evaluate.
When "not enough governance" becomes an argument against any governance
IDC's own guidance on responsible AI policy identifies sustained investment in infrastructure, skills, and ethics oversight as requirements for genuine governance. A per-workflow template addresses none of that. AI models produce probabilistic outputs, and a fixed output standard won't account for every failure mode a language model introduces. These are real objections.
They prove too much. The shadow AI evidence shows failures occurring at the task level — inside email drafts, not at the policy layer. Teams bypass oversight not because they lack an AI ethics statement, but because no one specified who reviews the output before it leaves. That is the precise problem the one-pager addresses. The argument that per-workflow documentation is insufficient for full governance is correct and irrelevant to the question of whether it's better than nothing. The current state, for most founder-led teams, is nothing.
Start with email drafting, not with strategy
I'd start with the workflow your team uses most, which for most knowledge-work companies is email. Write the four fields on a shared doc: input source, output standard, reviewer, approval trigger. Share it with the people who draft AI-assisted emails. Ask them to flag the first time the standard doesn't fit.
That flag is more useful than the document. It tells you where the standard is wrong, which tells you what the AI is actually doing in your workflow, which is information your current undocumented process will never surface.

Read next

Human-Centered Transformation
Shadow AI Is Already Here
Your employees aren't waiting for IT approval — they're already using AI tools you've never seen. Here's how to surface what's running in the shadows before…
4 min read

Human-Centered Transformation
When Proximity Stops Protecting You from Your Own Team's AI Use
Founders trust small-team closeness to catch problems fast. NSBA and Business.com survey data show employees aren't waiting for that conversation.
3 min read

AI Readiness
Shadow AI Is Already On Your Team
Your team is already using AI you haven't approved. Here's how to find it, assess the real risk, and build lightweight governance that doesn't kill…
3 min read