Skip to content

AI Compliance: What HR, Legal, and IT Need to Agree On Before You Roll It Out

Before rolling out AI at your company, HR, Legal, and IT must each own distinct responsibilities and align on a shared governance framework. Without that coordination, employees end up using unauthorized tools, sensitive data flows into public AI systems, and legal exposure grows across all three departments simultaneously -- with no one catching it before it costs you.

 

The meeting that should happen before your AI rollout rarely does.

HR is in the corner reviewing bias risks in your new hiring algorithm and figuring out what disclosures employees are owed. Legal is parsing vendor contracts and data processing agreements. IT is assessing security configurations and access controls. Each department is working the problem -- just not the same problem, and definitely not together.

That misalignment has a price. Only 38% of organizations have formal, comprehensive AI policies in place -- and 25% have no AI policy at all.1 Meanwhile, 78% of employees bring their own AI tools to work without IT approval.2 The tools are already on your network. The governance framework just hasn't caught up.

Here's what needs to change -- and who needs to own what.

Why HR, Legal, and IT Each See AI Differently

It's not stubbornness -- it's professional scope. Each department was hired to protect a different set of organizational interests, and AI creates new risk vectors in all three.

HR sees a people problem: who's using AI to make decisions about employees, what disclosures are required, and whether your workforce has the training to use these tools responsibly. Sixty-five percent of HR teams now use AI for compliance and policy-related work -- but only 39% have a formal process to review those AI outputs for bias, accuracy, or legal risk.3

Legal sees a liability problem: vendor agreements, data residency requirements, intellectual property exposure, and a regulatory environment moving faster than most companies' playbooks. Twenty-two percent of organizations have already faced legal claims tied to AI use.4

IT sees a security problem: 27% of enterprise employees have entered confidential company data into public AI tools.5 Shadow AI -- employees using unsanctioned tools without IT's knowledge -- now drives the most expensive insider risk category, costing organizations $10.3 million annually.6

Three departments. Three valid concerns. Zero coordination.

What HR Needs to Own

HR's job in an AI governance framework is to own the human layer: the acceptable use policy, the training program, and the process for handling AI-related complaints or bias claims.

That means drafting -- and actually enforcing -- a policy that tells employees which tools are approved, what data they're allowed to input, and what happens when they go around the rules. It also means ensuring employees understand those rules before they break them. Only 45% of organizations provide AI literacy training to all employees.3

HR also owns the disclosure piece. State and local laws increasingly require employers to notify employees when AI is used in employment-related decisions. That's not a Legal job. That's not an IT job. It's HR's -- and it needs to be written into your AI governance policy before the next hiring cycle begins.

For a deeper look at training your workforce for AI adoption, see our post on Employee AI Training: Building Tomorrow's Workforce Today.

What Legal Needs to Own

Legal's job is to map your AI use to the regulatory environment you operate in -- and to make sure your vendor relationships don't create exposure you haven't reviewed.

That means examining every AI vendor agreement for data use clauses, output ownership terms, and indemnification limits. It also means understanding where your AI tools fall under existing frameworks -- and where the gaps are. Only 29% of organizations have mapped their AI usage to applicable regulatory requirements.2

If your company operates in a regulated industry, this work is not optional -- it's already overdue. See our post on AI and Compliance: What Regulated Industries Need to Know Now for the industry-specific breakdown.

Legal also needs a policy position on AI-generated content: who owns it, whether it can be used in client deliverables, and how your team discloses it when disclosure is required. These questions are going to get answered one way or another. Better for Legal to answer them first.

What IT Needs to Own

IT owns the technical controls: the approved tool list, the data classification policy that governs what can and can't be entered into an AI system, the monitoring layer, and the incident response plan for when something goes sideways.

This is where most organizations have the biggest gap. Only 34% have formal shadow AI detection programs, and 60% lack visibility into how employees are actually using AI tools across the organization.2

You can't govern what you can't see. IT needs tooling and policy authority to close the visibility gap before a data event closes it for you.

IT also needs to own the vendor assessment process. Before Legal signs the AI vendor agreement, IT should have completed a security review. Before HR launches the training platform, IT should have confirmed it meets your data handling requirements. That sequencing matters, and it only happens when someone is running it.

For guidance on getting your Microsoft 365 environment ready for AI tools like Copilot, see our post on Preparing Microsoft 365 for Copilot: Your Security-First Guide.

How You Get All Three in the Same Room (and Keep Them There)

The governance framework doesn't have to be complicated. But it does have to exist.

Start with a cross-functional AI steering committee with a clear chair -- a dedicated AI governance lead, or your CTO/CISO if you're not there yet. Set a quarterly cadence. Before any new AI tool goes live, agree on three things:

  • Who approved this tool, and what was the review process?
  • What categories of data is this tool permitted to process?
  • Who gets called when something goes wrong, and what's the escalation path?

Organizations that deploy AI governance platforms are 3.4x more likely to achieve high governance effectiveness.4 You don't need a platform to start. You need a policy, an owner, and a meeting on the calendar.

At Sentry, we help clients build this foundation as part of the Secure phase of our Technology Maturity Model. Before AI can drive innovation -- the Innovate phase -- it needs guardrails. The right guardrails don't slow you down. They're what let you move fast without leaving the company exposed.

Frequently Asked Questions

What is AI compliance for businesses?

AI compliance refers to the policies, controls, and oversight processes an organization puts in place to ensure AI tools are used legally, ethically, and securely. It covers data governance, acceptable use policies, regulatory alignment, and employee training across HR, Legal, and IT.

Who is responsible for AI governance in a company?

Responsibility is shared across HR, Legal, and IT -- but ownership fragments when there's no designated governance lead or cross-functional committee. Most organizations assign some responsibility to IT (25%), risk management (18%), or cross-functional teams (17%), but only 10% have a dedicated AI governance function.4

What is shadow AI and why does it matter?

Shadow AI refers to employees using AI tools that haven't been reviewed or approved by IT. It matters because those tools can expose sensitive company data -- 27% of enterprise employees have already entered confidential information into public AI systems.5 Shadow AI is now the most expensive insider risk category for most organizations, and it's largely invisible until something breaks.

What should an AI acceptable use policy include?

At minimum: a list of approved tools, prohibited data categories (PII, financial data, client data, proprietary IP), disclosure requirements for AI-generated content, and consequences for violations. HR typically owns this policy; IT enforces it technically through access controls and monitoring.

How does AI compliance connect to cybersecurity?

Directly. Employees entering sensitive data into public AI tools creates data leakage risk. Unapproved vendors may not meet your security or data residency requirements. Shadow AI increases your attack surface. IT's role in AI governance is as much a cybersecurity issue as it is an operations issue.


Ready to build your AI governance framework? Start with Sentry's Technology Maturity Model Assessment. We'll show you exactly where your organization stands -- and what to lock in before your next AI rollout. Book your discovery call at sentryitsolutions.com.


References
1. ISACA, 2026 AI Pulse Poll (via Kiteworks, "The AI Policy Gap: When 90% Use AI and 25% Have No Rules," 2026).
2. Multiple sources: Microsoft, "Work Trend Index," 2025 (78% stat); Cisco, "AI Readiness Index," 2024 (60% visibility gap); KPMG, "AI Governance Report," 2025 (29% regulatory mapping); Gartner, "AI Governance Survey," 2025 (34% shadow AI detection).
3. Traliant, The AI Governance Gap Report, 2026. Survey of 500+ HR professionals.
4. Optro, AI Governance Stats, 2026. optro.ai/blog/ai-governance-stats
5. Salesforce, Workforce AI Research, 2024.
6. Ponemon Institute / Kiteworks, Insider Risk Cost Research, 2026.