AI Readiness: Governance Comes Before the Tools

August 27th, 2026

AI governance panel discussion at the Valve+Meter masterclass in Indianapolis

On August 26, Steven Sigmon, Director of IT at Van Ausdall & Farrar, took the panel stage at the AI & Marketing Masterclass at Ruth's Chris in Indianapolis. Presented by Valve+Meter Performance Marketing alongside Van Ausdall & Farrar and Leaf Software Solutions, the invite-only session drew manufacturers, distributors, and logistics teams — the businesses most likely to be handed an AI tool and told to find something useful to do with it.

The panel's theme was AI usage, governance, and safety. The message that kept surfacing was that the tool is the easy part.

Readiness Comes Before Tools

Most AI conversations start with a product. Sigmon starts somewhere else. “What is the business problem that we're trying to solve, what's the friction, what's the repeatable process that we're trying to utilize AI to help with,” he said. “It's really understanding the problem before we just throw tools out there to fix.”

That order matters. A tool chosen before the problem is defined produces a pilot that never reaches production, or one that quietly becomes a second way of doing the same work. The question worth asking first is which process is repetitive, rules-based, and expensive enough that shaving time off it justifies a project.

What an Acceptable Use Policy Actually Covers

Sigmon's more pointed question was about readiness. “Is there an AI policy? Do we need to help out with an AI policy? Do we have guardrails with AI and what we're using?”

An acceptable use policy is neither a ban nor a permission slip. It answers the questions your team is already improvising answers to:

  • Which tools are approved, and which are prohibited outright
  • What categories of data may be entered into an approved tool — and what may never be
  • Whether vendor training on your inputs is on or off, and how that gets verified
  • Who reviews a new AI tool before someone starts using one
  • How outputs are checked before they reach a customer, a contract, or a filing
  • What happens when something goes wrong

Written down, that is a page or two. Unwritten, the policy still exists — it is just different in every employee's head.

Shadow AI Is a Data Governance Problem

The risk the panel kept returning to is not that employees use AI. It is that they use it with company data, in tools nobody vetted, and no one finds out until a client asks a question.

Consider what leaves the building when someone pastes a spreadsheet into a consumer chatbot to clean it up: customer names, pricing, contract terms, employee records. The employee's goal is reasonable — they are trying to finish faster — which is exactly why a ban does not hold. People route around a rule that blocks the work.

Data governance solves it from the other direction. Classify what you hold, decide which classifications may enter which tools, and then give people an approved path to the same outcome so the honest option is also the fast one. Businesses that already take document management seriously have most of this groundwork done — they know where their sensitive data lives.

Where the Guardrails Come From

Governance for AI is less a new discipline than a familiar one applied to a new tool. The controls that protect the rest of your environment carry over: identity, access, data classification, monitoring, and a plan for when something slips through.

That is why AI readiness tends to stall in organizations missing a foundation. If nobody owns network security, nobody owns the AI guardrails either. Van Ausdall & Farrar's AI consulting work starts with the acceptable use framework and the governance questions above, then builds outward to tooling — the reverse of how most AI projects begin. It is a natural extension of the managed IT services we already deliver, because the team watching your environment is the team that decides what may connect to it.

A Readiness Check Takes an Afternoon

You do not need a committee or a twelve-month roadmap to find out where you stand. Four questions get most of the way:

  1. Which AI tools are your employees using today, and how do you know?
  2. What company data have they put into them?
  3. Is there a written policy, and does anyone remember reading it?
  4. Who decides whether the next tool is allowed?

If any answer is “we're not sure,” that is the finding. Not a failure — a starting point, and a far cheaper one to reach now than after an incident.

AI readiness is a short engagement, not a long one. Schedule a Technology Strength Assessment and we will review your data handling and give you a straight read on what has to be in place before the tools go out.

Posted in: AI Consulting, News & Press