← Field Notes

What Fortune 50 companies know about AI governance that your 60-person company can steal for free

Large companies are slow, political, and frequently ridiculous. I've spent enough time inside them to say that with confidence.

But they're unusually good at one specific thing, and it's the thing most smaller companies are getting wrong about AI: they don't let a technology initiative touch the business without governance in place first.

That sounds like bureaucracy. In practice, it's the reason their AI programs produce measurable results while a lot of nimbler, smarter companies burn eighteen months and produce a slide deck.

Here's what's actually in that discipline — and how much of it costs nothing.

They decide what data can go where, before anyone asks

Every large company has a data classification scheme. It's usually four tiers, it's usually boring, and everyone knows which tier their information falls into.

Which means when a new AI tool appears, the question "can I put customer records into this?" has an immediate answer. No committee, no delay.

Most companies at 60 people have no classification at all, so every question is a novel judgment call made by whoever is holding it — usually under time pressure, usually resolved as "probably fine."

You can build a serviceable version in an afternoon. Four categories: public, internal, confidential, restricted. Assign your major data types. Write down which AI tools are permitted for each. That's it. This is not a six-figure exercise — it's a one-page document that eliminates a hundred future arguments.

They evaluate vendors with a checklist, not a demo

Large companies have a standard vendor evaluation process. It's tedious. It also means nobody buys software because a demo was impressive.

The AI vendor market right now is unusually hazardous: young companies, aggressive claims, thin products with polished front ends, and consolidation coming. Some of what your team is evaluating today won't exist in two years.

The questions that matter aren't complicated. Where is our data processed and stored? Is it used to train their models? What happens to it if we cancel? Who actually owns the output? What's the underlying model, and what happens when it changes? What's your funding position and runway?

Write those down once. Make anyone proposing a tool answer them in writing. You'll disqualify a third of vendors immediately and negotiate better terms with the rest.

I built this one as a tool. The Vendor Evaluation Scorer runs eighteen of these questions and turns anything you can't answer into a diligence email you can send today. Score a vendor →

They write the policy before the rollout, not after

This is the one I see reversed most often. Tools get deployed, staff start using them, and someone writes an acceptable use policy nine months later after an incident.

Large companies do it in the other order — not because they're cautious by temperament, but because they've learned that retrofitting rules onto established behavior is enormously harder than setting expectations at the start. Once your team has spent six months pasting client information into a public chatbot, telling them to stop is a much larger conversation.

A workable AI use policy is about two pages. What tools are approved. What data never goes in. What requires human review before it goes out. Who to ask when unsure. You do not need a law firm to produce a first draft, though you should have one review it.

They assume the output is wrong until someone checks

Large organizations in regulated sectors have a concept of a control point: a defined place where a human verifies before something proceeds.

AI produces confident, fluent, plausible output that is sometimes entirely fabricated — citations that don't exist, figures that were never real, summaries that invert the meaning of the source. Fluency is not accuracy, and the failure mode is specifically that wrong output looks exactly like right output.

So define your control points. What must be reviewed before it reaches a client, goes into a contract, or informs a decision about a person? Who reviews it? That's a thirty-minute conversation and it prevents the failure that would actually hurt you.

They measure against a baseline

If you don't know how long something took before, you cannot know whether AI improved it. Large companies instrument obsessively, sometimes to a fault.

You don't need their infrastructure. You need one number, captured before you start. How long does this take today? How many of these do we handle a week? What's our current error rate? Write it down before the tool arrives, because after it arrives nobody will remember accurately and everyone will be optimistic.

None of this requires a budget

Data classification, a vendor question list, a two-page policy, defined review points, and a baseline measurement. That's the whole thing.

It's perhaps two days of focused work, and it's genuinely most of what separates companies that get value from AI from companies that get a subscription bill.

The advantage large companies have here isn't resources. It's that someone senior is accountable for doing it, so it gets done. That part is available to you too — it just has to be somebody's actual job.


Related tool. The AI Policy Drafter produces the two-page policy described above, tailored to your sector and risk posture, in about four minutes.

Draft a policy →

Want someone to own this?

Twenty minutes. What you've tried, what stalled, and what you're actually trying to accomplish.

Book a 20-minute conversation