Collective Campus
Blogs

AI governance

Who is allowed to let an internal AI agent send a message?

A glowing gate in front of a swarm of nodes and a sealed envelope

A team can draft with a model for months and still freeze the first time someone wants the tool to send the note itself. The draft was a private experiment. The send is a promise, to a customer, a colleague or a regulator. Those are not the same act, and they should not have the same owner by default.

Deloitte UK's GenAI Workforce Survey, 25,000 workers, fieldwork 7 May to 10 June 2026, found that 31 percent of generative AI users say they use the tools without their employer's knowledge. Hayley McKelvey, the firm's chief AI officer, put the management problem in one line: the challenge is no longer getting people to use the tools, it is meeting that demand in a way that is secure, responsible and useful. An agent that can send is that problem with the safety catch off.

Drafting is not sending

Most of what people do today is still a draft. The same Deloitte release says the common uses are search, email drafts and summaries. A person reads the result and decides. An internal agent changes the shape. It can open a thread, file a ticket, or reply, without that pause, if someone has given it the right.

Before that right exists, write down four facts. What data can it see? Who receives the output? Can it act, or only propose? What happens on a weekday when it is wrong in public? If nobody in the room can answer those, the agent does not get a send button. It gets a draft folder and a named reviewer.

Who actually signs

The signature should sit with the person who carries the downside, not with the person who is most excited about the demo. For a customer email, that is the owner of the customer relationship, with legal or risk in the room if the note can promise money, a remedy or a regulated statement. For an internal ticket, it is the process owner. For anything that spends money or changes a record, it is the control owner who already signs the manual version.

Learning teams do not own this signature. They can teach the questions. They cannot be the person who is called when the message is wrong. The AI governance workshop is built for that split: a plain language line for staff, and an operating model for the leaders who approve use. It is not a statute class.

A rule that survives the pilot

Write the rule on one page, before the pilot, not after the first complaint.

  1. An agent may draft into a queue. It may not send, file or pay until a named role has said yes for that class of action.
  2. The yes is recorded. A screenshot in a chat is not a record.
  3. Shadow tools are out of scope. If people are already using unsanctioned accounts, the first job is to see that, not to add another bot.
  4. The pilot has an end date. On that date the permission stays, shrinks or stops.

If the only control is a hope that people will be careful, you do not have a control. You have a demo that can reach a customer.

Source: Deloitte UK, "British workers spend nearly £1bn of their own money on GenAI for work", 16 September 2026. https://www.deloitte.com/uk/en/about/press-room/british-workers-spend-one-billion-pounds-of-their-own-money-on-gen-ai-for-work.html

WorkshopBook the AI Governance workshop