How many good ideas has your team's IT approval process quietly killed? Not rejected outright. Just slowed down until the moment passed, the tool became old news, or the person who asked stopped asking.
I've asked myself that question too. For years, when someone wanted to try something new, the fastest way to protect the company was to say no, or wait, which usually amounted to the same thing. That was the accepted cost of managing technology safely. I understand that instinct. I've relied on it myself. But once AI became how our people work by default rather than an occasional tool, that answer was no longer good enough.
So here's the question my team and I are working through now: how do you put the tools behind those good ideas in the hands of your whole company, quickly, without losing control of risk? You shouldn't have to choose between moving fast and managing risk. That's the balance this piece is about, and what it took for us to get there.
If your default answer is no, you're already behind
Most technology and security functions operate from a place of no by default. That instinct isn't wrong on its own. But in an AI-first environment, it's too slow to keep up.
Flipping that default takes more than a memo, because no was never just a policy. It was a posture, built into how technology and security teams see their job. We made a deliberate leadership decision to shift it: Instead of asking “what could go wrong if we allow this?” we ask “how do we help you do this safely?”
That shift reshapes how an entire organization relates to its governance. People stop hiding what they are trying and start asking. And once they are asking, you can guide them with confidence.
Enablement and guardrails have to move together
Treat enablement and governance as separate initiatives, and you'll spend your time fighting one with the other. Without guardrails, broad tool access invites the kind of open, anything-goes environment that eventually causes harm. Without enablement, guardrails leave your people watching competitors pull ahead.
We think about this as two efforts that reinforce each other: enablement puts AI tools in the hands of every associate and helps them develop real fluency through daily use. Governance is the controls, risk reviews, and rules that keep AI activity safe. Run them together, and each one makes the other stronger.
That structure works at a few levels. Clear, easy-to-follow rules of the road tell everyone what they can and can't do. Security tooling blocks the sites and applications we know to be unsafe today. And a nimble, multi-layered governance team sits behind it all as a safety valve, ready for the questions the rules don't cover.
Most governance programs stop at the rules. The ones that last also own the enablement: the tools, the training, and the daily practice that make the rules worth following.
Match your review process to the pace of the work
Our CEO, Mike Thomson, recently made the case that a governance process too slow for the technology will be bypassed, and that a policy nobody follows isn't governance at all. Taking that one step further involves knowing which decisions deserve which speed.
Mike laid out what a governance framework has to cover: approved tooling, data access controls, and a decision-making process fast enough to keep up. Here's how those three run day to day for us.
First, we have easy-to-consume rules of the road, short enough to read in a few minutes and clear enough to act on, published on our AI First hub.
Access to data sits alongside those rules. Who can connect what to which systems, under what conditions, and what those systems can pass back out. In most organizations that question, rather than a shortage of ideas, is what holds AI programs up.
Next, security tooling blocks access to the tools and sites that aren’t currently right for us as a company. And then we have the governance layer itself, and it moves at two speeds. Simple, well-understood requests (e.g., access to a specific tool for one team) get a fast answer from an empowered team, without a queue. But when the call is strategic, like whether to expand our four company-approved AI tools to include a fifth, it rises to our executive steering group for the level of scrutiny that decision deserves.
Matching the review process to the weight of the decision is what keeps the whole system fast and effective. Before you add another layer of approval to your own process, ask whether it's sized to the decision it's protecting, or just to the org chart that's always existed.
A strong foundation is what makes speed possible
Saying yes more often only works if you can trust what happens next. Skip the underlying foundation, and speed becomes a liability.
This is where our history matters. Unisys has built secure environments for more than 40 years, and security by design describes how we architect, day in and day out. Without that foundation, speed can result in chaos: unmanaged tools and unknown exposure. Our foundation lets us open the door to experimentation instead.
Other companies are reaching the same conclusion. In our 2026 AI & Cloud Insights Report, 96% of organizations said their cloud security approach helps them adopt new technology faster than their competitors, up from 60% a year earlier. Security shouldn’t be the price you pay for speed.
The same principle applies to the clients who trust you with their most sensitive data. As more employees use more tools, that protection has to be (and stay) woven into your systems from the start.
Prepare in advance
In most organizations, adoption arrives before the policy does. That's the normal shape of useful technology, and it's why the gap between the two is where risk collects. We had a head start. Well before we launched our AI-first initiative, a cross-functional working group was already shaping how we'd govern this shift, with people from across the company at the table: technology and security, as well as legal, commercial, and client management. AI governance touches every part of a business. That group is a big part of why we could move quickly once the moment came.
Over decades, we developed a habit of getting our arms around risk early. If you're waiting for the AI conversation to force your hand in your own organization, start forming that habit now.
We don't have every answer, but we welcome every question
A posture of yes comes with an honest admission, no matter how strong your foundation is.
That foundation gives us confidence, but it doesn't give us certainty. We don't have all the answers yet, and neither does anyone else this early. What we can do is stay open to all the questions and give people more than one way to ask them.
We've got a formal place for questions at the AI First hub, the homepage for our AI Center of Enablement, but some of the most useful conversations happen somewhere less official. We also have an opt-in internal community that's grown to roughly 15,000 associates since launch. People join because they want to participate, and real questions surface there constantly, in the middle of everyday conversations.
That visibility matters. Nobody has to work through this in the dark, guessing what's allowed and what’s not. And the questions people ask show us where our guidance falls short, so we can improve support as we go. The same will be true anywhere. The gap in your own guidance is easiest to find by listening for it, not by waiting to be told.
The next test: from advisor to actor
The clearest test of any organization's governance-enablement balance is how much autonomy it gives AI to act.
As an advisor, AI recommends, and a person decides. As an actor, an agentic system carries out the work itself. We already run both across our own operations and in the solutions we deliver for clients. The real governance question is how much autonomy to grant, and where.
That decision scales with confidence. A well-understood task with contained consequences can move quickly to autonomous action. A higher-stakes one earns more scrutiny, because handing a system the authority to act means thinking hard about its dependencies and recognizing that the service levels we trust in mature systems don't yet apply the same way to frontier models. Setting that dial deliberately, use by use, is what lets us expand autonomy with confidence rather than by leap of faith.
Whatever stage you're at, ask yourself whether you've matched the scrutiny to the stakes of the task you're handing over. The same discipline applies to the approvals behind it. Audit your own approval timelines against the pace of the work they're gating. If a request that should take days is taking weeks, that discrepancy is your starting point.
Curious how Unisys applies this balance? Explore our AI solutions and read the 2026 AI & Cloud Insights Report for more on how leaders are turning AI capability into measurable value.