Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Ivanti: Closing the AI Governance Gap with Brooke Johnson

Ivanti
07/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


and sort of even more than a tool, it's an experience for employees and people right now. You know, there's a lot of excitement around it. There's a lot of excitement around what it can do and how it's going to be changing our lives and the workforce. And so there are some employees who want to run really fast. And I think part of the struggle with compliance, those of us who work in compliance function always have, is making sure that we're doing it safely and we're doing it correctly. And so there's just, I think, a natural tension there, right, with how exciting AI is and how it is so revolutionary, but also, you know, needing to make sure that we're getting our arms around how it can be used responsibly, appropriately, and securely. Only one out of four employees report consistent policy adherence, which really, I think, highlights the disconnect there between, you know, when you're ruling out policies and what the actual adoption is. So, you know, one thing is that governance can't be something that comes after an AI tool. It's already being used. It's already been integrated in someone's workday and workflow. One potential cause of the gap and the impact would be shadow AI use. So shadow AI is when you have employees out there in the company using AI, using IT, AI tools without supervision, right, from the right departments. And so, you know, again, you know, there's an employee who has an agent that has been very effective in helping them, you know, respond to emails quickly in their personal life. So they want to bring that into the company and they, you know, give an agent authority to send emails on their behalf. And that's, you know, without the right, you know, first of all, it hasn't been checked against policies. There's no one supervising it. Maybe that, you know, that agent decides to, you know, send an email, a nasty email to the CEO. I mean, that's just, that's a very benign example. But I think, you know, the impact of shadow AI is something that we can all imagine. But from a policy perspective, it is a very strict breach of any kind of governance and policy and process that the organization has put in place. And it is something that's very serious and a big risk. Yeah, and at Avanti, we, as part of our governance, we do talk about managing AI the way we manage employees. And I think that's a really responsible way to think about it because it's like, don't, you wouldn't trust a human to do all this. Don't trust this tool that also needs to have some kind of human oversight and control. So IT organizations are successfully scaling AI by aligning their work with the business value. So a really good way to sort of get your arms around that is to have conversations, start with the executive team and senior leadership and discuss, you know, what AI actually means to the company. We did that at Avanti. We made some commitments to AI, both internally with our employees and externally. And from that, as sort of like the baseline of discussions here about AI, we built the AI Governance Council. That is a cross-functional team because AI is not one team's responsibility. It's not one individual's responsibility, really, because it's something that's changing our lives. It's changing our industry. It's changing our business.

TL;DR

  • Only 1 in 4 employees report consistent AI policy adherence, revealing a significant gap between governance intent and actual organizational behavior.
  • Shadow AI — employees using unsanctioned AI tools without IT or compliance oversight — poses serious security and policy breach risks that organizations must actively detect and manage.
  • Effective AI governance must be established before tools are deployed; retrofitting policies after adoption creates compounding compliance and security exposure.
  • Ivanti built a cross-functional AI Governance Council anchored in executive alignment, treating AI oversight as a shared organizational responsibility rather than a single team's mandate.

Summary

In this short-form segment from Ivanti's 'Scaling AI in IT Operations: The Path to Maturity in 2026' research series, Brooke Johnson — Ivanti's Chief Legal Counsel and SVP of HR and Security — addresses the widening gap between AI policy creation and real-world employee compliance. Drawing on research showing that only one in four employees report consistent AI policy adherence, Johnson frames the core challenge as a natural tension between employee enthusiasm for AI's transformative potential and the organizational need to govern its use responsibly. She introduces the concept of shadow AI — employees deploying unsanctioned AI tools or agents without oversight from IT or compliance functions — and explains why this represents a serious security and governance risk, not merely a policy technicality. Johnson argues that governance frameworks must be established before AI tools are deployed, not retrofitted after adoption has already occurred. She describes how Ivanti addressed this internally by anchoring AI commitments at the executive level and establishing a cross-functional AI Governance Council, emphasizing that responsible AI at scale is a shared organizational responsibility rather than the domain of any single team or individual.

Chapters

0:00 - AI Excitement vs. Compliance Tension
0:47 - The Policy Adherence Gap
1:09 - Shadow AI Risks Explained
2:12 - Ivanti's Governance Council Model

Key Quotes

0:47 "Only one out of four employees report consistent policy adherence, which really, I think, highlights the disconnect there between, you know, when you're ruling out policies and what the actual adoption is."
1:02 "Governance can't be something that comes after an AI tool. It's already being used. It's already been integrated in someone's Workday and workflow."
2:01 "It is a very strict breach of any kind of governance and policy and process that the organization has put in place. And it is something that's very serious and a big risk."
2:14 "We do talk about managing AI the way we manage employees. And I think that's a really responsible way to think about it because it's like, don't trust a human to do all this. Don't trust this tool that also needs to have some kind of human oversight and control."

FAQ

What is shadow AI and why is it a risk?

Shadow AI refers to employees using AI tools or agents without authorization or oversight from IT and compliance teams. According to Brooke Johnson, this is a serious governance breach because such tools haven't been vetted against company policies, lack supervision, and can take consequential actions — like sending communications on an employee's behalf — without appropriate controls in place.

How did Ivanti structure its AI governance approach?

Ivanti began by aligning AI commitments at the executive and senior leadership level, then built a cross-functional AI Governance Council. The model reflects the view that AI governance is not one team's responsibility — it affects the entire organization and requires coordinated oversight across functions.


Categories:
  • » Webinar Library » Ivanti
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Compliance & Governance
  • Security Operations
  • Thought Leadership
  • Executive Briefing
  • AI governance
  • Shadow AI
  • AI policy compliance
  • Enterprise AI adoption
  • Cross-functional governance
  • AI risk management
  • IT operations
  • Human oversight of AI
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Ivanti: Closing the AI Governance Gap with Brooke Johnson

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    22

                    Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                    07/22/202601:00 PM ET
                    • Aug
                      19

                      Becoming Agent Ready: Insights from Cyera's Expertise

                      08/19/202612:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 07/22/2026
                        06:30 AM
                        07/22/2026
                        Insights and Strategies for Effective Data Privacy and Protection
                        https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection/
                      • 07/22/2026
                        01:00 PM
                        07/22/2026
                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                        https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                      • 07/28/2026
                        01:00 PM
                        07/28/2026
                        Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                        https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                      • 07/29/2026
                        04:00 AM
                        07/29/2026
                        Real-Time Strategies for Safeguarding Against Prompt Injections
                        https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                      • 07/29/2026
                        01:00 PM
                        07/29/2026
                        Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                        https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                      • 08/19/2026
                        12:00 PM
                        08/19/2026
                        Becoming Agent Ready: Insights from Cyera's Expertise
                        https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version