Every company I talk to has already adopted AI. Most of them just have not decided to. Somebody in accounting is pasting invoices into a chatbot. A project lead turned on a meeting recorder that emails transcripts to everyone on the call. A vendor switched on an “AI assistant” inside a platform the firm has used for years. None of it went through a decision. All of it touches company data, and some of it touches client data.

When I speak to CEO peer groups about this, the question is never whether to use AI. It is how to get control of what is already happening without slowing the business down. The approach I teach is a four-step sequence I call SAFE: Surface, Aim, Fence, Expand. It is built for companies that will never hire a chief AI officer, which is most of them.

What the SAFE framework is

SAFE is an operating sequence for AI adoption in a mid-market or regulated company. Each step answers one question a leadership team needs to be able to answer on demand: what AI is in use, what it is for, what keeps it inside the lines, and how the company gets the benefit at scale. The order is the point. Skip a step and the later ones stop working.

Surface: find what is actually in use

You cannot govern what you have not found, so the first job is discovery, not policy. Single sign-on logs, OAuth grants to third-party apps, browser extension inventories, credit card statements and expense reports each turn up tools nobody mentioned. So does a direct question to every department head: what are your people using to get work done faster?

In one enterprise assessment I led, that inventory surfaced 346 unsanctioned AI tools across 130 departments. The approved list had none of them. Smaller companies find the same pattern at smaller scale. The number is not the failure. Not knowing the number is.

Aim: make it a business decision

Once the list exists, leadership decides what the company actually wants from AI. Good meeting notes are worth having. Faster proposal drafts are worth having. So each approved use case gets an owner, a purpose and a definition of success. That is what turns AI from a scattered set of experiments into something the company can fund, measure and defend. It also gives you a principled reason to say no to the tools that serve no purpose beyond novelty.

Fence: put controls around the approved tools

Fencing is where governance becomes real. Business accounts replace personal sign-ups. Retention settings are chosen on purpose. Contracts say whether the vendor may train on your data. Clients consent before a call is recorded. Access is scoped, and usage is logged. The NIST AI Risk Management Framework and ISO/IEC 42001 give these controls a structure an auditor or an assessor recognizes, and for defense suppliers the same tools have to be scoped under NIST SP 800-171 like any other asset that touches controlled data.

The controls matter more than the paperwork. IBM’s 2025 Cost of a Data Breach report found that 97 percent of organizations that reported a breach of an AI model or application lacked proper AI access controls. A policy nobody enforces is not a fence.

Expand: get the payoff

With the fence in place, the company rolls the approved tool out to every team that can use it, with training, and measures whether it saves the time it promised. This is also when the unapproved tools get retired, because people now have a sanctioned option that works. Expansion is the step most companies try to start with. It only pays off when the first three steps are done.

Why the order matters

Companies that begin by banning tools push usage underground, and shadow AI grows. Companies that begin by buying a platform automate the confusion they already have. Companies that begin by surfacing what exists get to make real decisions, and they can show their work when a client, an insurer, a regulator or a board asks. Boards are starting to ask about AI the way they started asking about ransomware a few years ago. The executives who come out of those conversations well are the ones who can answer three questions without a scramble: what AI is in use, what data it touches, and who is accountable for it.

Frequently asked questions

What does SAFE stand for in AI governance?

Surface, Aim, Fence, Expand. Find the AI tools already in use, decide which use cases the business wants and who owns them, put access, data and contract controls around the approved tools, then roll them out with training and measurement.

Who is the SAFE framework for?

Leadership teams at mid-market companies, professional services firms and defense suppliers that need practical AI governance without a dedicated AI executive. It maps to the NIST AI Risk Management Framework and ISO/IEC 42001 so the results hold up in an audit.

How long does the Surface step take?

For most mid-market companies, a first inventory takes two to four weeks: pull the identity and expense data, review browser and SaaS integrations, and interview department heads. The inventory is then maintained, because vendors switch on new AI features with routine updates.

I first described SAFE in an interview with TechRound earlier this year. My team at Stealth Technology Group runs the Surface and Fence steps for clients as part of our AI strategy and governance work. If you want to talk it through for your own company, or have me walk a leadership team or peer group through it, get in touch.