Thoughts Brewing Blog

Book Brew 188:Your Default Settings Are Writing Your AI Policy

Written by Danielle Price Griffin | Sep 14, 2026, 6:00:00 PM

Your written AI policy says, “Use caution.(I mean, that is if you even have one....)

Your system says, “Sure, connect EVERYTHING!! YOLO! What could go wrong?”

This is the operational equivalent of putting Tobias Fünke in charge of subtlety.

On paper, everything looks responsible. In practice, the permissions are standing in the middle of the office painted blue, wearing denim cutoffs, and wondering why everyone suddenly looks concerned.

 

The “Allow All” Button Has Entered the Chat

“People will often make better decisions if they are provided with better information, clearer feedback, and timely reminders.” — Richard Thaler and Cass Sunstein


Choice architecture can look like:

  • A warning before someone shares a client file is choice architecture.
  • A list of approved tools.
  • A required human review before AI-generated copy reaches a customer.

But, keep in mind that leaving every permission wide open is also choice architecture. It has the err of Tobias’ bad judgment of auditioning for the Blue Man Group after seeing one flyer.

Employees notice what the system makes easy:

  • Can the AI tool reach the whole shared drive?
  • Can it retain chats or use them for training?
  • Can generated material leave the building without review?
  • Does anyone know where to report an AI answer that appears to have been written during a carbon-monoxide leak?

When leadership leaves those questions unanswered, employees build their own policies from whatever buttons appear, something a coworker heard in March, and the deeply authoritative statement, “I think Kevin uses it.”

Kevin has now become the Chief AI Governance Officer. Kevin does not know this.

 

Your Policy May Be a Never-Nude

Tobias insists that he is fully dressed because the denim cutoffs never come off. Some organizations treat their AI policy the same way.

  • The document technically exists.
  • Everyone can point to it.
  • Nobody can explain how it applies
    • when an employee connects Gemini to Drive,
    • uploads a client spreadsheet to ChatGPT,
    • or lets an AI assistant draft a recommendation that could affect someone’s job.

“People will eventually gravitate to the least demanding course of action.” — Daniel Kahneman

 

Let Mrs. Featherbottom Add Some Friction

Some friction deserves to stay.

  • A confirmation screen before an external share creates a pause.
  • A required source check before publishing an AI-generated statistic creates a pause.
  • A second reviewer on a sensitive recommendation creates a pause.

Those pauses give human judgment time to put on pants and enter the room.

The warning also needs to arrive before the damage, because a privacy message that appears after the shared drive has been connected has Mrs. Featherbottom energy: dramatic entrance, broken coffee table, very little improvement to household tidiness.

Damien’s video on the Gemini Privacy Hub and data settings shows the level where this work needs to happen.

 

Audit the PDF, the Buttons, and Kevin

We help businesses examine three layers together:

  1. The written rule: Can employees understand it without a legal decoder ring?
  2. The system environment: Do permissions, defaults, and approval steps support that rule?
  3. The human reality: What happens when the deadline is real, the client is waiting, and Kevin says, “It’s probably fine”?

The fix may involve:

  • training,
  • clearer tool boundaries,
  • a permission change,
  • an approval workflow,
  • a well-written policy (that’s actually enforced)
  • or a human review step with standards behind it.

How We Help

Next-Level AI Workshops can help your team understand the tools, data boundaries, and judgment calls.

Fractional COO/CTO support can connect those expectations to permissions, ownership, workflows, and business risk.

Tobias can keep the cutoffs. Everyone else gets clearer instructions.

 

PONDER THIS

  1. What does your AI Usage Policy look like? (do you even have one???)
  2. What can your AI tools access right now?
  3. Where would one deliberate pause protect a client, employee, or the business?

 

Books

  • Nudge — Richard Thaler and Cass Sunstein
  • Thinking, Fast and Slow — Daniel Kahneman