Why AI policy acknowledgements aren't evidence of compliance

Getting employees to acknowledge an AI acceptable use policy sets expectations, but it doesn't prove compliance. Learn how to prove that your AI policies are secure.

July 21 2026 by

Hannah Bien

Do you have kids? Or ever been around one? Imagine with me: You’re at a restaurant, supervising a 5-year-old child who insists on using the restroom by themselves. They even promise they’ll wash their hands afterwards. So you agree — after all, they promised. They come back, maybe a little too quickly. How can you be sure they washed their hands?

While your employees (probably) aren’t children, the theme of this scenario also applies at your organization — agreements don’t always give us the results we want or expect. Often, this isn’t malicious noncompliance; the employee might even be trying to improve their work quality or efficiency. But neglecting best practices has a cost.

According to a report by the Ponemon Institute and DTEX, the average cost of an insider risk security incident rose from 2024 to 2025 by over 2 million USD, to 19.5M. They found that the fastest-growing risk category was insider negligence, which rose 15% year over year.

Shadow AI turns “routine productivity behaviors into persistent data leakage.”

Cost of Insider Risks 2026 Global Report, Ponemon Institute and DTEX

By now, you likely suspect we’re not talking about hand washing here. Instead, we’re discussing AI use at your organization, which, if it goes unchecked, can leave your hands dirty too.

AI is a powerful tool with unique implementation, which is why organizations have to battle with shadow AI and AI-related data protection. Naturally, organizations write Acceptable Use Policies (AUP) to make sure that workers understand what AI platforms are approved and what company data to input (or not).

But can you prove that employees are adhering to your AI AUP? Can you guarantee an employee isn’t creating a personal account for unapproved AI platforms and inputting company data? Or that an approved AI tool isn’t connecting to MCP servers with access to data you don’t want it to access?

AUPs alone are not enforcement. Read on to learn why you should progress from AUPs to AI governance.

The proof is grounded in behavior after AUPs are accepted.

Your AI AUP is a great tool to start educating users on how to use AI, and it might include topics like:

  • What third-party AI tools are allowed
  • How code or content created by generative AI is vetted
  • Information on how to use AI tools
  • How to handle employee, customer, company or other information when using AI

It’s time for a classic adage: “Trust, but verify.” Your organization trusts that employees will take care of company information and that they will use tools that enhance their work. But even though employees agree to the terms in your AUP, sometimes this agreement gets broken. An AUP can’t cover every possible use case, leaving gray areas subject to employee judgement. Or users find themselves pressured by leaders, workload or company initiatives, causing them to turn to unapproved tools. Or they simply forget what the AUP entails.

That’s all to say, policy acknowledgement and compliance are not the same. Compliance is measurable, and measurement requires data beyond a “yes, I agree.”

If you can’t prove it, you can’t guarantee it.

If you assume that a signed AUP removes AI-related risks, you’ll likely find yourself lulled into a false sense of security — at least until your board or executives ask for concrete proof that your AI deployment is securely implemented.

“Once teams begin exploring AI in their organization, the chance they’ve had an incident rises.”

Jamf’s AI Governance Survey, 2026

In a recent survey, Jamf found that 1.4x the number of organizations with deeply integrated AI experienced an AI-related incident, compared to organizations that have just began exploring AI. In general, the more AI that’s implemented, the greater the risk.

A lot of this comes from lack of visibility — or in other words, the missing proof of enforcement. Beyond increasing the chance of a serious incident, this absence of proof causes problems during audits, investigations, customer security reviews or regulatory inquiries.

But when you can’t prove enforcement, you can’t answer these questions:

  • What AI platforms are employees using?
  • What data is being processed by AI and how is this data being handled?
  • What MCP servers are accessed by AI, what data are they accessing and what are the risks of each MCP server?
  • What AI agents are running on device?
  • Is our AI deployment secure?

Your customers, auditors, executives and regulators want concrete evidence of your security measures. If you can’t answer these questions, you might find yourself in some uncomfortable situations — but it doesn’t have to be this way.

Finding your way to effective AI governance starts with visibility.

The risks of AI are too great to let it run around ungoverned. Successful AI governance ensures that AI is used appropriately, safely and ethically, in a way that can be continuously validated and maintained. To get to this point, you need:

  1. Visibility into every AI tool, agent and MCP server running on your fleet.
  2. Control over what AI platforms employees can use, what users can access them and configurations specific to each vendor

This, essentially, leads to your “proof.” You likely already manage your devices and require them to meet certain compliance standards through configurations like least privilege access, an enforced minimum OS version or by allowing/blocking certain apps. AI platforms follow the same principles, but with added complexity that SaaS tools don’t have:

  1. AI platforms can handle sensitive data, including in agentic ways that don’t involve humans in the loop.
  2. Each vendor configures permissions differently, requiring a deep understanding of each platform, even with frequent updates.
  3. Traditional ways of determining AI traffic don’t always work, as not all AI passes through DNS or exists as an app on device.

Because humans (and generative AI platforms) make mistakes, the stakes are too high to only rely on agreed upon AUPs. Plus, this means you’re lacking visibility, the first step of AI governance that regulators, customers and other stakeholders require.

You cannot prove what you can’t see. Nor can you control it, at least not in a sustainable way. An AI AUP defines employee expectations — but it does not mean employees always follow them. Getting to a secure AI deployment requires AI governance.

Jamf for Mac brings AI governance to your fleet.

Tags: