
The AI leaderboard moved again in 2026. Reporting through the year has Anthropic overtaking OpenAI on enterprise revenue, while ChatGPT holds a commanding lead in consumer usage, Google pushes Gemini deeper into Workspace, and most organisations quietly end up running two or three platforms at once. OpenAI is pushing hard on new products to win business customers back. By the time you read this, some of that will already be out of date.
I have no view on who wins, and neither should your management system. But I do have a view on what the churn tells you, and it is the thing almost every AI policy I audit gets wrong.
If your AI acceptable-use policy names a vendor, it has a shelf life, and it is shorter than you think.
The policy I keep reading
It usually says something like: “Staff may use ChatGPT for drafting and research. No confidential information is to be entered into ChatGPT.”
It is well-intentioned, it was signed off by someone senior, and it is already failing. Here is what happens to it in practice.
Someone starts using Claude, because a colleague said it was better for the thing they were doing. Someone else uses Copilot, because it is already in the Office licence and nobody had to ask. Marketing signs up for a tool that has a model bolted onto it and never thinks of it as “AI” at all. None of these people believe they are breaching the policy: the policy talks about ChatGPT, and they are not using ChatGPT. Technically, they are correct. The policy simply does not reach them.
So your rule now covers one tool, and your exposure covers a dozen. Worse, the people outside the policy are outside it in good faith, which means you will not find them by looking for wrongdoing. This is how you end up with shadow AI in an organisation that genuinely believed it had a policy.
Vendor-named policies fail three ways
- They go stale silently. A policy that is out of date announces nothing. It sits in the document register looking approved and current, and everybody keeps working outside it. There is no alarm, no error message, just a growing gap between the paper and the practice, which is exactly the gap an auditor is trained to find.
- They create a false negative. “Are we compliant with our AI policy?” “Yes. Nobody is misusing ChatGPT.” Both statements are true, and the organisation is still exposed. A control that can be satisfied while the risk goes unmanaged is not a control.
- They put you on a treadmill. Every model release, every acquisition, every new tool with AI quietly added to it becomes a policy amendment, a re-approval, a re-issue and a retraining cycle. Nobody has the appetite for that, so in reality the policy is updated once, never revisited, and slowly becomes fiction.
Govern the use, not the tool
This is the core idea in ISO 42001, and it is why the standard has aged better than the news cycle it was born into. ISO 42001 does not care which model you use. It asks a different set of questions, questions that stay true whoever is winning:
- What data may go in? Classify it. “No customer personal information, no unpublished financials, no health information, no source code” works regardless of what is on the other end of the prompt.
- What may the output be used for? Drafting, yes. Making a decision that affects a person, not without a human in the loop who can explain it.
- Who approves a tool, and against what criteria? Where is the data stored, is it used for training, can it be turned off, who is the vendor, and what happens when they change their terms?
- Who is accountable? Named. Not “IT”.
- How do you know what is actually in use? Because if the answer is “we asked people”, you do not know.
Write it that way and a vendor swap changes nothing in your policy. The approved-tools list is a separate, living register that sits underneath it: a controlled record, not a clause. You update the register when the market moves, which takes an afternoon. You update the policy when your risk appetite moves, which is rare. That separation is the whole trick, and it is the difference between a management system and a document.
Does your AI policy survive the next model release?
If it names a vendor, it doesn’t. A gap analysis tells you what AI is actually in use across your business, what data is exposed, and how far your current policy is from something that will still be true in twelve months.
Book a gap analysis →“But we want to name our approved tool”
Good. You should. The distinction is where you write it down.
The policy states the principle: only AI tools on the approved register may be used with company information, and here are the rules about what may be entered and what the output may be used for. The register lists the tools, the approval date, who approved them, what data classification each is cleared for, and any conditions. One is a governing document that changes rarely. The other is a record that changes whenever it needs to.
If that sounds like a fussy distinction, consider how you already handle suppliers. Your supplier policy does not name your accountant. It says how suppliers are assessed, approved and reviewed, and the approved supplier list names the accountant. Nobody finds that confusing. AI is a supplier, and a fast-moving one; treat it accordingly.
The awkward question the vendor war forces
There is a reason the market is fragmenting rather than consolidating: different models are genuinely better at different jobs, so organisations run several. Which means the honest end state for most businesses is not one approved tool. It is three or four, each cleared for different data and different uses.
That is manageable, but only with a framework. Without one, “we use a few different tools” is just a polite description of having no idea where your data is. And the cost of that is no longer theoretical: IBM’s 2025 research found that breaches involving shadow AI cost US$670,000 more than the average, and that 97% of organisations which suffered an AI-related security incident had no AI access controls in place, while 63% had no AI governance policy at all.
Read that last number again. Almost two-thirds had no policy. Of the third that did, I would wager a fair proportion had one that named a vendor.
Five tests for your AI policy
Pull it up and check. It should pass all five.
- Search it for brand names. If a vendor appears in the policy itself rather than in a register beneath it, that is your first edit.
- Does it define the data, not the tool? Someone should be able to read it and know what they may type, without knowing what they are typing it into.
- Does it cover AI you did not choose? Features that appear inside software you already own. Notetakers that join your meetings uninvited. Most policies only imagine the tools people deliberately go and get.
- Is there a named human accountable? Not a department.
- Would it still be true if every vendor in the market changed places tomorrow? If yes, you have a policy. If no, you have a snapshot.
Frequently asked questions
Should we just approve one AI tool and ban the rest?
You can, and for some organisations it is the right call. But be honest about whether it will hold. Different models are better at different tasks, and a ban that people find genuinely obstructive gets routed around, usually through personal accounts you cannot see, which is worse than the thing you banned. Approving a small, considered set is generally more enforceable than approving one.
Does ISO 42001 tell us which AI tools to use?
No. Deliberately. It is a management system standard: it requires you to identify your AI risks, decide your own controls, assign accountability and check that it is all working. The choice of tool is yours; the requirement is that the choice is made deliberately, recorded, and reviewed.
We’re a small business. Isn’t a whole AI management system overkill?
Certifying to ISO 42001 may well be, for now. Writing a two-page policy that governs data rather than brand names is not: that is an afternoon’s work and it removes most of the exposure. You do not need the certificate to use the thinking.
How often should the approved-tools register be reviewed?
At least annually, and whenever something changes materially: a vendor updates its terms, a tool starts training on your inputs, a new capability appears in software you already own. The register is designed to move. The policy is designed not to.
Speak with an experienced ISO auditor
The vendor war will keep going, and the leaderboard will keep flipping. None of that should reach your policy, and if it does, the policy is built wrong.
Streamline helps Australian businesses build AI governance that outlives the news cycle, through ISO 42001 and ISO 27001, or security and AI advisory where certification is not the goal. If you would rather write it yourself, ISO mentoring means you keep the knowledge and we make sure it is right.
Email hello@streamline.business or call us. You will deal directly with an experienced ISO auditor.
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Market positions described above are drawn from industry reporting through 2026 and move constantly, which is rather the point of this article. Shadow AI cost and governance figures: IBM Cost of a Data Breach Report 2025.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











