Key Takeaway
The first phase of workplace AI adoption revolved around a simple question: should employees be allowed to use these tools? That question is no longer enough. Companies increasingly need to define where AI may be used, what data must never be entered into external systems, when AI involvement should be disclosed, who must review the output, and who remains accountable when something goes wrong.
A Wall Street Journal special report published on 14 September 2026 frames this as a workplace trust problem. When employees do not know the rules, they begin guessing whether colleagues have used AI appropriately, whether the work is genuinely theirs, and whether everyone is being judged by the same standard. What looks like a technology issue quickly becomes an organizational one.
Permission Is Not a Policy
Many organizations still oscillate between two extremes: almost unrestricted use or broad prohibition. Neither approach deals well with everyday work.
Can an employee ask an AI system to summarize an internal report? Can a customer email be pasted into a writing assistant? Can generated code be used without review? Should a presentation disclose that AI helped create part of it? Who verifies numbers, legal wording or financial claims?
The WSJ article argues that these gray areas breed suspicion. An employee may believe a colleague took an unfair shortcut even when no company rule clearly defines what is acceptable. Another employee may conceal legitimate use because they do not know how a manager will react.
A modern workplace therefore needs an operating framework, not simply a yes-or-no answer.
What the New Rules Need to Cover
The first issue is data. Employees need to know what information may enter an external AI service and what must stay inside controlled systems. Personal data, confidential client information, contracts, non-public financial information, passwords and trade secrets should not be placed into tools whose data-handling terms have not been assessed by the organization.
The second issue is human accountability. AI participation in drafting, analysis, coding or recommendations does not transfer responsibility to the software. BTU research materials on AI governance emphasize the same principle: a material process needs a named human owner, and human intervention in higher-impact decisions should be designed into the workflow rather than added only after a problem occurs.
The third issue is transparency. Not every low-risk use requires a formal AI label. But companies should specify when disclosure is expected. Using AI to organize ideas is not equivalent to using it to prepare a client-facing financial recommendation or an employment decision.
The fourth issue is traceability. When AI contributes to an important decision, organizations benefit from retaining a basic record of the task, the system used, the sources relied upon, the human reviewer and the final approver. This matters particularly in finance, human resources, procurement, compliance and other functions where errors can create direct financial, legal or reputational consequences.
Trust Is Not Just a Technical Problem
The WSJ case focuses on trust between colleagues, but weak management often creates the problem. When there are no shared rules, teams invent their own boundaries. One department uses AI daily, another avoids it, and a third suspects that everyone else is quietly breaking the rules.
Performance evaluation makes the issue even harder. If one employee can compress hours of work into a much shorter process, while another completes the same task conventionally, the company has to decide what it is actually rewarding: time spent, output quality, independent knowledge, or the ability to use new tools effectively.
There is no universal answer. But having no answer is the worst option because it encourages hidden use, resentment and inconsistent standards.
Georgia’s Digital Starting Point
According to Georgia’s National Statistics Office, Geostat, 94.9% of enterprises had internet access in 2025. 74.7% used fixed-line connections, while 35.5% of employees used enterprise-provided portable computers or smartphones for business internet access. 15.3% of enterprises had a website and 25.8% used social media.
These figures are not measures of AI adoption and should not be presented as such. Their significance is narrower: Georgian businesses already operate in a broadly connected digital environment, creating the technical conditions for AI tools to spread quickly. At the same time, this specific Geostat release does not provide a national indicator for enterprise use of generative AI. That data gap should be acknowledged rather than filled with assumptions.
According to an assessment by BTU researchers, the first practical step for many Georgian companies is therefore not a complex technology programme but a usage map: which teams use which systems, what data they provide, what tasks they delegate, and where final decisions remain with humans.
International Governance Is Becoming More Operational
The U.S. National Institute of Standards and Technology’s AI Risk Management Framework calls for structured governance, risk assessment, monitoring and documentation. Its Generative AI Profile further highlights governance, pre-deployment testing, content provenance and incident disclosure.
The OECD’s July 2026 review of AI policy in labour markets shows that governance is increasingly expanding beyond productivity and skills into privacy, non-discrimination, occupational safety, transparency, explainability, accountability and social dialogue. A separate OECD study on algorithmic management reports that firms perceive decision-quality benefits while also facing concerns about unclear accountability, limited explainability and worker protection.
The European Union’s AI Act also illustrates how workplace AI is moving into formal governance. The regulation imposes specific duties around high-risk systems and requires affected workers to be informed before certain high-risk AI systems are deployed in the workplace. It also contains AI literacy obligations. These provisions do not automatically apply to every Georgian company, but they show the direction of travel for businesses connected to European markets and partners.
Small Companies Need Rules Too
AI governance is often associated with large corporations, but smaller businesses may face greater exposure because they often lack dedicated information-security, privacy or compliance teams. A single employee uploading client material into an inappropriate tool can therefore become an organization-wide problem.
A small company does not need a hundred-page manual. A practical policy can answer a short set of questions: which tools are approved; what data cannot be entered; when human review is mandatory; when AI involvement should be disclosed; who owns the final result; and how incidents should be reported.
Policies also need updating. A tool that only drafts text today may soon connect to email, files, calendars and operational systems. A policy written once and left untouched can quickly become obsolete.
Rules Should Not Become Prohibition
The purpose of governance is not simply to reduce risk. Excessively strict rules can drive employees toward hidden use or cause the company to lose genuine productivity gains.
The WSJ article therefore recommends learning how employees are using AI in reality, including through cross-functional groups and anonymous feedback. If workers violate rules because workloads are unrealistic, skills are missing or approved tools are inadequate, the problem is not purely disciplinary. It may be a workflow-design problem.
A better policy distinguishes lower-risk from higher-risk use. Brainstorming, language editing and summarizing public information can often be managed with relatively simple controls. Hiring, financial decisions, legal analysis, personal-data processing or important external communications require stronger review and accountability.
BTU Researchers’ Assessment
According to an assessment by BTU researchers, one of the biggest mistakes companies can make is delegating AI rules entirely to the technology department. Workplace AI is simultaneously a human-resources, legal, financial, security, management and organizational-culture issue.
The objective of good rules is not to monitor every employee. It is to reduce ambiguity. Employees should know where they have freedom, where restrictions apply, and where human approval is mandatory. Managers should know what outputs can be trusted and what verification is required.
For Georgia, this transition matters because companies can start using AI long before they build sophisticated technical infrastructure. Responsibility, data and trust rules therefore need to be designed at the beginning, not after the first incident.
Why This Matters for Georgia
First, productivity. If employees do not know what is allowed, they either avoid useful tools or use them quietly. Both outcomes reduce management visibility and organizational learning.
Second, data security. Georgian companies handle customer, financial, contractual and employee information. Unplanned use of generative AI increases the risk that information leaves controlled environments.
Third, trust. When employees do not understand how colleagues produced their work, collaboration becomes more difficult, especially in performance reviews, promotions, bonuses and questions of authorship.
Fourth, international integration. For firms working with European markets, international partners and foreign clients, the quality of AI governance may increasingly become part of both compliance and reputation.
Conclusion
Companies need new rules because workplace AI is no longer only a choice between software tools. It changes how work is produced, how results are checked, how responsibility is allocated and how much colleagues trust one another.
The right answer is neither a total ban nor unlimited use. Organizations need clear data boundaries, named accountability, mandatory human-review points, disclosure rules and continuous employee learning.
In the AI era, the strongest competitive advantage will not necessarily belong to the company that uses the most tools. It may belong to the company that knows precisely how to use them safely, responsibly and without losing the trust of its workforce.
Data and Main Sources
The Wall Street Journal, “Do You Suspect Your Colleague Is Using AI at Work?”, Tessa West, 14 September 2026. User-supplied print edition.
National Statistics Office of Georgia (Geostat), Use of Information-Communication Technologies in Enterprises – 2025, published 29 May 2026.
https://www.geostat.ge/en/single-news/3764/use-of-information-communication-technologies-in-enterprises-2025
National Institute of Standards and Technology (NIST), AI Risk Management Framework.
https://www.nist.gov/itl/ai-risk-management-framework
NIST, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile.
https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence
OECD, Recent policy developments on AI in the labour market, 24 July 2026.
https://www.oecd.org/en/publications/recent-policy-developments-on-ai-in-the-labour-market_c0ffced7-en.html
International Labour Organization, Governing AI in the World of Work: A review of global ethics guidelines, 14 November 2025.
https://www.ilo.org/resource/article/governing-ai-world-work-review-global-ethics-guidelines
Regulation (EU) 2024/1689 – Artificial Intelligence Act.
https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32024R1689
Prepared by the academic team of Business and Technology University and the BTUAI Research Team, Tbilisi, Georgia.



