The AI Tool Settings Executives Need to Govern
- Aug 6
- 5 min read
A checklist crossed my feed recently listing nine settings to turn on in an AI assistant: pick the most capable model, raise the effort level, enable web search, connect Gmail and Google Drive, save a few skills, organize projects, switch on a shared workspace mode, write custom instructions, and turn on memory. Framed as a productivity upgrade, most of it is genuinely harmless. One setting on that list, connecting the AI assistant to email and file storage, is not a productivity toggle. It is a data governance decision, and it is the one most executives click through without a second thought.
That distinction matters because AI tool settings are no longer a personal preference question. They are quietly becoming an access control question, and access control has always belonged to governance, not to whichever employee reads the checklist first.

Why It Matters
The scale of this is larger than most leadership teams assume. Nearly half of employees have already shared sensitive company data with third-party AI providers they have no data processing agreement with, and shadow use of unauthorized AI tools has become common enough that it now shows up directly in breach economics: IBM's 2025 Cost of a Data Breach Report found that shadow AI was a factor in one in five breaches, adding an average of $670,000 in additional cost per incident. None of that requires a sophisticated attacker. It requires an employee turning on a connector because a checklist told them it would make their AI assistant more useful.
The connector risk specifically is well documented outside the AI context, and AI tools inherit it directly. Enterprises typically run dozens of third-party applications connected through OAuth into core platforms, and the access those connections grant, once approved, does not expire on its own; it persists until someone actively revokes it, and most organizations lack full visibility into what is still connected months later. An AI assistant with a live connector to email and file storage is that exact pattern, granted by an individual, in minutes, usually without IT or legal ever being consulted.
The Core Framework: Which Settings Are Preferences and Which Are Governance Decisions
Most of the settings on a typical "AI tool checklist" sort cleanly into one of two categories, and the confusion happens when they get treated identically. Model selection and effort level are cost and quality preferences. Choosing a more capable model for complex work and a faster one for routine tasks is a legitimate productivity decision, and it belongs to the individual or team using the tool, with a light cost-governance check from finance if usage scales.
Skills, projects, and custom instructions are process preferences with a light governance layer. They encode how someone wants the AI to work, which is fine, but because that encoding persists and repeats across every future session, it deserves a brief review the same way a saved email template or a macro would, since a flawed instruction now runs automatically every time rather than once.
Web search is a provenance question. An AI assistant pulling live information from the internet on someone's behalf needs the same scrutiny applied to any external source cited in a business document: is the output checked before it is relied on.
Connectors and memory are the real governance layer, and they deserve to be treated differently from everything else on the list. A connector is a live, standing grant of access to a real system, exactly the kind of OAuth relationship security teams already struggle to inventory, and memory means whatever the assistant learns in one context persists into every future one, which is convenient and also means a single mistake in what it was taught keeps repeating quietly until someone notices.
Governance Section
What is leadership's role? Decide, as a matter of policy, that connectors are approved individually, not enabled by default because a checklist recommended it. Gartner's own research on the workforce finds that 65% of employees are excited to use AI at work, which is a real adoption tailwind, but enthusiasm is exactly why the connector decision needs a policy rather than individual judgment applied inconsistently across the organization.
What risks exist? An AI assistant with mail and file access effectively becomes a new identity with its own permissions inside the organization, and NIST's AI Risk Management Framework treats exactly this kind of access as something to be mapped, measured, and governed like any other operational risk, not assumed safe because it sits inside a familiar consumer-style settings menu. The second risk is memory drift: an assistant that has silently learned an inaccurate assumption about a client, a deal, or a policy, and keeps applying it because nobody audits what it has retained.
What metrics matter? How many employees have an active AI connector to company email or file storage, how many of those connections were ever formally approved, and how long it has been since anyone reviewed what a given assistant's memory or custom instructions actually contain. MIT Sloan Management Review's research on AI adoption found that employees typically start using tools like this on their own initiative, ahead of any policy, which means the honest starting number for most organizations is close to zero visibility.
What oversight is required? A simple registration step for any AI connector touching company systems, paired with a periodic review of what each assistant's memory and custom instructions have accumulated, reported with the same seriousness as any other access review, not folded into a general IT update.
Executive Actions
CIOs and CISOs should treat AI connectors exactly like any other OAuth grant, requiring approval, defined scope, and a revocation trigger tied to role changes, the same discipline already expected for every other SaaS integration. CEOs should ask, plainly, how many people in the organization have already connected an AI assistant to their email or drive, because only 27% of organizations report comprehensive visibility into how employees actually use AI, which means most leaders are answering that question with a guess. Boards should expect this inventory the same way they expect a vendor list, since Gartner has separately found that only 27% of executives report having a comprehensive AI strategy in place, and a connector inventory is one of the fastest ways to close that gap without slowing adoption down. This is the discipline BetterWorld Technology builds into its managed cybersecurity compliance practice for every new tool that requests standing access to company systems.
Final Thoughts
Most of the nine settings on that checklist are exactly what they look like: sensible defaults that make an AI assistant more useful. Two of them, connectors and memory, are not settings at all in the governance sense, they are standing decisions about who and what has access to company data, and they deserve the same scrutiny as any other access grant, not a single click because a list said to turn it on. Harvard Business Review's research found that only 6% of companies fully trust AI agents to run core business processes autonomously, and that gap between trust and adoption closes fastest when leadership can actually say what every connected AI tool has access to, not when it pretends the question does not apply below the executive level. For more on how BetterWorld Technology helps leadership teams build that inventory, see the AI governance advisory practice and the companion piece on AI voice cloning governance, and for the broader operating discipline behind both, see Working Excellence's guidance on scaling personal leadership systems.




Comments