Itequia

Primero el diagnóstico, después la inversión: ¿por qué gobernar la IA no empieza por las herramientas?

Primero el diagnóstico, después la inversión: ¿por qué gobernar la IA no empieza por las herramientas?

When an organization decides to govern AI use, the natural tendency is to start with the solution. A control platform, a corporate policy, or a list of approved and banned tools.

The problem is that none of these decisions answer the fundamental question: what is actually happening inside the organization today?

The situation is becoming increasingly common. There are corporate Microsoft 365 Copilot licenses, specialized assistants in certain departments, and employees using different AI tools to solve specific needs in their daily work. At the same time, leadership needs to understand what value is being generated, what risks exist, and what the next steps should be.

This is exactly the moment when many organizations make the same mistake: investing before diagnosing. And, as in any other area of management, it's difficult to make good decisions when you don't yet have a reliable picture of the situation.

The usual reflex: buying before measuring

Faced with the need to govern AI, three responses tend to appear.

  1. The first is to purchase a control platform.
  2. The second is to draft a corporate usage policy.
  3. The third is to restrict or ban certain tools.

All are reasonable decisions. The problem isn't the chosen solution, but the timing of the decision.

A policy can hardly be applied if nobody knows which tools are actually being used. A platform will offer visibility over what it manages to detect, but not necessarily over the shadow AI that already exists beyond its reach. And bans tend to produce a well-known effect: business needs don't disappear, so usage doesn't disappear either — it simply becomes less visible.

In any other significant investment, leadership demands data before deciding. The situation is analyzed, opportunities and risks are identified, and only then is an action approved. The same should happen with AI. Before deciding what to control, what to allow, or where to invest, you need to understand what's happening.

What does it really mean to diagnose AI use? 3 perspectives

Many organizations equate an AI diagnosis with reviewing contracted licenses or building a tool inventory.

But that view is insufficient.

A useful diagnosis combines three complementary perspectives: reality, demand, and maturity.

Reality: what AI is actually being used

The first question is simple:

Which AI tools are currently in use? The answer is usually found in sources that already exist within the organization:

  • Login records.
  • OAuth consents granted by users.
  • DNS and proxy logs.
  • Corporate card spending.
  • Information available in ERP, procurement, and finance systems.

These sources allow you to build an objective picture of actual AI usage: which tools are used, how many users rely on them, which departments they appear in, and where solutions exist outside the corporate catalog.

It is, in short, the map of reality.

Demand: what teams actually need

There's something logs don't show. They don't explain why someone uses a tool. They don't indicate what problems they're trying to solve or what opportunities they perceive. That's why the second perspective involves listening to the teams.

Short, anonymous surveys reveal aspects that no technical data can capture:

  • Emerging use cases.
  • Unmet needs.
  • Adoption barriers.
  • Operational friction.
  • Automation opportunities.

The key is to frame these as an enablement and improvement initiative, not an audit. When employees perceive that the goal is to understand how they can work better, the answers tend to be far more useful and honest.

Maturity: where the organization stands

The third perspective answers a more strategic question:

What level of AI maturity has the organization reached?

It's not enough to know the tools or understand user needs. You also need to assess the company's capacity to govern that reality.

This means analyzing dimensions such as:

  • Strategy and governance.
  • Identity and data protection.
  • Technology architecture.
  • Training and adoption.
  • Operations and monitoring.
  • Measuring generated value.

The result is a picture that places the organization on an evolution scale, ranging from scattered, uncoordinated use to industrialized, governed adoption.

Why one perspective alone isn't enough

Each of these perspectives adds value.

But none works on its own. Telemetry without context can turn opportunities into problems. Surveys without objective data remain mere perceptions. And maturity models without real evidence risk becoming theoretical exercises. Combining all three offers a far more reliable view of the situation.

From diagnosis to action: the risk × value matrix

A good diagnosis doesn't end with a report. It ends with decisions. That's why the goal isn't to identify tools, but to understand what to do with the different AI use cases that already exist in the organization.

A practical way to do this is to classify them using a risk and value matrix. Each use case ends up placed in one of four possible actions:

  1. Automate. What adds value, carries low risk, and can be scaled quickly.
  2. Replace. Cases that generate value but could be handled more efficiently with corporate solutions already available.
  3. Control. Uses that add business value but require additional governance, security, or compliance measures.
  4. Let it flow. Low-risk cases where introducing more control would create more friction than benefit.

The most relevant quadrant is usually the high value, high risk one, because it typically contains tools already being used intensively to gain productivity. The answer is rarely to ban them. The usual approach is to channel that need toward corporate alternatives that offer the same value with an appropriate level of control. And this is precisely where investment starts to make sense. It's no longer driven by intuition — it's driven by data showing where a real opportunity or risk exists.

A proven method, not an experiment

At Itequia, we approach this process through an initial scoped engagement that combines three clearly defined phases.

  • Scoping. We define the scope, the teams involved, the available sources, and the questions the organization wants answered.
  • Analysis. We combine telemetry, maturity assessment, and perception analysis to build a complete, objective picture.
  • Results. We present leadership with a diagnostic report along with a prioritized action plan, focused on both reducing risk and generating value.

We also understand that this picture has limited shelf life.

AI adoption evolves quickly, new tools appear, and usage patterns change. That's why we approach the diagnosis as a repeatable exercise every three to six months, with comparable metrics to track evolution over time.

To support this, we bring experience working with complex organizations and proprietary tools such as Opinatics, our perception collection and analysis platform, which can even be deployed within the client's own Azure environment when required. 

Before governing AI, understand it

Most organizations don't have a tool problem. They have a visibility problem. Before deciding what to control, what to allow, what to block, or where to invest, you need to answer a much more basic question: how is AI actually being used within the organization? Only once you have that answer does it make sense to talk about platforms, policies, investments, or adoption plans. Because governing AI doesn't start with tools. It starts with diagnosis.

Want to know what a diagnosis would reveal in your organization? Schedule a 30-minute diagnostic session and we'll explain what we'd measure in your specific case, what information you could obtain, and how to turn it into a prioritized action plan for your organization. Get in touch today.