Ankit Kumar

Aug 12, 2026 • 4 min read

Beyond Blocking AI: Why We Built an AI Governance Gateway

Beyond Blocking AI: Why We Built an AI Governance Gateway

I wanted to write a little more about what we built during the AI Friday Regionals Final not just what the solution does, but why we made some of the decisions behind it.

As AI becomes part of everyday work, I think enterprises are moving into a difficult phase. Employees want to use AI because it genuinely improves productivity but organizations also need to protect sensitive data, follow internal policies and maintain control over how information is shared with external or internal AI systems.

For me, the interesting part of the problem was that the answer cannot simply be “allow AI” or “block AI.”

If an organization blocks AI completely, employees lose productivity and may eventually look for workarounds. On the other hand, unrestricted access creates obvious security, compliance and governance risks.

That led us to a different question:

Can we govern the interaction itself, instead of governing every AI tool separately?

Why We Chose a Gateway Approach

Our approach was to introduce an AI Governance Gateway between the employee and the AI system.

The idea is simple at a high level: before an employee request reaches an AI model, it can be evaluated against the organization’s business context, policies, and data boundaries.

Based on that evaluation, the request can be allowed, blocked, or escalated for human review.

What I personally liked about this approach is that it is not tied to one specific model or one specific AI application. The governance layer can sit independently between enterprise users and different AI systems.

That makes governance a shared capability rather than something every application has to solve independently. And we created chrome extension to check requests going to Chatgpt.com for demo.

Why Context Became Important

One of the things we realized while building this was that looking only at the content of a prompt is not enough.

The same request can mean very different things depending on who is making it, what business function they belong to, what type of data is involved and which policies apply to that situation.

A developer asking AI to explain a piece of generic code may be completely acceptable. The same interaction involving sensitive production code or confidential customer information may require a very different decision.

So instead of thinking only in terms of prompt filtering, we started thinking in terms of context-aware governance.

That was an important shift in how I looked at the problem.

Not Everything Should Be Fully Automated

Another decision we felt strongly about was keeping a human in the loop.

In enterprise environments, some situations are straightforward enough to handle through deterministic rules. Some are clearly prohibited. But there will always be cases where the answer depends on business judgment.

Rather than forcing the system to make a decision when confidence is low or the situation is ambiguous, we preferred having an escalation path where a human reviewer could make the final call.

For us, that thinking translated into enterprise AI governance. But again question arises here is does user has to wait until human approval is given and degrading User experience. Am already thinking on this part on how can we make this better, Let me know what you think on this?

Governance Should Enable AI, Not Just Restrict It

One of my biggest takeaways from working on this problem is that AI governance should not become another security layer whose primary objective is to stop employees from using AI.

The better objective, in my view, is to make AI usage safe enough that enterprises can confidently enable more of it.

That changes the conversation from:

“Should we allow employees to use AI?”

to:

“Under what context and boundaries should this AI interaction be allowed?”

That may sound like a small difference, but I think it leads to a very different way of designing enterprise AI systems.

The AI Friday Regionals Final gave us an opportunity to explore this idea and build a working version of it, but the larger problem goes far beyond a hackathon.

As AI adoption continues to increase, I believe organizations will need governance that is centralized, context-aware, model-independent and capable of combining automation with human judgment.

I would really like to hear how others are approaching this.

How is your organization governing employee use of AI today? Are you primarily relying on restrictions and policies or are you starting to introduce governance directly into the employee-to-AI interaction?

Would love to hear different perspectives in the comments.

Join Ankit on Peerlist!

Join amazing folks like Ankit and thousands of other builders on Peerlist.

peerlist.io/

It’s available... this username is available! 😃

Claim your username before it's too late!

This username is already taken, you’re a little late.😐

0

2

0