How to handle non-compliant AI tool usage without slowing down developers
GitHub explains that when developers buy and use their own AI tools, it often points to unmet needs rather than a simple compliance failure.
Overview
The video covers approaches for handling non-compliant AI tool usage in a way that avoids slowing down engineering teams.
Key points discussed:
- Why blanket bans often fail: broad prohibitions can push usage further underground instead of addressing the underlying demand.
- Provide safe, viable alternatives: organizations should offer approved options that meet developer needs so adoption is realistic.
- Open feedback loops: create channels where developers can explain what they need from AI tools and where current approved tooling falls short.
- Communities of practice: build internal groups to share patterns, guidance, and practical usage norms for approved AI tools.
- Encourage adoption of approved tools: focus on making compliant tools easy to access and useful enough that teams choose them.
Referenced resource:
- GitHub's Agentic Engineering System (AES): http://gh.io/aes-framework