Establishing AI Governance Without Stifling Innovation: Lessons Learned
Billy Norwood (CISO · FFF Enterprises)
[un]prompted 2026 — AI Security Practitioner Conference · Day 1 · 2
Overview
Billy Norwood, CISO of $5B pharmaceutical distributor FFF Enterprises, walked through the hard lessons of building AI governance from scratch: the 40-project roadmap that hit reality, the AI usage policy that was too vague to be useful, and the intake processes that had to be rebuilt after every new use case exposed a gap. His central message — governance is about balancing value and risk, not blocking either. ---

Key moments
- 1:57 FFF: $5B pharma distributor with IoT drug fridges, 40 AI projects planned in waves
- 4:00 Tiered governance: CISO+CIO+general counsel at top, risk-based escalation model
- 5:59 Lesson: intake forms underestimated — need current process metrics and future goals
- 7:59 Single control plane: funnel AI through Databricks rather than fragmented shadow AI
- 10:00 PHI use case: AI-assisted pharmacy nurse documentation, compliance-heavy approval
- 13:59 Critical lesson: governance committee excluded security at start — major risk blind spot
- 15:59 Agent checkout model: catalog of vetted use cases with risk-tiered approval workflow
- 19:59 What worked: involving HR to reframe AI adoption as enablement not job threat
Establishing AI Governance Without Stifling Innovation: Lessons Learned
Speaker: Billy Norwood, CISO, FFF Enterprises
Conference: [un]prompted 2026 — The AI Security Practitioner Conference
Date: March 3–4, 2026, San Francisco
Watch on YouTube: https://www.youtube.com/watch?v=sh9LpVM1QBM
Reading time: ~9 minutes
TL;DR
Billy Norwood, CISO of $5B pharmaceutical distributor FFF Enterprises, walked through the hard lessons of building AI governance from scratch: the 40-project roadmap that hit reality, the AI usage policy that was too vague to be useful, and the intake processes that had to be rebuilt after every new use case exposed a gap. His central message — governance is about balancing value and risk, not blocking either.
Introduction
FFF Enterprises is not a tech company. The $5 billion pharmaceutical distributor is better known inside healthcare circles than outside them — they distribute specialty drugs, operate an online pharmacy, deploy IoT mini-fridge devices at hospitals and pharmacies, and employ nurses to consult on therapies. When the AI wave hit in 2025, their CIO didn't wait. He grabbed a consulting firm, convened VPs across the business, and produced a roadmap of 40 AI use cases slated for delivery in five waves by 2027.
Billy Norwood, the CISO, was not in the room for that conversation.
What followed was an accelerated, sometimes chaotic effort to build governance structures that could contain real risk while not killing momentum. At [un]prompted 2026, Norwood shared both what they built and — more usefully — what they would have done differently. The talk was candid in a way that polished vendor keynotes rarely are.
▶ Watch: Company background and the 40-project roadmap (00:00)
Starting Point: The 40-Use-Case Roadmap
The consulting-driven roadmap spanned HR automation, pharmacy workflows, logistics operations, medical pre-authorization, and customer service. The CEO initially resisted AI entirely; once he was convinced, he wanted everything immediately. That whiplash dynamic — "No AI" followed by "I want it now" — compressed the timeline and pulled in emergency budget that hadn't been planned for.
Norwood's team had to build governance structures in real time. Their first attempt was a high-level executive AI governance committee responsible for policy, ethics, and regulatory compliance. Below that, they built an AI Center of Excellence populated by VPs, directors, data science leads, infrastructure owners, and HR representatives. HR's involvement was deliberate — not everyone was excited about AI, and someone needed to run internal change management and counter the narrative that AI would eliminate jobs.
The Center of Excellence focused on standardized practices, shared services, embedded controls, access management, and monitoring. The long-term vision included a catalog of approved use cases that could be shared across departments and an AI review board — essentially an "agent checkout" — where teams could request and return agents for specific tasks.
▶ Watch: Governance committee structure and Center of Excellence (04:02)
What They Got Wrong the First Time
The first major lesson was that good-sounding governance structures don't automatically produce good controls.
The AI usage policy that wasn't. FFF's initial policy said, in essence, "Check with IT before you use AI." Legal and compliance signed off. Norwood approved it. In hindsight, it was useless. When business units started asking whether specific software packages with embedded AI features were permitted — questions that required clear answers about approved tools and prohibited use cases — the policy offered nothing concrete. A policy needs to name approved tools, list prohibited technologies, and specify which use cases are off-limits by category, not just tell employees to ask permission.
Intake forms that didn't ask the right questions. The early risk assessment intake forms were too shallow. Teams were asked broadly what they expected and how much technical work would be involved — but there was no structured process for understanding the current workflow, the target metrics, what data would be involved, or what the expected ROI looked like. Norwood described the intake process as something that has been "modified almost every new use case, because something comes up." That's a sign the initial design left too many gaps.
Access controls and "security OU spaghetti." FFF discovered that figuring out who has access to what — and ensuring AI agents received only the access they needed — was harder than anticipated due to accumulated organizational complexity in their Active Directory and permission structures. Norwood called it "security OU spaghetti." Cleaning it up became a prerequisite for safely expanding agent access.
▶ Watch: Lessons learned — policy gaps and intake failures (08:02)
The Use Cases That Worked
Despite the governance growing pains, FFF deployed several high-value AI use cases early — and one of them became the clearest proof point for executive buy-in.
Medical pre-authorization — a $250,000 use case. FFF handles specialty drugs, many of which insurers routinely deny on cost grounds. The pre-authorization workflow is painful: gather documentation, compile denial letters, assemble a complete case for a doctor to review. FFF built an agent that reads the denial letters, pulls all supporting documentation, packages it cleanly, and hands it to a physician for review and approval. The result: a workflow that previously consumed significant staff time now runs largely automated, with a human doctor retaining final authority. Norwood put the value of the use case at $250,000 in efficiency savings — and noted that his boss frequently cites it to anyone who'll listen.
Customer complaint resolution via multi-agent orchestration. FFF's second major deployment involves complex product return and dispute workflows. A customer complaint triggers an orchestrator agent inside Databricks that reaches out to SAP to pull ship dates, aggregates relevant documents, incorporates any images or video the customer uploads (including footage of packing processes for high-value items like $13,000 drug vials), and compiles a complete dossier for a human agent to review and respond. Each step in that chain — Databricks orchestration, SAP integration, video ingestion — represented a distinct security control point.
▶ Watch: Live use cases — medical pre-auth and complaint resolution (10:02)
What They Fixed: Practical Governance Improvements
The iteration between early stumbles and workable controls produced several concrete improvements worth adopting.
Tool-specific and use-case-specific policies. Rather than a blanket "check with IT" policy, FFF moved to explicitly named approved tools, specifically prohibited technologies, and categorized prohibited use cases. The policy now answers the questions that business units actually ask.
AI champion model in each department. After struggling to get security champions embedded across the business, FFF found that AI adoption was a much easier hook. Employees who might resist being a "security risk management champion" were more willing to become the department's AI expert. Those champions became the relay point for communicating governance requirements in both directions.
Scorecards for use-case prioritization. With 40 projects and multiple business divisions all pushing for priority, FFF developed scorecards that assess expected benefit, risk profile, technical complexity, and required human oversight. The governance committee uses the scorecards to sequence the project backlog rather than defaulting to whoever has the most executive momentum.
Human oversight as an explicit design choice. FFF explicitly documents where human review is required in each workflow. Given their domain — pharmaceutical distribution with regulatory exposure — they are "leaning toward" more human checkpoints rather than fewer. The pre-authorization workflow, for example, requires physician sign-off regardless of how confident the AI output looks.
Stricter third-party risk for AI vendors. Norwood described the team starting to add AI-specific questions to their procurement and third-party risk process: Does the vendor use AI on their backend? Where is data stored? What models are they using? These questions weren't part of the original vendor assessment framework.
▶ Watch: Governance improvements — champions, scorecards, oversight (12:02)
Q&A Highlights
The audience Q&A surfaced several sharply practical points.
On prompt injection: FFF's current defense for end users is the secure browser. If an employee navigates to ChatGPT, the browser redirects them to FFF's approved Microsoft Copilot instance. When code is pasted into a browser session, the secure browser strips API keys and credentials. On the agent side, FFF is relying on Databricks' internal controls — though Norwood acknowledged gaps remain.
On friction by design: When asked whether the intake form was friction-free, Norwood was direct: "The point is to insert friction." The intake form is meant to slow down requests enough that risk can be assessed. Because FFF controls the API keys and routes everything through Databricks, teams can't get very far without going through the process.
On the "system of context" question: The moderator raised the emerging concept of AI vendors competing to become the "system of context" — the central orchestration point for all enterprise data and actions — rather than a system of record. FFF's answer was pragmatic: their two main systems of record are Salesforce and SAP, but they're centralizing everything into Databricks and treating that as their system of context. They're building the layer themselves rather than ceding it to a vendor.
▶ Watch: Q&A — prompt injection, friction, and system of context (16:03)
Notable Quotes
"The point of governance is to balance the value and the risk."
— Billy Norwood, 06:02
"We created an AI usage policy that said, 'Hey, check with IT before you use AI.' We needed something way more specific."
— Billy Norwood, 08:02
"We designed this thing, but it grew legs. We were aiming for controlled execution, but it spawned child processes."
— Billy Norwood (via Copilot-generated summary), 16:03
"The point is to insert friction."
— Billy Norwood, on whether the intake form is friction-free, 20:03
Key Takeaways
- A generic AI usage policy is not governance. "Check with IT" doesn't answer the questions employees actually have. Policies need to name approved tools, enumerate prohibited technologies, and specify off-limits use cases.
- Intake forms need to capture baselines and ROI metrics upfront. If you don't record what the current workflow looks like and what success looks like before deploying, you can't measure whether the AI actually delivered value.
- HR belongs in your AI governance structure. Change management and internal adoption are as important as technical controls. Employees who fear job displacement won't use the tools, and employees who circumvent governance will find ways around it.
- The $250K use case argument wins executive support. A single high-visibility deployment with measurable financial impact does more for governance buy-in than months of policy documents.
- Friction is a feature of AI intake, not a bug. The goal is to slow down requests enough to assess risk — not to accelerate every idea to production. Governance committees exist to make prioritization decisions.
Slides Reference
Slides are available from the conference: 2026-04-04-D1-S2-9-39-Establishing-AI-Governance-Without-Stif.pdf. A transcript PDF is also available: 2026-04-04-Day1-Stage2-EstablishingAIGovernance-Norwood-txt.pdf. The slides cover the governance committee structure, the AI Center of Excellence model, use case intake and scorecard frameworks, and the multi-agent Databricks architecture.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
Norwood was candid about his failures, which is more than most CISOs manage, and the $250K pre-authorization use case is a real proof point. But this is a lessons-learned talk from a pharmaceutical distributor's AI governance growing pains — interesting for enterprise security leaders in regulated industries, wrong venue for a practitioner AI security conference.
Heather Calloway (CISO) — STRONG ACCEPT
Billy Norwood built AI governance under fire at a pharmaceutical distributor — 40 projects, a CEO who went from 'no AI' to 'I want it now' in one meeting, and a security team that wasn't in the room when the roadmap was drawn. The candor about what failed — the useless 'check with IT' policy, the shallow intake forms, the Active Directory spaghetti — is more useful than most polished governance frameworks.
→ Top-rated talks at [un]prompted 2026 — AI Security Practitioner Conference
All talks from [un]prompted 2026 — AI Security Practitioner Conference