TL;DR: Most IT decisions feel political because nobody was ever assigned to make them. Speed versus control, replace versus defer, security versus commercial pressure: these are business trade-offs sitting in an ownership gap, and IT absorbs the blame either way. Shadow AI is the current proof. Name the decider, name the default, and most of the politics goes away.
The hardest IT decisions have almost nothing to do with technology. One department wants speed. Another wants tighter control. Leadership wants lower risk and faster delivery and lower cost, ideally all at once.
The usual diagnosis is that this is politics, and navigating it is part of running technology. Build consensus. Read the room. Know when to push.
That’s not wrong, but it lets everyone off the hook. Look at the recurring arguments and they share a trait: each is a real business trade-off nobody has been assigned to make. So it gets settled by whoever pushes hardest that week, and the person running IT ends up owning a decision they were never given authority over.
You can watch this happen in real time with AI. Verizon’s 2026 Data Breach Investigations Report found that regular AI use on corporate devices tripled in a year, from 15% of employees to 45%, and 67% of those users signed in with personal accounts. Nobody approved that. Nobody rejected it either. It happened in the space where a decision should have been.
Why does IT leadership feel so political?
Because decisions with real business consequences have no named owner, so they get settled by influence instead of authority. When the rule is unwritten, the loudest team wins, and whoever runs technology absorbs the fallout whichever way it lands.
Notice the shape of it. Tighten a process and sales is frustrated and you’re the obstacle. Leave it loose and something goes wrong, and you’re the one who should have known. Both outcomes flow from the same missing sentence: who decides this.
It’s missing because nobody thinks of these as decisions. They feel like tensions to be managed, and tensions get managed forever. Decisions get made once and revisited on a schedule.
Shadow AI is what an unowned decision looks like
The AI numbers are worth sitting with, because they’re the cleanest example available.
Verizon found that shadow AI is now the third most common non-malicious insider action showing up in data loss prevention systems, a fourfold jump in one year, and that the leading data type going into unapproved AI tools is source code. Separately, 86% of IT leaders reported at least one negative incident tied to unapproved AI in the past year.
Here’s the part that matters. Surveys through 2026 keep finding that many employees using AI at work believe it’s against policy, and a meaningful share say they’d rather not ask than risk being told no.
Read that as an org chart problem rather than a discipline problem. People didn’t defy a decision. They routed around the absence of one, because their work got faster and nobody had told them where the line was. A written AI use policy and governance plan isn’t bureaucracy here. It’s the thing that stops 45% of your staff from deciding for you.
What only you can decide
This is where the division of labor gets useful, and where a lot of advice about delegation goes wrong.
Some of the work can be handed to anyone competent. Monitoring, patching, ticket triage, after-hours coverage, gathering evidence for an audit or insurance renewal: none of it requires knowing your business. It requires process and capacity.
Other parts can’t be handed over at all, because no vendor and no tool has the information. Software doesn’t know who resigned last month, which subscription finance approved, which client is fragile right now, or that the operations manager will quietly stop following any process that costs her twenty minutes. You know that. It’s why you’re in the room.
A third category shouldn’t be handed over even though people try. Accepting risk for the business, setting priorities, and deciding what gets deferred belong to leadership. When an IT provider or an internal IT lead absorbs those by default, everyone is comfortable right up until they aren’t.
How do you settle a recurring argument for good?
Write four things down for each one: who decides, who gets consulted, what happens by default if nobody responds, and when it gets reviewed. Four lines, one page, no framework required. The default clause is the part that does the heavy lifting.
Take the arguments you’re already having. Who approves a new tool that holds company data? Who decides whether a legacy platform gets replaced this year or deferred again? Who signs off when a security control will slow a team down?
Name a person for each, not a committee. Then write the default: if no answer comes within ten business days, the request is declined, or the control goes in, or the upgrade is scheduled. Silence currently defaults to whatever is easiest, which is why nothing resolves.
Bring the page to leadership as a decision, not a complaint. Most executives will sign it, because being asked “who owns this” is easier than being asked to settle a fight between two departments.
Who owns the friction?
Whoever benefits from the control, not whoever implemented it. If MFA on remote access slows the field team down, the person accountable for that friction is the leader who accepted the risk reduction, with IT explaining the trade-off rather than defending it alone.
That one change removes a surprising amount of resentment. Right now security friction arrives with an IT name on it, which makes every control feel like a preference instead of a business decision. This is worth working through with an outside advisor during a security review, since a third party can name the trade-off without inheriting the argument.
Move the name and the conversation changes. The control was chosen for a reason the business agreed to, and the person who agreed can say so.
What can you hand off, and what can’t you?
Hand off capacity, not judgment. Monitoring, patching, escalation, after-hours coverage, documentation, and the evidence-gathering that eats your week are all portable. Business context, relationships, priorities, and risk acceptance stay with you.
That distinction is the real case for co-managed IT support, and it’s more honest than “we’ll free up your time.” Time isn’t the scarce resource. Uninterrupted attention is. You can’t work through a decision rights conversation with leadership in the fifteen minutes between escalations.
The same split applies with no internal IT at all. Someone still owns the business context, usually the owner or an operations lead. Full managed IT services covers the rest, but the judgment stays in the building.
The takeaway
Politics is what you call a decision with no owner. Most of what makes technology leadership exhausting isn’t personalities. It’s the accumulated weight of choices nobody was assigned.
Pick the three arguments you’re tired of having. Write down who decides, who’s consulted, and what happens if nobody answers. You’ll resolve more in an afternoon than in a year of careful diplomacy.
If you want a second opinion on where those lines belong, or help taking the operational load off so you can go have the conversation, set up a short call.
Frequently Asked Questions
What is shadow AI and why does it matter?
Shadow AI is employees using AI tools that IT hasn’t approved or can’t see. Verizon’s 2026 report found regular AI use on corporate devices tripled to 45% of employees, with two-thirds signing in through personal accounts. Data going into those tools leaves your environment permanently.
How do you stop employees using unapproved AI tools?
Give them an approved one and write down the rules. Bans mostly move the activity out of sight. Pick a business-tier tool, state what data can and can’t go into it, and make the approved option good enough that nobody needs a workaround.
Who should own technology decisions in a small business?
Business trade-offs belong to business leaders, with IT advising on consequences. Assign a named decider for each recurring choice, along with a default outcome if nobody responds. Without that, decisions get made by whoever pushes hardest.
What should you delegate to an IT partner?
Capacity work: monitoring, patching, escalation, after-hours coverage, documentation, and evidence gathering for audits or insurance renewals. Keep business context, priorities, relationships, and risk acceptance in house, because no outside party has the information to hold them.
Is co-managed IT only for companies with an IT department?
Mostly, yes. Co-managed works alongside an internal IT lead or team who keeps direction and relationships while a partner carries operational load. Businesses without internal IT typically use a fully managed arrangement, though someone internal still owns the business decisions.
Decide Once, Instead of Arguing Every Quarter
If the same technology arguments keep resurfacing, the problem is structural rather than personal. Z-JAK helps Louisville companies sort out who owns what, then takes the operational weight off the people who shouldn’t be carrying it. Get in touch and we’ll talk through where the gaps are.
