
General-purpose AI like ChatGPT and Claude is one thing, but AI capabilities are now quietly built into the SaaS products and everyday work tools people already use — that's the reality of business in 2026. And it's no longer limited to specialists: it's now common for non-engineers to build their own work tools and automation flows using GitHub Copilot or generative AI.
As this convenience grows, new challenges are emerging for companies. It's becoming harder to see the full picture of AI use — not just the AI a company formally adopts, but also the AI employees use on their own judgment, AI features added later to existing tools, and automation flows that have naturally taken hold in day-to-day work.
What companies are being asked today isn't whether they use AI, but whether they've built a system for using AI safely, and whether they can explain the cause and response when something goes wrong.
This time, we asked Shinomiya, who works on AI governance and C Certification (AI Governance Core Certification), why companies should be considering C Certification now.
With the recent spread of AI use, how has the challenge companies need to face been changing?
The biggest thing, I think, is that the line for what counts as "AI-powered" has become very blurry.
In the past, AI services and non-AI work tools were relatively clearly separated. Companies could decide whether to allow use and set rules at the point of introducing a new AI service.
But now, AI features such as summarization or generation are increasingly being added later into SaaS and work tools that didn't originally have AI built in. I feel there are more and more cases where employees use these tools without even realizing, "AI is involved in this tool," or "the information I enter might be processed by AI."
On top of that, we're now in an era where even non-engineers can build simple work tools and automation flows themselves using generative AI like GitHub Copilot. That's extremely convenient, but it also means that new tools and workflows are being created every day in places the company isn't aware of.
That's exactly why what matters isn't whether you're using AI, but whether the company, as an organization, can grasp which AI is being used, by whom, and for what purpose.

Amid all this, what risks do you think are easy for companies to miss?
The biggest risk is so-called "shadow AI" — AI use that the company isn't aware of.
Employees aren't using AI in order to create risk. If anything, I think most cases come from good intentions — wanting to make their work more efficient, finish it faster, or produce a better result.
But if the company can't grasp that usage, it loses sight of what information is being entered and what decisions AI is being used for. Whether confidential information is being entered, how much the AI's output is being checked, whether people are using it with an understanding of the terms of service and how data is handled — all of that ends up left to individual judgment.
As with the GitHub Copilot example earlier, now that even non-engineers can easily build things themselves, there's a real possibility that work flows and automated systems involving confidential information are being created in places the company doesn't know about.
A situation where operations vary by department or by employee, depending on individual judgment and AI literacy, is, I think, something that's likely to lead to incidents down the road.
Why does it matter whether a company can fulfill its accountability when something happens?
I think this is a perspective that's going to become extremely important going forward.
For example, there's a big difference in how much trust a company gets depending on whether it can explain which AI was used, by whom, and under what rules, versus having to search for the cause starting from a state of having grasped nothing at all.
Even with a solid system in place, problems can still occur. But there's a completely different reception for a problem that happened after risks were understood and rules were set, versus one that happened because there was no management at all to begin with.
Going forward, I think being able to explain your own situation will become something demanded of every company, regardless of size.

What kind of companies need C Certification?
To give the conclusion first, I believe C Certification is a certification that will become necessary for every company that uses AI.
To repeat, AI use is no longer limited to a handful of leading-edge companies. That's exactly why it's important to be in a position where you can explain which AI your company is using, what information is being entered, and what rules govern how it's managed.
This is especially true for companies that are already using multiple AI services but haven't fully grasped the actual state of that use — for them, pursuing C Certification can be the trigger for building the core of an AI governance system.
C Certification checks whether the basic mechanisms for using AI safely are in place — grasping which AI is being used, a system for responding to risk, risk assessment, and risk response. That's exactly why I think it makes it easier to sort out where to start and build the system in a practical way.
Also, even for companies that already have an AI governance system in place, being able to demonstrate it externally in a form recognized by a third party can lead to greater trust and differentiation.
Some companies probably think, "We don't need to get this right away." What changes if they put it off?
Honestly, I think some companies feel that not getting it right away won't cause a major problem. But AI use within companies has already started spreading quite widely.
For example, the Ministry of Internal Affairs and Communications' FY2025 (Reiwa 7) White Paper on Information and Communications in Japan reports that 55.2% of Japanese companies use generative AI for some part of their operations. At the same time, roughly half of small and medium-sized enterprises have not clearly defined a policy for using generative AI.
In other words, while AI use is advancing, there are still many companies where policy and management systems haven't caught up. That's exactly why I think it's important to grasp the state of AI use within the company at an early stage — rather than dealing with everything at once later — and to put rules and risk-response systems in place.
This is strictly my own personal opinion, but I think C Certification could eventually come to be seen the way the Privacy Mark or ISMS are — as proof that a company has a certain baseline system in place.
That's exactly why I think it's important to grasp the actual state of AI use now and build a system you can explain, rather than scrambling to respond only once it becomes necessary. Starting early doesn't just limit future risk — I believe it also helps build up a company's trustworthiness.
Is there anything you'd like to say to companies now considering C Certification?
C Certification isn't meant to stop companies from using AI. It's meant to let companies keep using AI with peace of mind.
AI tools and AI features will keep increasing. In proportion, the risks that arise without anyone noticing will keep increasing too. If nothing is sorted out at this stage, you won't be able to explain the cause when something happens, and your response will end up lagging behind.
On the other hand, if you correctly grasp the risks and build a system you can explain, that in itself becomes a source of trust with business partners and customers. You can prove, not just in your own words but through a third party's eyes, that "our company uses AI responsibly." I think that's the state companies will need to be in going forward.
We've supported a great many companies in getting C Certification, and we've also been involved as assessors ourselves. That's exactly why we understand both how hard it is to build a system from zero, and what's actually asked and evaluated.
This is a subject we'd like companies to take seriously. But at the same time, we'd also like them to know there's a partner out there who can help sort through it with them.
It's fine to start simply by sorting out how AI is being used within your own company. If you have even a little anxiety or sense of a problem, reaching out early on means there's a lot we can think through together.
As a certified C Certification consulting firm, Elith supports companies in building AI governance systems and working toward C Certification. If you're facing challenges around setting rules and guidelines for using AI in your organization, or building an internal system, please feel free to reach out to us.
We also welcome inquiries at the stage of "we don't know where to start" or "we want to sort out where we currently stand." Even if the specifics aren't decided yet, we'll work with you to figure out an approach that fits your current situation.

