
Corporate AI use has already moved past the stage of debating whether to use it at all. AI features are built into more than just generative AI like ChatGPT and Claude — they're now embedded in the SaaS products and work tools people use every day, and the number of moments when employees use AI without even realizing it keeps growing.
At the same time, not many companies have a real grasp of which AI is being used, by whom, and how, within their own organization. As convenience takes the lead, there are cases where awareness of risks such as information leaks, misuse, and accountability hasn't caught up.
Amid this situation, C Certification (AI Governance Core Certification) is one entry point for building an AI governance system. So why has Elith positioned support for obtaining C Certification as a business, and what possibilities does it see there?
This time, Elith's CAIO Shimogauchi spoke with Murakami, who has known the C Certification support business since its launch, about the background behind turning it into a business, the challenges companies face around AI risk, and the significance of connecting C Certification with GENFLUX Security.
What background led to the start of C Certification support?
Murakami: Originally, as the use of generative AI spread, we had a growing sense that companies would need a system for using AI with peace of mind.
More companies are using generative AI in their work, but at the same time, there's still a lot that hasn't been sufficiently worked out about how to face risks such as information leaks, misuse, and grasping the state of usage. Using AI itself is becoming commonplace, but the system for managing and explaining that use hasn't caught up.
Amid that, we at Elith had been thinking from an early stage that a mechanism was needed for checking the reliability of AI use from a third-party perspective. Taking into account insurance-like thinking around information leaks and misuse involving generative AI, as well as the AI assurance trend advancing overseas, we were discussing that a certification would be needed for companies to demonstrate that they use AI with peace of mind.
As we repeated discussions on that issue with related companies and experts, it converged with the momentum toward formalizing a system at JDLA, and that led to the shape of C Certification. So rather than joining the system after the fact, we at Elith feel strongly that we were on the side that said, quite early on, "a certification like this will be needed," and helped give it shape.
I see C Certification not simply as a system for "getting certified," but as something that gives companies a trigger to review their own AI use, understand the risks, and build the systems they need. For Elith too, as a company working on AI governance and AI security, getting involved in this area was a natural progression.
Shimogauchi: That's very much like Elith, isn't it. Because we look at all sides — the side that builds AI, the side that uses it, and the side that protects it — we can't just stop at "it's become convenient." We have to go further and think about what companies should be able to explain.
GENFLUX Security is exactly an extension of that thinking. The more AI use advances, the more rapidly the AI used within a company increases. In fact, AI tools are said to already number more than 50,000 (source: Z Platform, "How Many AI Tools Are There?"), and AI features are being built one after another into existing SaaS products. Given that, it's realistically quite difficult to keep track of which AI employees are using and what information they're entering through surveys or interviews alone. That's exactly why I think a mechanism is needed that continuously makes visible what AI services are being used inside the company and where the risks are likely to be.

In the course of actually supporting companies, what challenges have you felt?
Murakami: The biggest one was that companies' awareness of AI risk hadn't caught up nearly as much as we'd expected.
For example: how is the information entered into an AI service handled? Could it be used to train the model? Could a human check it during content moderation? Things that a company involved in AI would naturally be concerned about often go almost entirely unconsidered at ordinary companies.
And it's not just employees on the front line. Even DX or IT departments sometimes haven't fully grasped the risks specific to AI.
For companies, AI is a convenient tool. They use it because it's convenient, because it speeds up their work. That feeling itself is natural. But when convenience comes first, discussion of risk — what shouldn't be entered, which AI is okay to use, how far you can trust the output — ends up put off.
That's exactly why I feel it's important, through support for getting C Certification, to first help companies understand where they currently stand.

When a company sets out to build AI governance, what should it start with first?
Murakami: Grasping which AI your company is using, what information is being entered, and what rules govern how it's managed.
In the process of getting C Certification, you organize things like your AI usage policy, a list of AI services, risk assessments, and risk response measures. In the course of creating these, companies often realize for the first time, "so this is the AI being used at our company," or "this is the kind of risk this use carries."
What matters isn't building a perfect system from the start. It's first making visible where you currently stand.
AI governance doesn't function on abstract principles alone. You need to look at the AI actually being used, the information actually being entered, and the situations where it's actually used for decisions, and then decide, as a company, how far to allow it and where to draw the line.
I think C Certification serves as a very clear goal for advancing that core part of AI governance.
Does the mindset on the company side change through this support?
Murakami: I think it does.
Even if a company starts out simply asking, "What do we need to do to get certified," many of them come to realize, as the support progresses, how difficult it is to judge their own risks by themselves.
For instance, even just creating AI usage rules isn't as simple as deciding "this is allowed" or "this isn't." Which tasks it's used for, what information is entered, how the output is checked, who takes responsibility when a problem occurs — there's actually a lot to think through.
In that process, an awareness grows that "it's difficult to keep making these judgments alone" and "we need to keep reviewing this even after certification." In fact, we sometimes get asked for ongoing support and operational improvement even after certification.
C Certification doesn't end once you obtain it. If anything, the real operation begins after you get it. I think helping companies realize that is a major part of the value of our support.
What's particularly difficult about operations after certification?
Murakami: The fact that the state of AI use keeps changing constantly.
Even if you build a list of AI services and put policies in place at the time of certification, the situation will have changed by six months or a year later. New AI tools appear, AI features keep getting added to existing SaaS, and some AI gets adopted by employees on their own initiative.
In other words, fixing things at the state they were in the moment you got certified isn't enough on its own. You need to continually take stock of AI use and review your rules.
What's especially difficult is AI use the company isn't aware of — so-called shadow AI. Employees usually aren't using it with malicious intent; more often they're using it to make their work more efficient. But as long as the company can't see it, it can't manage what information is being entered or what decisions it's being used for.
I think it's quite difficult to keep tracking this by human effort alone.
Shimogauchi: And now, it's not just generative AI services — AI features are starting to work their way into the everyday business SaaS people use too. From the perspective of someone on the ground, they're "just using their usual tool," but from the company's perspective, there's a real possibility that information is being processed by AI.
That's exactly why I think a mechanism is needed that can continuously grasp AI use inside the company, not just through usage applications or interviews.

Is that where the connection with GENFLUX Security becomes important?
Murakami: Yes. I think it's a very natural connection: use C Certification to build the foundation of AI governance, and use GENFLUX Security to support the operation that follows.
The state of AI use and the risks organized at the time of certification need to keep being reviewed even after certification. Being able to support that as a system is, I think, the value Elith can offer.
Shimogauchi: What we're trying to do with GENFLUX Security isn't to monitor a company's AI use in order to ban it. If anything, it's to make usage that isn't visible, visible, so companies can keep using AI.
For example, AI features are showing up not only in obvious generative AI like ChatGPT and Claude, but also inside the everyday work tools people use — meeting-notes tools, CRM, chat tools, design tools, development-support tools, and more. For people on the ground it's "just using their usual tool," but from the company's perspective, that can involve risks around AI processing, external transmission, use in training, and access control.
GENFLUX Security is a platform for taking stock of that kind of AI use inside a company — grasping which services are being used, which departments or devices the use is spreading across, and whether the AI that needs to be managed is increasing. At the time of getting C Certification, it can be used to build the AI service list and organize risk; after certification, it can also be used for ongoing monitoring toward renewal.
Certification is a check at a single point in time, but AI use changes day by day. That's exactly why you use C Certification to organize what needs to be managed, and GENFLUX Security to keep watching how it's actually being used. With this combination in place, I believe you can make AI governance something that actually operates, not just something on paper.
What significance do you think C Certification will come to hold going forward?
I think the significance of C Certification will keep growing.
C Certification is a certification companies can aim to obtain in a relatively short time. That's exactly why it could become a clear, easy-to-point-to way for AI-using companies to show they have a certain system in place.
Right now, we may still be at the stage where having it makes you look advanced. But as AI use becomes even more commonplace, there may come a time when companies are instead asked, "why haven't you gotten it," or "you use AI, so why can't you show your system?"
Especially for companies that handle customer information or confidential data, or that bear accountability to business partners, I think being able to show an AI governance system will lead to greater trust.
AI use is no longer a subject that can be left entirely to the front line. When an incident occurs, can management explain what it understood and what system it had in place? I think we're heading into an era where a company's trustworthiness is judged on that basis too.
Finally, is there anything you'd like to say to companies now considering C Certification?
C Certification isn't meant to stop companies from using AI. If anything, it's meant to let companies keep using AI with peace of mind.
AI will keep working its way further into everyday operations. AI features will be built not just into generative AI but into the tools and systems people already use. Stopping that trend entirely isn't realistic.
That's exactly why what matters isn't "don't let people use it," but "create a state where it can be used safely."
Grasp which AI your company is using. Sort out what risks exist. Build the rules and systems you need. And keep reviewing them continually even after certification.
I think C Certification is extremely effective as that first step. And Elith can support not just getting certified, but everything through to the operation and AI security that follow.
Precisely because we're entering an era where using AI is taken for granted, companies are being asked to reach a state where they can explain, "we can use AI responsibly." Building that state together with companies is, I believe, the meaning behind Elith's work supporting C Certification.
Closing
For companies, C Certification isn't just a target to obtain — it's an entry point for reviewing their own use of AI.
Which AI are you using? What information is being entered? Which risks are you willing to accept, and which do you need to address? And have you built a state where you can explain things if something happens?
The more commonplace AI use becomes, the more being able to answer these questions will lead to trust in a company.
Through support for C Certification, Elith helps build the core of AI governance and supports everything through to the operation and AI security that follow. We don't let certification be something you "just get and finish." We help build the system for continuing to use AI safely.
That's the reason Elith is committed to supporting C Certification.
As a certified C Certification consulting firm, Elith supports companies in building AI governance systems and working toward C Certification. If you're facing challenges around setting rules and guidelines for using AI in your organization, or building an internal system, please feel free to reach out to us.
We also welcome inquiries at the stage of "we don't know where to start" or "we want to sort out where we currently stand." Even if the specifics aren't decided yet, we'll work with you to figure out an approach that fits your current situation.

