There is a striking irony at the center of US AI policy right now. The people writing the rules for some of the most powerful AI systems ever built are not allowed to use them.
An NPR investigation published today found that US Senate lawmakers and their staff are barred from accessing the most advanced AI tools currently on the market. While they can use Microsoft Copilot Chat, Gemini Chat for Google Workspace, and OpenAI’s ChatGPT Enterprise, the sergeant at arms has not authorised the more capable tools that sit at the centre of the regulatory debate happening just a few floors away.
This is not a minor administrative detail. It is a signal worth paying attention to if you run a business that is building with AI.
What Senators Can and Cannot Use
Senate staff have approved access to three AI chat interfaces:
- Microsoft Copilot Chat — the productivity-layer assistant bundled with Microsoft 365
- Gemini Chat for Google Workspace Enterprise Plus — Google’s enterprise AI assistant
- OpenAI ChatGPT Enterprise — the business-tier version of ChatGPT
What they cannot use includes the agentic, autonomous, and reasoning-capable systems that have become the real frontier of enterprise AI in 2026. The advanced tools now central to regulatory conversations — models capable of multi-step reasoning, extended autonomous tasks, and complex decision support — are off limits to the lawmakers debating whether and how to regulate them.
The reason is security. The Senate’s approach to AI access reflects a precautionary stance: allow productivity tools with well-understood risk profiles, restrict autonomous or highly capable systems where the security implications are less clear.
Why This Matters More Than It Looks
The immediate reaction to this story might be something like: of course Congress doesn’t understand AI, this is nothing new.
But the more useful reading is different. The Senate is not alone. The gap between what advanced AI can do and the practical reality of most organisations’ AI access is enormous. Most companies are still running pilots. Most procurement teams are still evaluating tools. Most compliance teams are still trying to figure out what questions to even ask.
The Senate’s situation is an extreme version of something happening across enterprise organisations everywhere: the people who need to make high-stakes decisions about AI governance, procurement, and deployment are often the least equipped to do it from direct experience.
This creates a specific problem for business leaders. AI policy is being shaped by people who have not used the tools they are describing. And internal AI strategy is often being shaped by executives and boards who have had limited direct exposure to what modern AI agents actually do in practice.
The Governance Gap Is Real and Growing
What the Senate’s AI restrictions reveal is not just a congressional quirk. It is a governance gap that shows up in organisations of every size.
When the people setting the rules have not used the tools, you get policy that is either too cautious or misses the actual risks. When the executives approving AI budgets have not worked with AI agents directly, you get either naive enthusiasm or unfounded fear. When the compliance teams writing internal AI policies have not seen what an AI agent can actually do across a production system, you get policies that address the AI of three years ago rather than the AI being deployed today.
The Senate’s situation just makes this visible. They are writing rules for technology they are not permitted to experience firsthand.
What This Means for Business
Regulatory timelines will be slower than capability timelines. The disconnect between what AI can do and what the people making rules understand it can do is not closing fast. Businesses should assume that meaningful federal AI regulation will lag capability development by years, and plan accordingly. Relying on waiting for regulatory clarity is not a strategy.
Your internal governance gap is probably also real. If even the US Senate is struggling to get the right people access to the most capable AI tools, the same dynamic almost certainly exists inside your organisation. The business case for getting your leadership team direct experience with current AI systems is not just about enthusiasm. It is about the quality of decisions they will make about AI strategy, vendor selection, and deployment.
The vacuum creates risk. In the absence of clear federal regulation, the regulatory floor for US businesses is increasingly being set by state laws (California’s framework has effectively become the national baseline), sector regulators (financial services, healthcare, and energy are all developing AI-specific guidance), and international law (EU AI Act enforcement began August 2 and is now reaching beyond EU-headquartered companies). Companies that are waiting for a clear federal signal before building governance infrastructure are increasingly exposed.
Experience is the only way to close this gap. The Senate’s solution to its AI access problem — restrict access to manage risk — is understandable as a security posture. But for business leaders, the opposite approach is often the right one: controlled, deliberate exposure to frontier AI tools is how you build the judgment to govern them well.
Enterprise DNA’s advisory practice helps business leaders build practical AI literacy alongside governance frameworks that hold up as the regulatory environment evolves. If you are trying to understand what current AI can actually do for your operations, and what that means for your strategy, start with a discovery conversation.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideYour guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideSource
NPRTalk it through
Talk it through with Sam
30 minutes on what a Command Centre would look like for your business.
Book a call