AI Governance & AI Use Policy Services
Your people are already pasting emails, contracts, and spreadsheets into AI tools, mostly on personal accounts, with no rules and no visibility. An AI policy is how you keep the productivity and lose the risk. We write it, enforce it, and keep it current.
What is an AI policy?
Why you need one now
Shadow AI is already happening
Free and personal AI accounts don't give your company control over what happens to the data typed into them. If staff use them for work, client and company information leaves without anyone knowing.
Compliance rules still apply
HIPAA, attorney confidentiality, and financial privacy rules like GLBA don't pause for new technology. Patient data going into an AI tool without a business associate agreement is a real exposure.
Insurers and clients are asking
Cyber insurance renewals and client security questionnaires increasingly ask whether you govern AI use. "We haven't gotten to it" is a hard answer to give.
Is every AI policy the same?
No. A policy depends on the tools you use, your industry's rules, your client contracts, and how much risk you'll accept. Copying another company's policy gets you rules for tools you don't use, gaps in the compliance areas that matter to you, and no way to enforce any of it. It's like borrowing someone else's insurance policy: wrong name, wrong coverage.
Choose your approach
Prohibit
Block AI entirely. Rarely works; staff find workarounds on their phones.
Guardrails
Approved tools plus clear data rules. Where most small and mid-sized businesses land.
Managed and enabled
A company-wide AI platform with data loss prevention and monitoring. The mature end.
What goes into an AI policy
Acceptable use, a simple data classification (what's safe to use, what needs care, what never goes in), approved and prohibited tools, vendor and BAA requirements, who owns the policy, how violations are handled, and a review schedule. Every employee signs an acknowledgment.
How we enforce and monitor it
A lawyer can hand you a document. We make the rules hold in your systems.
Protect sensitive data
Data loss prevention rules in Microsoft Purview that stop restricted data from being pasted or uploaded into unapproved AI sites.
Find and block unapproved tools
Discovery of AI apps in use across your network and devices, and blocking of the ones you haven't approved, including personal accounts on otherwise-approved tools.
Control access
Company accounts with single sign-on and multi-factor authentication through Microsoft Entra, so access ends when someone leaves.
Ongoing monitoring
Regular review of alerts and AI usage, approved-tool list updates, and an annual policy refresh. The policy decays without it.
Leadership has to own it
An AI policy changes how everyone works. If management doesn't sponsor it and follow it, staff won't either. We help leadership set the direction and explain it to the team.
Built on recognized frameworks
Our approach aligns with the NIST AI Risk Management Framework and ISO/IEC 42001.
The path to an AI policy
Frequently Asked Questions
Why do we need an AI policy?
Because employees are likely already using AI tools with company data. A policy sets clear rules for which tools are allowed and what information can go into them, protecting client data and keeping you in line with regulations like HIPAA.
What does an AI policy do?
It defines approved AI tools, data handling rules, who approves new tools, and consequences for misuse. Paired with technical controls, it prevents sensitive data from leaking into unapproved AI services.
How do you enforce an AI policy?
Through technical controls (data loss prevention, blocking unapproved apps, company-managed accounts with single sign-on) plus training, signed acknowledgments, and ongoing monitoring.
Can we just use another company's AI policy?
Not effectively. A copied policy won't match your tools, industry regulations, or systems, so it can't be enforced and gives false confidence.
Should employees use personal ChatGPT accounts for work?
No. Company business or enterprise accounts give you contractual data protections and admin control. Personal accounts don't, so work data should stay off them.
Get ahead of AI risk
Start with a discovery conversation. We'll show you what's in use today and what to do about it.
