Your staff are already using AI. The question is what's leaving with it.
Shadow AI discovery, an honest data exposure assessment, an acceptable-use policy people will actually follow, and the controls to keep sensitive work inside tooling you control.
45 min · Free · No commitment
Nobody asked permission, because the tools work
Somewhere in your business, someone is pasting a client contract into a free AI tool on a personal account to get a summary. They aren't being reckless. They're being efficient, using something that genuinely helps, that nobody told them not to use.
The problem is that the data is now outside your control, possibly retained, possibly used for training, and definitely not covered by whatever you tell clients about how their information is handled. If you're in a regulated industry, that gap is not theoretical — it's the kind of thing that surfaces during an audit or a claim.
Governance closes that gap without pretending the demand will go away. Approve good tools, control where prompts go, write a policy people will read, and log enough that you can answer questions with records rather than assurances.
What governance covers
Shadow AI discovery
An honest picture of which AI tools are already in use across the business, on which accounts, and for what. It is often more than leadership expects — usually because the tools genuinely help and nobody said not to.
Data exposure assessment
What has plausibly been pasted into consumer AI tools: client records, financials, contracts, patient or case details. We establish which categories of data are at risk and what your disclosure obligations look like if any of it is regulated.
Acceptable-use policy
A written policy in language your staff will actually read: what's approved, what's prohibited, what needs sign-off, and what to do when someone is unsure. Policies that only exist to satisfy an auditor get ignored, so this one is written to be followed.
Approved tooling & tenant controls
Moving people off personal accounts onto managed, company-controlled tooling where prompts stay inside your tenant — then turning on the controls that keep it that way. The goal is to make the compliant path the easy one.
Vendor & model risk review
What each AI vendor does with your inputs, whether they train on them, where the data is processed, and what their terms say about retention and deletion. These answers vary enormously between tools that look similar.
Audit trail & monitoring
Logging what was asked, by whom, and against what data — so that if a question is ever raised, whether by a client, a regulator, or an insurer, you can answer it with records instead of assurances.
Staff briefing
A short, practical session on what the policy means day to day. Most data leakage through AI is a well-meaning employee saving time, so the fix is understanding rather than enforcement.
What changes once it's in place
- A truthful picture of what AI is already in use across the business
- An acceptable-use policy staff can follow without a law degree
- Sensitive work moved onto tooling you actually control
- Vendor terms reviewed before data goes into them, not after
- An audit trail that answers a regulator's or insurer's question
Governance that survives contact with your staff
Shadow AI is a people problem first.
It happens because the tools work. Governance that ignores that gets routed around within a couple of weeks, so we design for the path of least resistance rather than against it.
We connect it to the security you already have.
AI governance isn't a separate program. It's identity, data classification, and logging — the controls we already run for you, extended to cover a new category of tool.
We write policies people read.
Plain English, one page where possible, with concrete examples from your actual business. A policy nobody finishes reading protects nobody.
AI governance questions
Should we just block ChatGPT and other AI tools?
Blocking on its own rarely works. People who find the tools useful move to their personal phones and home accounts, where you have no visibility at all. The approach that holds up is to approve a managed tool that covers the common needs, then block or restrict the rest — so the compliant path is also the convenient one.
What is the difference between a free AI account and a business one?
Business and enterprise tiers typically come with contractual terms on whether your inputs are used for training, how long they are retained, and where they are processed, plus admin controls and logging. The details vary a lot between vendors that look similar on the surface, which is why the vendor review reads the actual terms rather than the marketing page.
We are a small business. Do we really need an AI policy?
Size does not change the underlying problem: client data pasted into a free tool on a personal account has left your control. A small business needs a short policy rather than a long one — often a single page that says what is approved, what is off-limits, and who to ask.
Does AI governance make us compliant?
Not on its own, and we will not pretend otherwise. What it does is close a gap that auditors, clients, and cyber insurers increasingly ask about: where regulated data can flow into AI tools, and whether you can show records of it. We align the controls with the rest of your compliance program rather than running them as a separate project.
Ready to take this off your plate? Six questions.
Spend 90 seconds answering. We'll spend a few hours putting together a written assessment of where your IT stands — and a 45-minute call with one of our engineers.