Write the AI use policy before you choose the AI tools
Your staff are already using it. The only decision still available is whether that happens through something sanctioned with a written position, or through a personal account with client material in it.
There is a version of the AI conversation that assumes the business gets to decide when it begins. That window closed. In any organisation of more than a handful of people, someone is already pasting work into an assistant, because it is genuinely useful and it takes ninety seconds to start.
So the real choice is not adoption. It is whether adoption is governed.
Why a personal account is the problem
Not the technology. The account.
Material pasted into a consumer service on a personal login sits outside your tenancy, outside your retention policy, outside your access controls, and outside your ability to answer a question about it. If a client asks whether their information has been disclosed to a third party, “probably, by someone, we are not sure which service” is not an answer any professional firm wants to give.
For businesses with confidentiality obligations in their contracts, that is potentially a breach that happened without anyone intending anything. For anyone holding personal information, it is a Privacy Act question about disclosure and about where data is held.
The same tool, licensed through the business and configured properly, changes most of that. Not all, and the difference is worth understanding rather than assuming a business licence solves everything.
What a usable policy contains
Short enough to be read. One page, ideally.
What is approved. Name the specific tools. “AI is permitted subject to policy” is not guidance, it is an invitation to interpret.
What must never go near it. This is the part people actually need. Client identifiable information, credentials, anything under an NDA, health information, personal information about staff. Be concrete, with examples from your business rather than categories.
Where the line is on outputs. Draft assistance is different from advice going out under your name. If a document leaves the building, a human is accountable for it and should have read it properly. Say so.
Disclosure obligations. Whether clients need to be told, and in what circumstances. Some contracts already require it.
Who to ask. A named person for the case the policy did not anticipate, because there will be one and the alternative is people guessing.
The order that saves money
Policy, then permissions, then tools.
The middle step is the one that gets skipped and causes the most regret. An assistant pointed at your own content is only as safe as your access control, because it is very good at finding material that was overshared years ago and never noticed. Rolling one out across a tenancy nobody has audited is an expensive way to discover your permissions model.
Once those two are settled, tool selection is comparatively easy, and the pilot has a chance of surviving.
What we would say about the technology itself
It is genuinely useful for a narrow set of things: extracting structure from messy input, triage and classification, drafting the repetitive document a person then edits, and summarising long records down to the exception worth a human’s attention.
It is unreliable for anything where being confidently wrong is expensive and nobody checks. Which is a design constraint, not a criticism, and it is why the good deployments keep a person on the decision and give the machine the shapeless part.
Where we sit
We deliver AI work and we govern it under the same frameworks as the rest of an environment, which is the whole argument: an AI tool with access to your data is part of your environment and belongs under the same identity, logging and access rules as everything else.
A one page policy is an afternoon. It is also the cheapest thing on this list and the one that prevents the incident.