Create an AI policy people can understand and follow.
Employees are already using tools such as ChatGPT, Microsoft Copilot, Gemini and other AI services. A clear acceptable-use policy defines what is approved, how sensitive information should be handled, where human review is required and what to do when something goes wrong.
Focused engagement · tailored to your environment · designed to support rollout and ongoing governance
Give employees clear rules before AI use expands further.
AI use spreads quickly because the tools are easy to access. Policy gives teams a common baseline for approved use, sensitive information, accountability and escalation while broader governance and technical controls continue to mature.
Reduce Shadow AI risk
Clarify approved tools and processes so employees know where they can use AI and when additional review is required.
Protect information
Set expectations for confidential, personal, customer, regulated and proprietary information before it is entered into AI systems.
Set accountability
Define human review, verification, disclosure, exception handling and escalation for higher-risk uses.
A policy built around your business and current AI use.
Discovery
Review current AI use, approved platforms, business needs, sensitive information, existing policies and key stakeholders.
Policy draft
Develop clear rules for approved use, data handling, verification, restricted uses, accountability, exceptions and escalation.
Stakeholder review
Work through the draft with business, technology, security, privacy, legal, HR or other relevant stakeholders.
Rollout
Finalize the policy and provide guidance for communications, employee education, acknowledgement and periodic review.
Cover the decisions employees face every day.
- Approved and restricted AI tools
- Confidential, personal and sensitive information
- Customer and third-party data
- Human verification and accountability
- Intellectual property and generated content
- Higher-risk or regulated use cases
- Software development and code use where relevant
- Incidents, exceptions and escalation
- Policy ownership and review cadence
Grounded in recognized AI governance and security guidance.
We use relevant guidance from NIST AI RMF, ISO/IEC 42001, ISACA, Cloud Security Alliance and Canadian privacy/security sources to inform the policy while keeping the document readable and tailored to the organization.
Policy can become the foundation for broader governance.
Once the policy is in place, organizations can build on it with AI inventories, Shadow AI discovery, risk classification, approval workflows, training, technical controls, monitoring and recurring governance reviews.
AI Readiness Assessment
Get a directional view of governance and cybersecurity foundations.
Take the assessment →Governance
Build ownership, risk decisions, monitoring and ongoing review around AI use.
Explore Governance →Training & Adoption
Help employees understand the policy and apply it to real workflows.
Explore Adoption →Need an AI acceptable-use policy?
Tell us how your teams are using AI today and what policies or controls are already in place.
Get in touch →