Cybersecurity is about small, targeted moves: 20% of the right actions prevent 80% of the risk. Find your 20%: assess your exposure →

AI governance

AI acceptable use policy: govern without blocking

Your teams already use AI assistants. What that genuinely exposes, what a policy must contain, and why an outright ban produces the opposite effect.

Key points

  • AI is already in daily use in most organizations, generally with no written framework.
  • The main risk is not the model: it is what employees paste into it to move faster.
  • Banning without an alternative pushes usage onto personal accounts, where you see nothing.
  • A useful policy runs to a few pages and names tools, data categories and owners.

Shadow AI is already here

In almost every organization, AI assistants are used daily without management having authorized or forbidden it. This is not deliberate circumvention: the tools are free, reachable from a browser, and they save time on real work. An absence of rules prevents nothing: it merely makes the usage invisible.

The phenomenon has a name (shadow AI)and it closely resembles what happened with consumer file-sharing services fifteen years ago. The difference lies in the type of data involved: you do not share a file, you paste content to have it rewritten.

What gets pasted is exactly what causes the problem: a contract to summarize, a customer list to sort, a dispute email to rephrase, a code excerpt to fix. In other words, the most sensitive material in the business, chosen because it is the most time-consuming.

The first step of a policy is therefore not writing rules, but looking at what is already happening. Without that, you govern an imaginary practice.

What are the real risks?

Four, and only one is specific to AI. Disclosure of information to a third party outside your control, exposure of intellectual property, decisions based on unverified answers, and deepfakes used against you. The first three arise from usage; the fourth comes from outside.

  • Disclosure of personal information. Pasting a document containing personal information into a third-party service constitutes a disclosure to that third party. Depending on the tool, data may be retained, processed outside Quebec, and used to improve the service. Law 25 governs this kind of disclosure, including across borders.
  • Intellectual property and trade secrets. A quotation, a method, a source-code excerpt sent to a consumer service leaves the company's confidentiality perimeter, with no contract governing it.
  • Decisions on unverified answers. An assistant produces a plausible, well-phrased answer even when it is wrong. The risk is not the error; it is the confidence with which it is delivered.
  • Deepfakes and fraud. Cloned voices and faces are now used to lend credibility to payment requests. The countermeasure is procedural (verification through a separate channel)not technical.

What must an acceptable use policy contain?

Four things, and it fits in a few pages: which tools are approved, tolerated or forbidden; which data categories may be entered; what verification is required before acting on an answer; and who decides to add a tool to the list.

A longer policy will not be read, and a policy that merely forbids will not be followed. The objective is that an employee can answer, alone and within ten seconds, the question "can I paste this here".

  • The tool list. Name the services, not the categories. "Conversational assistants" means nothing to the person with a tab already open.
  • The data categories. Three levels are enough: what may be shared freely, what requires an approved tool, what never leaves. The classification is done with the business functions, not against them.
  • Verification rules. What must be reread, cross-checked or validated by a human before being sent to a client, published, or executed.
  • The addition process. Who reviews a tool request, against what criteria, and within what timeframe. Without this, the list is obsolete in three months and the policy with it.

Why an outright ban fails

Because it does not remove the need that created the usage. Blocking access from the corporate network moves the practice onto phones and personal accounts, where the organization sees nothing, logs nothing, and can govern nothing. The risk has not decreased: it has become invisible.

The dynamic is well known and not specific to AI. It played out with personal email, then file sharing, then mobile applications. Each time, a ban without an alternative produced silent circumvention.

The approach that works is to offer an approved route at least as convenient as the unofficial one. When an approved tool exists, is accessible, and does not slow the work down, most usage migrates to it on its own.

That is also the logic behind running AI on infrastructure you keep control of: rather than forbidding the usage, you move the processing into an environment where the confidentiality question is settled upstream.

Frequently asked questions

Blocking alone is a poor first move: it pushes usage onto phones and personal accounts, out of all visibility. It can have its place later, once an approved route exists and is genuinely usable: blocking then closes the residual alternatives rather than substituting for the policy.

It solves part of it. Business plans generally restrict reuse of content and provide account administration, which is a clear improvement. They do not answer the question of where processing happens, nor the classification of your own data: you still have to define what may be entered.

Sending personal information to a third-party service constitutes a disclosure to that third party, whatever the technology. The usual obligations therefore apply: purpose, contractual framing, and assessment before any disclosure outside Quebec. The conversational nature of the tool changes nothing about the legal regime.

With observation, not drafting. Asking teams which tools they use and for which tasks takes little time and gives a far more accurate picture than a technical audit. The policy is then written from that real usage; it will be shorter, more precise, and actually followed.

The same person who owns personal information protection, in most mid-sized organizations. The two subjects overlap heavily and separating them produces two documents that contradict each other. What matters is that an owner is named and has the time to review tool requests.

Sources

Is your infrastructure ready for the next threat?

An initial assessment, free and without commitment, to evaluate your security posture.

Home Expertise RISS 360 PME Assess Card