AI Policy & Governance

Somewhere in your business, a good employee is deciding on their own whether a client name can go into a chatbot. Governance is how you stop asking people to guess. You get a written usage policy, an approved tool list, and vendor terms actually read. A few usable pages, not an enterprise framework nobody opens.

Book a Discovery Call

Four Documents, All Yours To Keep

01
Written AI Usage Policy

Plain language, a few pages, and specific to your business. What tools are approved, what data may never enter them, who reviews AI-assisted work, and what happens when someone is unsure. Yours to keep and edit.

02
Approved Tool List

A named list of what your team may use, with the account type and settings that make each one safe, so nobody has to interpret a principle to answer a Tuesday question.

03
Vendor & Data-Flow Review

We read the terms your team clicked past: whether inputs train the model, what retention actually is, where data is processed, and whether the vendor will sign a BAA or DPA if you need one.

04
Rollout & Sign-Off

A policy nobody was trained on is decoration. We brief the team live, answer the real questions, and give you a sign-off record and an onboarding version for new hires.

Three Reasons Clients Come To Us For This

Regulated Firms

Healthcare practices under HIPAA, law firms under state bar guidance and ABA Formal Opinion 512, advisors with recordkeeping duties, and public agencies under the California Public Records Act. Each needs the general policy plus its own specific lines drawn.

Firms Answering A Client Questionnaire

Enterprise clients and insurers increasingly ask whether you have an AI policy. A written, current, actually-followed policy turns that from a scramble into an attachment.

Firms That Just Want The Guessing To Stop

Most of the risk in a small business is not malice, it is a good employee making a reasonable guess about whether a client name can go in a prompt. Governance is how you stop asking people to guess.

We Don't Write Policies Nobody Reads.

A forty-page AI governance framework built for a company with a compliance department is worse than nothing for a twenty-person firm, because the length guarantees it goes unread and then gets cited as proof you were covered. We write the shortest policy that actually answers your team's real questions, and we are not lawyers, so anything that is genuinely a legal obligation gets flagged for your counsel rather than quietly absorbed into our scope.

Questions, Answered

What should an AI usage policy include?

At minimum: which AI tools are approved and in what account tier, what categories of data may never be entered, when AI-assisted output needs human review before it leaves the business, disclosure expectations for client-facing work, who to ask when something is unclear, and how the policy gets updated. For a small business that is a few pages, not a framework. Length is not the point; being specific enough to answer a real question is.

Is an AI policy a legal document? Do we need a lawyer?

We write the operational policy: the tool list, the data rules, the review steps, and the training. Where an obligation is genuinely legal, such as a BAA, a client contract amendment, an employment handbook change, or a bar-specific duty, that belongs with your counsel, and we flag exactly which items those are so nothing falls between us. Plenty of clients have their attorney review the finished policy, which we encourage.

Do we need this if we already banned AI?

A ban is a policy, but it is usually an unenforced one. Surveys consistently find employees using AI tools their employer has not approved, often on personal accounts where you have no visibility at all. A realistic policy with an approved path is safer in practice than a prohibition people quietly work around.

How is this different from the AI audit?

The policy and governance work is part of the two-week SafeStart Audit, alongside the tool inventory, data safety review, training, and roadmap. This page exists for businesses that specifically need the governance piece, whether because a client asked, a regulator changed something, or a board wants it in writing. If you need the full picture, the audit is the better starting point.

How often does the policy need updating?

More often than most businesses expect, because the tools change monthly and so do their terms. A policy naming a specific tool and setting can go stale in a quarter. Clients on retainer get it maintained as part of that; standalone clients get a policy built to be edited, with the parts most likely to change kept in one place.

Do we get to keep the deliverables?

Yes, all of them, in editable form. The policy, the tool list, and the vendor notes are your documents. We do not hold deliverables hostage to a retainer.

Related Insights

How to Write an AI Usage Policy

The sections a usable policy needs, and how to get it adopted.

Read the guide →
Is ChatGPT Safe for Business Data?

What leaks, which settings help, and how to build a safer workflow.

Read the guide →
Local LLM vs. Cloud AI: Which Is Safer?

When keeping the model on hardware you control is the right call.

Read the guide →

Start With A Free Conversation

A 30-minute discovery call, no pitch. Tell us how your business runs and we'll tell you honestly whether this is the right fit.

Book a Discovery Call