Artificial intelligence is moving into the workplace at a remarkable pace. Depending on who you ask or the day, it is either going to revolutionize business or end civilization. The truth, as usual, is probably somewhere in the middle. What is not up for debate is that AI has become an extraordinarily useful business tool. The challenge isn’t AI. The challenge is making sure associates understand how and where to use it. I think there are three points worth keeping in mind.
1. Adopt an AI Acceptable Use Policy and Keep Updating It
An AI acceptable use policy sets the standard. Associates should not have to guess of what is expected of them. Guessing works reasonably well for barbecue recipes, but it works considerably less well for handling firm confidential information. The only fires you should be tending are in the smoker.
At a minimum, every firm’s policy should answer s:
- Which AI tools are approved?
- What information should never be entered into an AI platform?
- When should employees seek approval before using a new tool?
- What level of human review is expected before AI-assisted work is used?
Just as importantly, do not think of the policy as a one-and-done project. AI evolves too quickly for that. If your AI policy hasn’t been updated in some time, there is a decent chance your employees are already using tools it never contemplated.
I have yet to meet anyone who says, “You know what sounds like a fun afternoon? Updating the AI policy.” Nobody looks forward to getting up in time for a 5:30 a.m. workout, but you are usually glad you did it once it is over.
To help get started, please see the model AI Acceptable Use Policy. We hope it provides a practical starting point and saves you from reinventing the wheel.
Download the AI Acceptable Use Policy here.
2. Regularly Train on that Policy
I believe that most people don’t go to work to try to violate firm policy. They do it because they do not know what is expected of them. In using outside AI tools, they may see nothing wrong with a document going to a personal email account. A few paragraphs get copied into a public AI tool. The work comes back into the firm’s systems, and the day moves on.
Until it doesn’t. Convenience and efficiency are wonderful servants, but these can lead to a terrible decision-making. (That is a lesson that extends well beyond AI.) Just because a platform is free, or because everyone seems to be talking about it, doesn’t mean it’s appropriate for firm confidential information. “Everyone else is using it” has never been recognized as a compliance defense, and I don’t expect that to change anytime soon. Let them know what is expected.
3. Surveil Activity

One final point deserves attention.
Firms have always had an obligation to protect confidential information and supervise their business. AI hasn’t changed those responsibilities. It has simply created new risks. That means firms should be thinking carefully about how they monitor activity involving:
- Personal email accounts
- Unapproved AI applications
- Other methods of moving firm information outside the firm’s technology stack
None of this is meant to discourage firms from embracing AI. Quite the opposite. I think firms should be looking for thoughtful ways to incorporate these tools because the productivity benefits are real.
The firms that get the most from AI will not necessarily be the ones chasing every new platform. They will be the ones that establish clear expectations, revisit those expectations as the technology evolves, and make it easy for employees to do the right thing.
Good technology deserves good governance.
After all, my clients have businesses to run and clients to serve. I would much rather see them focused on those priorities than explaining avoidable technology decisions to a regulator.