AI Governance for Business: The Rules Worth Writing Down Right Now
Most companies already use AI: someone writes copy with it, someone translates emails, someone uploads a spreadsheet of client data to produce a quick summary. It happens without rules, because nobody set any.
While the tools were used in isolation this went unnoticed. That is changing from two directions: regulation in the European Union is progressively taking effect, and the volume of data employees pass into external services grows faster than anyone notices.
A caveat up front: your specific obligations depend on country, company size and what exactly you do with AI. Check your position with a lawyer. What follows is the organisational part, useful regardless of jurisdiction.
Why rules matter even in a small company
Not for the sake of regulatory compliance. For three specific risks:
- Data leakage. An employee pastes a client list with phone numbers into a chat to sort it. The data went to a third-party provider and you do not know about it.
- An unchecked error. Generated text containing an invented figure goes to a client or into a proposal.
- Unclear accountability. When the error surfaces, it turns out a model made the decision and no owner was assigned.
All three are closed not by technology but by agreements written on a single page.
A minimum policy: seven points
| Point | What it fixes |
|---|---|
| Approved tools | A list of services allowed for work tasks |
| Prohibited data | What must never be pasted: client personal data, contracts, passwords, financial documents |
| Mandatory review | Which outputs never proceed without a human: anything a client sees |
| Disclosure | When we tell a client that text or a reply was generated |
| Owner | Who decides on new tools and answers questions |
| Usage log | Where we record which tool is used for which task |
| Review cycle | Quarterly reconciliation of the list against actual practice |
This is not a twelve-page document. It is one page people will read and remember. A policy nobody opens is worse than none: it creates the impression the question is settled.
Data is the main risk
Leaks usually happen not through a breach but through convenience: pasting the whole spreadsheet is faster than stripping out what does not belong.
A practical rule that works better than prohibitions: if you could not email this data to an outside company, you cannot paste it into an external service. The wording is clear without explanation and requires no knowledge of terminology.
What to check in the services themselves:
- Whether your data is used for training and whether that can be switched off.
- Where data is physically stored and for how long.
- Whether a business plan exists with different processing terms.
- What happens to history when an account is deleted.
This is the same vendor check you would run for any other service receiving data. There is no difference, yet it gets done less often.
Classifying tasks by risk
Rather than a blanket ban, it is more useful to split tasks by the consequence of an error. The same principle applies as with AI agents: the question is not whether the model will be wrong, but who will notice.
| Level | Examples | Mode |
|---|---|---|
| Low | Draft copy, meeting summary, ideas | Unrestricted |
| Medium | Client email, service description, translation | Human review required |
| High | Legal text, calculations, client data | Only with the owner’s approval |
What to write down today
A sequence that takes an hour and closes most of the risk:
- Ask the team which tools they already use. The list is usually longer than expected.
- Pick two or three from it and make them official. Do not ostentatiously ban the rest, simply stop recommending them.
- Write one sentence about prohibited data using the wording above.
- Name the person people go to with “is this allowed”.
- Agree that anything a client sees is read by a human before it goes out.
On disclosure
A question with no universal answer: should you tell clients that text was generated.
A practical guide: disclose where knowing it might change the person’s decision. An automated chat reply, yes, say so plainly. A draft proposal that a salesperson rewrote and checked, no, that is an ordinary tool like a word processor.
The line is drawn not by whether a model was involved, but by whether there is a person behind the output who answers for it personally.
AI usage rules look excessive for a ten-person company right now. Within a year they will be as routine a document as a password policy. It is cheaper to write them while they still fit on one page than to work out later which data went where over two untracked years.








