{"id":8162,"date":"2026-08-01T06:51:36","date_gmt":"2026-08-01T06:51:36","guid":{"rendered":"https:\/\/dextora.agency\/insights\/ai-governance-for-business-rules-to-write-now\/"},"modified":"2026-08-01T08:38:27","modified_gmt":"2026-08-01T08:38:27","slug":"ai-governance-for-business-rules-to-write-now","status":"publish","type":"insight","link":"https:\/\/dextora.agency\/en\/insights\/ai-governance-for-business-rules-to-write-now\/","title":{"rendered":"AI Governance for Business: The Rules Worth Writing Down Right Now"},"content":{"rendered":"<p>Most companies already use AI: someone writes copy with it, someone translates emails, someone uploads a spreadsheet of client data to produce a quick summary. It happens without rules, because nobody set any.<\/p>\n<p>While the tools were used in isolation this went unnoticed. That is changing from two directions: regulation in the European Union is progressively taking effect, and the volume of data employees pass into external services grows faster than anyone notices.<\/p>\n<p>A caveat up front: your specific obligations depend on country, company size and what exactly you do with AI. Check your position with a lawyer. What follows is the organisational part, useful regardless of jurisdiction.<\/p>\n<h2>Why rules matter even in a small company<\/h2>\n<p>Not for the sake of regulatory compliance. For three specific risks:<\/p>\n<ul>\n<li><strong>Data leakage.<\/strong> An employee pastes a client list with phone numbers into a chat to sort it. The data went to a third-party provider and you do not know about it.<\/li>\n<li><strong>An unchecked error.<\/strong> Generated text containing an invented figure goes to a client or into a proposal.<\/li>\n<li><strong>Unclear accountability.<\/strong> When the error surfaces, it turns out a model made the decision and no owner was assigned.<\/li>\n<\/ul>\n<p>All three are closed not by technology but by agreements written on a single page.<\/p>\n<h2>A minimum policy: seven points<\/h2>\n<table>\n<thead>\n<tr>\n<th>Point<\/th>\n<th>What it fixes<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Approved tools<\/td>\n<td>A list of services allowed for work tasks<\/td>\n<\/tr>\n<tr>\n<td>Prohibited data<\/td>\n<td>What must never be pasted: client personal data, contracts, passwords, financial documents<\/td>\n<\/tr>\n<tr>\n<td>Mandatory review<\/td>\n<td>Which outputs never proceed without a human: anything a client sees<\/td>\n<\/tr>\n<tr>\n<td>Disclosure<\/td>\n<td>When we tell a client that text or a reply was generated<\/td>\n<\/tr>\n<tr>\n<td>Owner<\/td>\n<td>Who decides on new tools and answers questions<\/td>\n<\/tr>\n<tr>\n<td>Usage log<\/td>\n<td>Where we record which tool is used for which task<\/td>\n<\/tr>\n<tr>\n<td>Review cycle<\/td>\n<td>Quarterly reconciliation of the list against actual practice<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This is not a twelve-page document. It is one page people will read and remember. A policy nobody opens is worse than none: it creates the impression the question is settled.<\/p>\n<h2>Data is the main risk<\/h2>\n<p>Leaks usually happen not through a breach but through convenience: pasting the whole spreadsheet is faster than stripping out what does not belong.<\/p>\n<p>A practical rule that works better than prohibitions: <strong>if you could not email this data to an outside company, you cannot paste it into an external service<\/strong>. The wording is clear without explanation and requires no knowledge of terminology.<\/p>\n<p>What to check in the services themselves:<\/p>\n<ul>\n<li>Whether your data is used for training and whether that can be switched off.<\/li>\n<li>Where data is physically stored and for how long.<\/li>\n<li>Whether a business plan exists with different processing terms.<\/li>\n<li>What happens to history when an account is deleted.<\/li>\n<\/ul>\n<p>This is the same <a href=\"https:\/\/dextora.agency\/en\/insights\/vendor-risk-checklist-before-integrating-services-guide\/\">vendor<\/a> check you would run for any other service receiving data. There is no difference, yet it gets done less often.<\/p>\n<h2>Classifying tasks by risk<\/h2>\n<p>Rather than a blanket ban, it is more useful to split tasks by the consequence of an error. The same principle applies as with <a href=\"https:\/\/dextora.agency\/en\/insights\/ai-agents-in-business-processes-where-they-work\/\">AI agents<\/a>: the question is not whether the model will be wrong, but who will notice.<\/p>\n<table>\n<thead>\n<tr>\n<th>Level<\/th>\n<th>Examples<\/th>\n<th>Mode<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Low<\/td>\n<td>Draft copy, meeting summary, ideas<\/td>\n<td>Unrestricted<\/td>\n<\/tr>\n<tr>\n<td>Medium<\/td>\n<td>Client email, service description, translation<\/td>\n<td>Human review required<\/td>\n<\/tr>\n<tr>\n<td>High<\/td>\n<td>Legal text, calculations, client data<\/td>\n<td>Only with the owner&#8217;s approval<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>What to write down today<\/h2>\n<p>A sequence that takes an hour and closes most of the risk:<\/p>\n<ol>\n<li>Ask the team which tools they already use. The list is usually longer than expected.<\/li>\n<li>Pick two or three from it and make them official. Do not ostentatiously ban the rest, simply stop recommending them.<\/li>\n<li>Write one sentence about prohibited data using the wording above.<\/li>\n<li>Name the person people go to with &#8220;is this allowed&#8221;.<\/li>\n<li>Agree that anything a client sees is read by a human before it goes out.<\/li>\n<\/ol>\n<h2>On disclosure<\/h2>\n<p>A question with no universal answer: should you tell clients that text was generated.<\/p>\n<p>A practical guide: disclose where knowing it might change the person&#8217;s decision. An automated chat reply, yes, say so plainly. A draft proposal that a salesperson rewrote and checked, no, that is an ordinary tool like a word processor.<\/p>\n<p>The line is drawn not by whether a model was involved, but by whether there is a person behind the output who answers for it personally.<\/p>\n<p>AI usage rules look excessive for a ten-person company right now. Within a year they will be as routine a document as a password policy. It is cheaper to write them while they still fit on one page than to work out later which data went where over two untracked years.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Three risks closed by agreements rather than technology, a seven-point minimum policy, a one-sentence rule about prohibited data, task classification by risk, and what to write down within an hour.<\/p>\n","protected":false},"author":5,"featured_media":8158,"template":"","insight_category":[156],"insight_tag":[174,168,186],"class_list":["post-8162","insight","type-insight","status-publish","has-post-thumbnail","hentry","insight_category-trends","insight_tag-ai-search","insight_tag-business-process","insight_tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/dextora.agency\/en\/wp-json\/wp\/v2\/insight\/8162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dextora.agency\/en\/wp-json\/wp\/v2\/insight"}],"about":[{"href":"https:\/\/dextora.agency\/en\/wp-json\/wp\/v2\/types\/insight"}],"author":[{"embeddable":true,"href":"https:\/\/dextora.agency\/en\/wp-json\/wp\/v2\/users\/5"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dextora.agency\/en\/wp-json\/wp\/v2\/media\/8158"}],"wp:attachment":[{"href":"https:\/\/dextora.agency\/en\/wp-json\/wp\/v2\/media?parent=8162"}],"wp:term":[{"taxonomy":"insight_category","embeddable":true,"href":"https:\/\/dextora.agency\/en\/wp-json\/wp\/v2\/insight_category?post=8162"},{"taxonomy":"insight_tag","embeddable":true,"href":"https:\/\/dextora.agency\/en\/wp-json\/wp\/v2\/insight_tag?post=8162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}