Most companies think they don’t have an AI problem — until we find the tools employees are already using on the side. We had a client come to us in just that situation when there was an customer information leak on AI. They wanted help now on how to govern and manage AI, while also showing action on the issue.
Our team started with a scan of the organization’s existing policies and governance structure. With that knowledge, we then worked to see what client data was contained in each system, and which systems already had integrations with AI adjacent tools, compared to which ones may be tools people had quietly adopted on their own, without any oversight.
With all of this knowledge, we then worked with the governance team to draft two policies that helped govern AI usage on an individual user level, but also on an enterprise level. We also helped to create a policy on what protections should be employed on customer data against all systems. We also helped to setup a corporate structure of accounts that could be used with AI, but had appropriate controls.
From there, we tied the training on these policies to other AI training the organization was already offering on a new tool. In this way, we were able to structure this important training, on policy, also with training on systems that benefited the users.

