Inventory the real workflows

Talk to the people doing the work. Which AI tools do they use, for which tasks, and what kind of context makes the output useful? An inventory based only on approved software misses the reason employees adopted other tools.

Publish a one-page starter policy

Define approved services, prohibited data, allowed low-risk tasks, account requirements, and an incident contact. Avoid treating every use of AI as equivalent. Writing a meeting agenda is not the same risk as uploading a payroll export.

Run a monitor-only period

Observe supported interactions without blocking. Review categories, deployment coverage, and false positives. Be explicit about what is and is not collected. Use the evidence to select controls instead of starting with maximum restriction.

Activate narrow protection

Begin with high-confidence credential patterns and validated financial identifiers. Add exact company terms carefully. Give employees a clear explanation, a usable redaction path, and a way to report false positives.

  • Block live authentication secrets
  • Redact supported financial identifiers
  • Warn on contextual customer PII
  • Review protected terms for overbreadth
  • Treat unsupported files honestly

Prepare for incidents

Even good controls can be disabled, bypassed, or miss content. Document credential rotation, internal reporting, provider contact, legal escalation, and customer communication decisions before an incident happens.