AI governance and data readiness
AI use policy, data classification, and retrieval readiness before the first model touches production data.
Employees are already using AI, with or without a policy
By the time most companies write an AI use policy, employees have already been pasting customer data, contract terms, and internal documents into public chatbots for months. The policy conversation usually starts reactively, after someone notices, rather than proactively.
The harder problem isn't the policy document. It's knowing what data actually exists, how sensitive it is, and what happens to it if it's exposed to a model that logs or trains on prompts. Most companies genuinely don't know the answer.
Good AI governance makes the sanctioned path easier than the risky one: a clear policy, a data classification that tells people what's safe to use where, and, where useful, an approved internal tool that removes the reason to use an unapproved one.
What's included
- AI use policy developmentA practical policy that tells employees what's allowed, not a legal document nobody reads past the first paragraph.
- Data classificationIdentifying what data is sensitive, what tools it can safely touch, and what it never should.
- Vendor and tool risk assessmentEvaluating the AI tools already in use or being considered, against their actual data-handling terms.
- RAG and retrieval readinessAssessing whether your document sets and data are structured well enough to ground an AI system safely and accurately.
- Model risk reviewFor AI systems already in production, a review of failure modes, fallbacks, and what happens when the model is wrong.
- Training and rolloutGetting the policy adopted, not just published.
How the engagement runs
- 01Current-state reviewWhat AI tools are already in use, sanctioned or not, and what data has likely already touched them. Often the right starting point is our AI Readiness Assessment.
- 02Policy and classificationA usable policy and a data classification that gives employees a clear, fast answer.
- 03RolloutTraining and, where it helps, a sanctioned internal tool that makes the safe path the easy path.
Technologies and platforms
- Data classification frameworks
- Microsoft Purview
- RAG architectures
- Anthropic Claude
- OpenAI
Proof
We build production AI systems ourselves, which means we've had to answer these governance questions for our own data before answering them for a client's.
Common questions
We don't have any AI projects yet. Is this too early?
It's usually the right time. A policy and data classification built before the first project exists is far easier than retrofitting one after employees have already adopted tools on their own.
Does this cover public tools like ChatGPT, not just internal AI systems?
Yes. Most of the real exposure right now is in ungoverned use of public tools, not in formal internal AI projects.
Do you write the actual policy document?
Yes, in plain language employees will actually read, not a legal document that gets ignored.
How does this relate to compliance work?
AI governance increasingly overlaps with formal frameworks like HIPAA and CMMC. We flag that overlap when it applies to your situation.
Related services
Ask us what your employees are already pasting into ChatGPT.
Most companies are surprised by the honest answer. Better to know now than after an incident.