The tools are already in the building. The rules may not be.
The tools are already in the building. The rules may not be.
People are using models for research, mail, analysis, and drafts. The question is not whether. It is whether anyone has said what is allowed. A model predicts tokens. It does not check facts, and a file dropped into a consumer chat is not in your vault.
Three controls that fit on one page
What can go in. Public info and drafts with no client or employee names: fine. Client names, money, employees, proprietary process, legal, anything under an NDA: no. A team that researched buildings from public government data saved hours without leaking a thing. Make that line easy to see.
How they ask, and who reviews. Vague prompts make sloppy or risky output. Specific context makes it useful. Treat every result as a draft. Nothing goes to a client, a regulator, or the outside until a person reads it. High-risk docs (filings, proposals, numbers) get a real review even if the prose looks done. Internal scratch can be lighter.
Which tools. The list changes weekly. For each: where does the data go, is there an enterprise agreement or consumer terms, and how do people sign in? ChatGPT Enterprise and Claude for Enterprise are a different deal than the free tabs.
Ethics is not a later chapter
If a model denies a claim or scores a person, ask whether the training data is fair enough and whether a human still owns the call. Automated decisions about employees, customers, or partners are legal and reputational risk. People keep the last word.
You do not need a 40-page policy to start. A data guide, an approved-tool list, and a review rule by risk. Plus a way to raise a hand. The shops that do this well will not ban the tools. They will use them with those three lines in place.