AI is already inside your company. The question is where.
Nobody signed a contract, yet company data is already flowing to external models. Here is how to map what exists before writing a policy nobody will follow.
The conversation about enterprise AI almost always starts in the wrong place: “should we adopt AI?” It is already adopted. It arrived through personal accounts, browser extensions, and features switched on by default in software you already pay for.
Start by looking, not by banning
The first AI policy written in a hurry is nearly always a ban. It achieves two things: it changes nothing about actual usage, and it makes that usage invisible. People carry on, they just stop mentioning it.
An honest map beats a rule nobody follows. Concretely:
- AI features already live in the existing office suite
- Browser extensions installed on workstations
- Individual subscriptions expensed quietly
- Integrations bolted onto business SaaS, often enabled by default
That list surprises people every single time. It is the right starting point.
Three questions per use case
For each use case found, three questions are enough to triage:
- What data leaves? Public, internal, personal, regulated.
- To whom? Vendor, jurisdiction, contractual commitment on training.
- What happens if the output is wrong? A reviewed draft does not carry the same risk as an answer sent straight to a customer.
Most use cases land in the “no consequence” bucket. Isolating them lets you concentrate effort on the minority that genuinely matters.
The attack surface that comes with it
An agent wired into your tools becomes one more user — a user that follows instructions found in the data it reads.
Prompt injection is not theoretical. A document, an email or a web page can carry text aimed not at the human but at the assistant summarising it. If that assistant may send email or write into a system, the text becomes a command.
The rule is the same as everywhere else: least privilege. An agent gets only the access the described task requires, and a human stays on the irreversible decisions.
A policy people actually read
An acceptable use policy fits on two pages. Beyond that it does not get read, so it does not exist. What it must state: what is allowed without asking, what needs approval, what is off limits, and who to ask when a case is not covered.
The rest is technical implementation — and that part is allowed to run fifty pages.
- AI
- governance
- data
Also available in Français