AI Enablement
Your team is already using AI at work. The question is whether it is on terms you chose.
A written acceptable use policy, a sanctioned tool list, clear rules about what may never go into a prompt, and training so your staff know both.
Ask an owner whether their company uses AI and the answer is often no. Ask the staff and the answer is usually yes: drafting emails, summarizing documents, rewriting proposals, working through a spreadsheet problem. It happens on personal accounts, on personal devices, with whatever tool someone found.
None of that is misconduct. People are trying to get their work done faster, and mostly they are succeeding. The problem is that nobody has told them where the line is, so the line gets drawn accidentally, usually by whoever pastes a client contract into a free tool to get a summary.
Our scope here is deliberately narrow and we would rather be clear about it than oversell. We help you decide which tools are sanctioned, write the acceptable use policy in language your staff will actually follow, and train your people on both. We are not doing shadow AI discovery and we are not configuring AI tooling inside your environment. What we produce is the governance layer, and for most small businesses that is exactly the piece that is missing.
Talk through what you need →- Businesses that handle client data under an obligation, HIPAA, financial records, legal privilege or a contractual confidentiality term, where the wrong paste is a reportable problem rather than an embarrassment.
- Owners who have noticed AI use spreading through the company and want to allow it deliberately rather than either banning it, which does not work, or ignoring it, which is what is happening now.
- Companies being asked by clients or insurers whether they have an AI policy. That question is appearing on vendor questionnaires with increasing frequency.
Scope
What we produce
A written AI acceptable use policy
In plain language, built around how your team actually works rather than a generic template with your name at the top. A policy nobody can follow is a policy nobody follows.
A sanctioned tool list
Specific to the plan and the account, not just the brand name. The same product can behave very differently on a free consumer tier than on a business plan, particularly in what it does with what you put into it.
Clear data-handling rules
What may never go into a prompt, stated concretely: client records, protected health information, credentials, contracts under NDA, anything covered by an obligation you carry. And why, so the rule survives contact with a busy day.
Review and accountability rules
Who checks AI-assisted output before it reaches a customer, a contract or a filing, and who owns the result. AI output is confident regardless of whether it is correct, which is precisely the failure mode.
Staff training on safe use
What the policy says, what good use looks like, and where the risks are. Including AI-assisted phishing and voice cloning, which have made several old instincts unreliable.
Onboarding and review cadence
The policy folded into new-hire onboarding and revisited as the tools change, which they do constantly. A policy written once and filed is out of date within a year.
Process
How this works
This is a short engagement with a concrete deliverable, not an open-ended program.
- 01
Understand the work and the obligations
What your team does, what data they touch, and what you are bound by. A medical practice, a law office and a manufacturer need genuinely different rules, and a generic policy serves none of them.
- 02
Decide what is sanctioned
Which tools, on which plans, for which kinds of work. Approving something specific matters: if nothing is sanctioned, people use whatever they already have.
- 03
Write the policy
Plain language, short enough to be read, specific enough to be applied. Drafted with you rather than handed down, because the people doing the work know where the edge cases are.
- 04
Train and roll out
Staff trained on the policy and on safe use, the policy added to onboarding, and a point set to revisit it as the tools change.
Common questions
AI Adoption & Policy
Should we just ban AI tools instead?
Bans mostly move the activity onto personal devices and personal accounts, where you have no visibility at all. Deciding what is sanctioned and stating the data rules gives you a policy people can actually comply with, which is the only kind that changes anything.
Can you give us a template we can fill in ourselves?
We do not hand out a generic template. A policy that misses an obligation your business carries is worse than no policy, because it creates the appearance of governance without the substance. What we write is specific to your work and your obligations.
Do you configure the AI tools for us?
No, and we would rather say so plainly. Our scope is the policy, the sanctioned tool decision and the training. Configuring AI tooling inside your environment and discovering unsanctioned usage are separate problems we are not selling.
How is this different from our existing acceptable use policy?
Most existing policies predate these tools and address web browsing, software installation and email. They do not address what may be typed into a prompt, what happens to it afterwards, or who is accountable for output that turns out to be wrong.
What does AI have to do with security training?
Attackers use the same tools. The obvious tells in a phishing email, awkward phrasing and bad grammar, are gone, and voice cloning has undermined recognizing a voice on the phone as a verification method. Both change what staff need to be taught.
Related
Often paired with
Awareness Training
Continuous training and realistic phishing simulation that turns the person an attacker aims at into the person who reports the attempt.
Read more →Consulting & Assessments
Assessments with a written report, NIST CSF 2.0 posture scoring, cyber insurance and compliance questionnaire support, and a roadmap you can actually budget against.
Read more →Managed IT & Helpdesk
Helpdesk, patching, monitoring, backups, onboarding and offboarding for small and medium businesses across Central Kentucky. Not a break-fix number you call after something has already gone wrong.
Read more →Not sure where to start? Start with the assessment.
It is free, it takes about an hour of your time, and you walk away with a scored report either way.