Free DIY Resource • AI Use, Policy & Governance
AI Use and Governance Checklist: 4 Checks You Can Run Yourself Today
Every unmanaged AI tool your team uses is a door into your company's confidential data, whether anyone intended it that way or not. Most organizations don't have a shadow IT problem with AI, they have a shadow AI problem: tools adopted department by department, account by account, with no one keeping track. Here's what's actually at stake, a few blind spots most leadership teams miss, and four checks you can run yourself in under an hour.
AI governance often gets treated as a policy-writing exercise, but the real risk usually starts well before any policy gets drafted, when an employee pastes a client's contract into a free AI tool to summarize it, and that data is now somewhere outside your control. None of the four checks below need a legal team or a formal AI strategy, just a clear look at what's actually happening across your organization today.
What's At Stake
- Confidential client data pasted into a public AI tool, with no way to know where it ends up or who else can see it.
- Shadow AI use that leadership only discovers after the fact, once it's already caused a problem.
- Your company's data training a vendor's AI model without your knowledge or consent, because nobody read the terms of service.
Other Blind Spots
- Employees using personal AI accounts for work tasks, entirely outside any company oversight or audit trail.
- AI-generated content going out under your company's name with no human review step in between.
- Vendor contracts that never actually say who owns the output, or the input data you fed in.
4 Checks You Can Run Yourself Today
0 of 4 complete
-
Ask each department which AI tools they're actually using. The tools IT approved and the tools people actually use are often two different lists, and the gap between them is where the risk lives. Ask directly, department by department, and expect the real answer to include more tools than your official list.
-
Check whether those logins are personal or free-tier accounts. A personal account sits entirely outside your company's oversight, audit trail, and data agreements, no matter how work-related the task is. Look for company-issued licenses versus personal email sign-ups, and flag any account you can't tie to a company contract.
-
Look for a data-retention or training opt-out setting in any AI tool you rely on. Many AI platforms default to using your inputs to train their models unless you explicitly opt out, and that setting is often buried in an admin panel nobody's opened. Check the tool's admin or privacy settings directly rather than relying on the vendor's marketing claims about data handling.
-
Write one plain-English rule for what should never be pasted into an AI tool. A single clear rule, covering client data, financial information, and anything under an NDA, stops more incidents than a lengthy policy document nobody reads. Keep it to one sentence, share it with the whole team, and enforce it the same way you'd enforce any other basic security rule.
Common Questions
Do we need a formal AI policy before doing anything else?
No, start with visibility first. You can't write a meaningful policy until you know which tools are actually in use, which is exactly what the first two checks above surface. A policy written without that visibility usually misses the tools people are already using.
What counts as confidential data in this context?
Anything you wouldn't want to see reposted publicly: client contracts, financial figures, health information, source code, HR records, or anything covered by an NDA. If a piece of information would need a data breach notification if it leaked, it shouldn't go into a public AI tool.
Is it realistic to ban AI tools entirely?
For most organizations, no. Employees will find a way to use these tools whether or not there's a policy, so a workable rule about what not to paste in tends to hold up better than an outright ban that just pushes usage further underground.
What's the difference between this checklist and a full AI governance review?
This checklist catches the immediate exposure: unmanaged tools, personal accounts, and unclear data handling. A full review goes further, covering vendor contracts, formal policy, employee training, and how AI use maps to your specific compliance requirements.
How often should I re-run this checklist?
Quarterly is a reasonable baseline, since AI tool adoption inside organizations tends to move faster than most other technology changes, and a tool that wasn't in use last quarter may already be running in three different departments today.