Start with curiosity, not a ban
People often use AI before the company has agreed how it should be used. They may draft emails, study data or prepare customer work with tools they found themselves.
Some of this work will be useful. Some may put private data, quality or trust at risk. You need to see both.
Ask five calm questions
Speak to the people doing the work. Ask:
- What job are you trying to make easier?
- Which tool do you use?
- What information do you give it?
- How do you check the answer?
- What would stop you trusting it?
Do not start by asking who broke a rule. People will hide the most useful evidence.
Sort the work by risk
Put each example into one of three groups.
Safe to learn from: public information, rough ideas and work that a person checks before use.
Needs a stronger rule: customer data, important claims, money, hiring or work that may reach the public.
Stop for now: private information in an unapproved tool, hidden decisions or work no person can check.
The groups should be easy for a ten-year-old to explain. If the rule needs a long legal note before it makes sense, it will not guide a busy team.
Keep the useful parts
Choose one example that saves time or improves the work. Move it into an approved place. Add the source material, a clear owner and a short check.
Then show the team what changed. This proves that speaking up can lead to better tools, not only more control.
Review the rule with real evidence
Meet again after a month. Look at what people used, what went wrong and what they stopped doing. Change the rule when the evidence changes.
The first useful map of AI in a company often already lives in the habits of its people.