AI governance
Most small businesses did not adopt AI on purpose. It arrived one tool at a time, in whoever's browser it was useful. This engagement takes stock of what is actually in use, writes rules people can keep, and sets up the records that show the rules are kept — so when a customer, an insurer or a regulator asks how you use AI, you have an answer.
The signs
Nothing on this list says damage has been done. It says nobody could say for certain, and that is the actual risk.
The work
Six strands, run against the tools your business actually uses rather than a template. Each one ends in something written down that a named person is responsible for.
Before any rule is written, we list what is actually in use: the tools the company pays for and the ones staff signed up for on their own. For each, what it touches — customer records, financials, employee data, code — and who uses it for what. Most of the surprises in this work surface here, and a policy written without this step regulates an imaginary company.
A short document stating where AI may be used, what data may go into it, and who reviews what. Written to be followed: a few pages in plain language with the reasoning included, because a rule nobody understands is a rule nobody keeps. The hard part is not the writing, it is the decisions — where the line sits between AI drafting and AI deciding, which data never leaves your systems — and we put those choices in front of you rather than making them for you. You approve the final text. It is your policy, not ours.
Each tool's terms, read closely: whether your data trains their models, how long it stays on their servers, where it is handled, and what happens to it when you cancel. Vendors revise these terms, and the paid tier often answers differently than the free one — which is frequently the whole argument for upgrading. The verdict on each tool comes back plainly: keep, upgrade, restrict or drop.
For each place AI feeds into real work, we set who checks the output before it counts, and what gets recorded. In our own builds, no customer-facing output ships without a named person approving it, and the same standard translates here: the review step is assigned to someone and logged. The log matters as much as the check. Being able to show, months later, what informed a decision and who signed off is what being answerable looks like in practice.
A pass over how the current setup handles data: which accounts are personal versus company-owned, who still has access after leaving, whether sensitive information is going into tools whose terms do not cover it, and how AI use fits obligations you already carry — health data rules, card rules, European privacy law, whatever applies to your industry. This is a review with written findings, not a certification audit. Where you need a formal attestation, we say so and help you prepare for one rather than pretending to issue it.
Two things keep the policy alive after we leave. First, an incident path: what staff do when AI output is wrong in front of a customer, when data went somewhere it should not have, or when a tool quietly changes its terms — who to tell, what to record, what to say. Second, a review rhythm: these tools change fast enough that a policy dated last year describes a different landscape, so the document names a schedule and an owner for keeping it current, whether that owner is you or us.
The shape
We talk to the people using the tools and assemble the inventory. Your side is honest answers and a list of subscriptions. What matters is what people actually do day to day, not what anyone assumed they do. Each phase is priced before it starts.
We bring you the findings and the decisions they force: what to allow, what to restrict, what to drop. You make the calls with the trade-offs laid out in front of you, and we draft what you decided.
The policy, the vendor findings, the oversight rules and the incident path are drafted, then walked through with you line by line. Anything with legal weight is flagged for your counsel — the drafting is ours, the final say is not.
The policy is introduced to the team in a working session, not as an email attachment: what changed, why, and what to do when something goes wrong. A rule people heard explained holds better than one they were sent.
What you keep
Everything produced belongs to you outright: documents in your own accounts, in editable form, with nothing that depends on us to stay useful.
Next step
If AI is already in the building and the rules are not, that is the normal starting point, not an emergency. A short call is enough to tell you what this would involve for a business your size.
Schedule a callAlso in the catalog