Who decides what AI your company is allowed to use, and on what data?
Usually nobody, which is the problem. Half of employed Americans already use AI at work while only 41% say their organization has integrated it, so the gap between those two numbers is running on personal accounts with no policy behind it. We write the policy, the tool list, and the approval gates with your leadership team, then leave you a governance cadence you will actually keep.

- At least a few times a year
- Weekly or more
- Daily
41% say their organization has integrated AI tools. Inside those organizations, 65% of employees say AI improved their productivity; about one in ten strongly agree it has transformed how work gets done.
Source: Gallup, Rising AI Adoption Spurs Workforce Changes (2026). 23,717 U.S. employees, 4 to 19 February 2026, margin of error ±0.9 points.
Data table
| Item | Value |
|---|---|
| At least a few times a year | 50% |
| Weekly or more | 28% |
| Daily | 13% |
- Map what already existsThe tools in use, sanctioned or not, and the policies that already mention them.
- Decide the boundariesleadershipRisk appetite, the data that is genuinely off limits, and who approves what. Only your leadership can make these calls.
- Write the tool list and the policyOne page for staff, an appendix for engineers, with named tools and a route for requesting more.
- Put the gates in placeApproval before anything AI-produced reaches a customer, a contract, or production.
- Set the cadenceA named owner, quarterly review, a version number, and a known location. The part that decides whether any of it survives.
AI Strategy & Governance
The gap that makes this urgent
Gallup surveyed 23,717 U.S. employees in February 2026. Half said they use AI at work at least a few times a year, 28% weekly or more, and 13% daily. In the same survey, 41% said their organization had integrated AI tools.
The difference between those numbers is your exposure. It is people pasting customer data into personal accounts because the approved path does not exist yet, and it is invisible until something goes wrong. Nobody in that gap is acting in bad faith. They are doing their jobs with the best tool available, and the organization has not told them which tool that is.
What governance actually means here
Not a document. Four things that have to exist and be maintained.
A tool list with names on it. “Approved AI tools” is not a policy. “ChatGPT Enterprise, Microsoft 365 Copilot, GitHub Copilot, and the internal knowledge assistant” is. Plus a route for requesting a fifth, and a person who decides.
Data rules people can remember. The categories that may never be entered, and one sentence anyone can apply under pressure: if you would not paste it into a public web form, do not paste it into a model that is not on the list.
Approval before it leaves. Anything AI produced that reaches a customer, a contract, production code, or a regulator has a named approver. By role, in writing, before the first deployment rather than after the first incident.
A cadence. Quarterly review in 2026, because the tools change faster than annual review can follow. One owner, a version number, a known location.
The strategy half
Governance without a plan is a brake with no engine. The same engagement produces the opportunity map, the refusal list, and the 90-day sequence.
The refusal list is the part clients keep. Every leadership team we have worked with arrived with more ideas than capacity, and the loudest idea was rarely the best one. Saying no to two things in writing, with reasons, is usually worth more than saying yes to a third.
Two offers inside this service area
Compliance and vendor-risk acceleration
For companies that sell to enterprises and drown in security questionnaires. We map your SOC 2 and other certification controls into the policies that actually govern your operations, so the two agree, then build the retrieval system that drafts questionnaire responses from that corpus with a human approving each one.
The policy work lives here. The system that drafts the answers is built under AI Automation, and the two are usually one engagement.
Document alignment
SOWs, MSAs, contracts, collateral, policies, and procedures that contradict each other are a liability in a dispute and a drag on every sales cycle. We use retrieval and review agents to find the contradictions across the whole corpus, fix the documents with your counsel, and leave a process that keeps them aligned as they change.
How we work with your leadership team
Four sessions, spread over the engagement rather than crammed into a workshop. The first maps what you already have. The second and third make the decisions that only your leadership can make: appetite for risk, what data is genuinely off limits, who approves what. The fourth is the readout, where we defend every line and you push back.
We write the artifacts between sessions. Nobody leaves a workshop holding a stack of sticky notes and a feeling.
What you get
- A prioritized opportunity map, each item with the hours it saves, the data it needs, and the risk it carries
- The refusal list: what not to do, with reasons a board will accept
- A 90-day plan with named owners, in the order the work has to happen
- An acceptable-use policy people will read: one page for staff, an appendix for engineers
- An approved tool list, with a route for requesting additions and a named decider
- Data-handling rules: what may never be entered, and the one-line test staff can remember
- A risk register mapped to NIST AI RMF functions, and a gap assessment against ISO/IEC 42001 if you need the certification
- A governance cadence: who reviews what, how often, and where the current version lives
- Budget model and build-versus-buy calls for the next four quarters
Questions we get
- We already have an AI policy. Do we need this?
- Read it against two tests. Does it name the specific tools that are approved, and does it name a person who approves AI output before it reaches a customer or production? Most policies we see fail both, because they were written by legal to manage risk rather than by operators to enable work.
- Do we need ISO 42001 certification?
- Only if a customer or regulator is asking for it. It is a management-system standard, which means audits and documented evidence, and it costs real money to maintain. If nobody is asking, the NIST AI Risk Management Framework gives you the same structure without the certification overhead.
- Does the EU AI Act apply to us, and will you handle it?
- It applies if you sell into the EU, partly and on a schedule: standalone high-risk systems from December 2027, high-risk AI embedded in regulated products from August 2028. We will tell you whether it reaches you and what it touches. We do not do conformity work itself, at any scope, and we refer it to specialist regulatory counsel. If you do not sell into the EU it is not your first problem and we will not bill you to pretend otherwise.
- How is this different from the assessment?
- The assessment tells you what to do. This service area is doing the governance half of it: writing the policy, standing up the tool list, and putting the approval gates in place. Most clients buy the assessment first and this second.
- Who owns the policy after you leave?
- A named person on your side, chosen during the engagement, not a committee. If nobody will take it, that is a finding and we will tell you before we write anything.
How it starts
Three-week assessment, then a four to six week policy and roadmap engagement. You keep everything produced, whether or not there is a next part.