Blog

Cyber Security Guidance
In Plain English.

Practical advice on Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, cyber basics and common issues affecting smaller businesses. The aim is to make cyber topics easier to understand and more useful in practice.

Practical AI Governance for Organisations

Practical AI Governance for Organisations

AI governance does not need to start with a large framework. It needs to start with honest questions.

·        What AI tools do staff use today?

·        What data do they put into those tools?

·        Which outputs reach clients, customers or the public?

·        Who checks the output before use?

·        What happens if someone uploads the wrong information?

Many organisations cannot answer those questions yet. That creates risk.

Step 1: discover current AI use

Start with discovery. Ask teams what they actually use. Include paid services, free tools, browser extensions, Microsoft 365 features, search tools, meeting assistants, code assistants and image generators.

The purpose is not to catch people out. The purpose is to understand the real workflow before writing rules that do not match reality.

Step 2: classify use cases

Not all AI use carries the same risk. A grammar check on public marketing copy differs from uploading an incident report. A meeting summary differs from drafting legal advice. A code suggestion differs from generating a client proposal.

A simple model can help:

·        Low risk: public information, grammar support, idea generation and non-sensitive drafting.

·        Medium risk: internal documents, meeting summaries, process notes and internal policy drafting.

·        High risk: client data, personal data, contracts, HR records, source code, security findings and board papers.

·        Prohibited: unmanaged tools for confidential information, harmful image generation and prompts that deliberately imitate protected work without permission.

Step 3: approve tools

List the AI tools staff can use. Prefer business-grade services with clear contractual terms, admin controls, identity management and data protection information. Decide whether staff can use consumer tools at work and under what conditions.

Approved tools should have an owner, a supplier review, a data-use position and a support route.

Step 4: define data rules

Define what data can and cannot enter AI tools. Link this to information classification.

Public information may carry lower risk. Internal information may need approved tools only. Confidential information, client data, personal data, source code, security findings, contracts, HR records and board papers need clear restrictions.

Step 5: require human review

AI output should not bypass human judgement. Review matters for accuracy, copyright, confidentiality, tone, bias, factual claims and brand risk.

Public and client-facing outputs need stronger checks than internal brainstorming. The reviewer should understand the subject matter and have authority to approve, revise or reject the output.

Step 6: treat AI suppliers as suppliers

AI tools are suppliers. Treat them that way.

Review where data goes, whether inputs and outputs train models, how long the provider retains data, who can access it, where it gets processed, what sub-processors exist and what contractual protections apply.

Step 7: prepare for mistakes

Staff need a safe route to report mistakes. If someone uploads a confidential document to the wrong tool, the organisation needs to know quickly. Fear-based cultures hide incidents. Clear reporting reduces harm.

Connect AI to existing security controls

AI governance should not sit in a separate box. It should connect to controls the organisation already understands:

·        Acceptable-use policy.

·        Web filtering.

·        Data loss prevention.

·        Endpoint management.

·        M365 and Google Workspace controls.

·        Supplier due diligence.

·        Data protection impact assessments.

·        Information classification.

·        Incident response.

·        Security awareness training.

This helps staff see AI as part of normal information governance, not a special mystery category.

A practical starting point

Start small.

·        Create a one-page AI acceptable-use policy.

·        Name approved tools.

·        Ban confidential and client data from unmanaged AI.

·        Give examples of safe and unsafe prompts.

·        Set review requirements for public content.

·        Train staff.

·        Create an incident route.

·        Review the policy every quarter as tools and laws change.

That will not solve every AI risk, but it will move the organisation from guesswork to control.

AI can improve productivity and quality. But organisations should not confuse access with governance.

The safest route is neither panic nor blind trust. It is controlled adoption.