Why it matters now
Staff already use AI tools. Without an approved option and a clear rule, client details, health information and contract terms end up pasted into consumer products whose terms you have never read. A policy costs far less than finding that out after a leak.
The five rules
- Keep an inventory. List every AI tool in use, who uses it and for what, including the ones people brought in themselves.
- Set data limits. Decide what may never go into an AI tool: client identifiers, health information, payment data, credentials and anything covered by a confidentiality agreement.
- Approve tools on their terms. For each approved tool, check whether it trains on your inputs, how long it retains them, how you delete them and whether it will sign the agreement your industry requires.
- Require human review. Anything customer-facing or consequential is checked by a named person before it goes out.
- Log and respond. Keep a record of what the AI did, and write down in advance who acts, and how, if it gets something wrong or leaks data.
A framework to borrow from
The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023) organizes AI risk into four functions: govern, map, measure and manage. You do not need all of it. Govern is your policy and ownership, map is your inventory and the context each tool is used in, measure is testing the output, and manage is your response plan.
If you are regulated
Health practices, law firms and financial businesses carry extra duties on top of this: HIPAA, professional conduct rules and state privacy laws. This guide is general information, not legal advice. For law firms, see our summary of what ABA Formal Opinion 512 means for AI intake.
When to bring in help
If AI is already facing customers, or you want a test set, redaction and an audit trail rather than a policy alone, that is the AI evaluation and guardrails build.