Blog

AI Governance: Turning Policy Into Practice for Workplace AI Compliance

Written by Tara Swaminatha | Jul 23, 2026 1:00:05 PM

Workplace AI uptake and integration has happened much faster than most organizations anticipated. Employees are actively using AI tools and developing AI efficiencies without knowing which laws may apply or how to appropriately manage data use.

Creating practical AI use policies is critical to mitigate risk. The proper organizational response to AI use is the creation of sound AI governance policies and practices, but that is not always easy. Successful AI governance creates policies that actually guide use, not just sit on a shelf. 

As the founder and principal attorney at ZeroDay Law, I discuss how AI governance policy has to drive practice in my latest podcast episode from Decoding Cyber Law. 

Here’s what to keep in mind.

Prefer to listen to the 10-minute podcast? Tune in here.

Understand The AI Laws That Apply to You

The first step in creating a strong AI governance policy for your organization is to understand the legal parameters in play. This research includes the laws that apply to your:

  • Industry
  • Organization
  • Usage
  • AI outputs, and
  • Geography

Your research findings will help establish the legal baseline for AI use policy development. 

Let’s now consider what elements to review when drafting those policies. 

Privacy acts and legal obligations vary depending on where you are located or even where you do business. Read our blog post, U.S. State Privacy Acts: Which Apply to Your Organization (2026), to learn more.

Build AI Use Policies Around Tools, Data and Use Cases

Effective AI governance policy creation comes down to defining three specific areas:

  • Which specific tools and types of tools will be used
  • What data can and cannot be used in these tools
  • Which use cases (purposes) are acceptable, including the purpose of any output

Creating an AI use policy should not require reinventing the wheel. Piggyback off existing policy reviews. For example, if you have a review process for approving software, add the AI tool review to the existing process with some new questions.

AI policy creation also includes identifying who in your organization is responsible for approving use cases and tools. Some organizations will have internal expertise with the bandwidth and knowledge to take on these additional AI-related responsibilities. However, AI use does represent a new set of risk management issues. 

Your organization may need to seek external expertise to help manage responsible AI use. We will address this element more in-depth at the end of this blog.

How to Vet and Allow-List AI Tools

The next step in proper AI use governance: deciding which tools to use and which to restrict. The obvious choice may not be the right choice for your organization. 

It is not safe to assume that big-name providers, such as OpenAI, Anthropic, Google or Microsoft, are automatically the safest choice. These AI service providers are ever-evolving and implement fast changes. Because of this development speed, their AI products are neither as reliable nor as secure as typical software and platforms, which can expose your organization to risk.

The specific features and parameters found in AI tools may also make them unsuitable for your use. For example, Gemini currently has some challenging quirks. The Google LLM allows you to set a retention period after which inputs and outputs are automatically deleted (which you should do!). If you want to delete one input during the retention period, however, the process is neither quick nor easy. The product forces you to request deletion from an administrator, and the administrator only has the ability to wipe everything in your account at that time, administrators cannot selectively delete particular input or output. If you set a very short retention period to avoid potentially unwanted input or output lingering, that can cancel out any benefit of using Gemini for longer-term projects, since no data would remain after the expiration period is over. 

Vetting AI tools and AI-enhanced tools is a process. Require use request forms that provide information on the tool, its purpose, and what data is required to be input and/or generated as output. Your IT and security staff cannot rely on marketing information about capabilities and protections provided by the AI tool company. You’ll need to allow the staff time to research and pilot the tool prior to approving it for use. 

This process should include:

  • An examination of what risks it could introduce to your organization based on actual tool pilots and not just marketing information.

  • A review of the vendor contract to see what protections are in place for users, your organization and any data you upload or create.

  • A review of the rights and limitations the vendors give themselves regarding your usage and data. Episode 3 of our podcast dives into this in detail.

If the tool passes the review according to your organization’s risk tolerance and exposure, it can then be safely added to your allow-list for use.

Defining Covered Data Types for Safe AI Use

Your AI governance policy should focus on proper uses of AI tools within your organization. While a strong AI governance policy should limit user access to certain storage areas or data stores, users should be educated on the specific limitations surrounding restricted data.

Data categories that, by default, should not be AI inputs can include:

  • HR/Personally Identifiable Information (PII), including names, social security numbers, home addresses, salary or leave histories, disciplinary information or other personally identifiable information for employees, clients or customers, or others.

  • Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA) or other health- and medical-related information.

  • Material Nonpublic Information (MNPI), a public company’s sensitive and/or significant financial data or confidential corporate information as yet undisclosed to the general public, and that could impact share price if disclosed.

  • Any other information subject to disclosure or breach laws, or applicable contractual commitments.

Many vendor licensing agreements prohibit the use of regulated data categories in their tools (e.g., Personal Information), but that is not always followed within organizations. 

Using free AI tools also poses another layer of complexity as users may include them in workflows without realizing there are limitations and legal implications to the data being used and exposed to the tool. For the most part, free or trial AI tools grant the AI vendor the most broad, unrestricted rights to your input and output, and they offer little to no legal protection for your use of the tool or its outputs.

A realistic and reasonable policy will explain these considerations and rules for your users and make it easier for them to use AI tools responsibly. 

Learn more about data inputs when using AI tools. Our blog post, What You Need to Know Before Uploading Internal Documents to AI Tools, explores this topic.

Use Stepwise Thinking for AI Use Cases

A good way to help users understand and apply an AI governance policy is to require stepwise thinking. This approach makes users walk through:

  • What they are actually doing
  • With what data
  • To generate what output
  • Which is seen by whom
  • And used for what purpose

This type of exercise can help users understand low-risk and high-risk usage. 

For example, an HR employee using PII to build an employee 401(k) participant list for offering a seminar on retirement saving is probably low- to medium-risk, provided the list is secured following an organization’s standard practices. Whereas dumping employee data without discretion into an AI tool to create staff profiles just to see what an AI tool can glean is a higher-risk activity. 

Right-Size AI Accountability for Your Organization

As touched on earlier, responsibility for setting AI usage policies will vary, depending on the size and depth of your organization.

  • For smaller organizations, it may be possible to fold AI seamlessly into legal/IT and existing cyber and privacy governance responsibilities.

  • In larger organizations, it may be necessary to create a tandem AI compliance structure.

  • In all cases, if your internal resources are limited, seek external assistance.

Fortune 500 and AI-forward companies should also have board-level AI expertise to honor fiduciary duty. This responsibility could fall to a board committee or a named director with enough AI expertise to advise your directors, or who could tap appropriate external consultants for needed expertise and advice. 

It’s also a good idea to have an internal review board/committee that can make the final, tough calls on data, tools and edge-case use cases that are high-risk, but high-reward.  

All decision-makers should receive training on AI hallucinations, scalability and the ethical, algorithmic, environmental and societal risks associated with AI use. Like AI technology, proper management must be dynamic as AI use and capabilities evolve.

Cybersecurity education for boards is a must. Read Best Practices for Cybersecurity Training Programs for Boards of Directors to learn more.

Use Privacy Assessments and Recognized AI Governance Frameworks 

Finally, integrate privacy assessments to drive sound AI governance policy across your organization. A privacy assessment is a systematic evaluation process that can be used to identify, measure and mitigate privacy risks before AI is deployed. Privacy assessments help ensure compliance and promote responsible and accountable AI use. 

Anchoring your program to a recognized AI governance framework, such as the Department of Homeland Security AI Roadmap, NIST AI Risk Management Framework, or OECD AI Principles, is a good place to start to calibrate your AI governance according to recognized best practices. There are other roadmaps available, and they can be very helpful in developing your AI governance approach. 

Governance Is an Ongoing Practice

Artificial Intelligence is continuously evolving and is likely to remain an unpredictable tool. Recognize that proper governance and policies must remain dynamic to be effective in your organization. 

A structured process for proposing, reviewing and allowing new AI use cases will help your AI governance policy live in practice, not just on paper or a screen. 

ZeroDay Law is available to help your organization establish a strong AI governance model that is also practical for your users. We can also help you assess what you have in place and what internal resources might be natural points for integrating AI governance practices. Reach out today to start the conversation. 

Listen to the Decoding Cyber Law podcast for our discussion on AI. 

Read more: