AI policies have a difficult job: setting meaningful rules for a dynamic technology likely to change while the policy is still in effect.
Creating a useful AI policy starts with understanding how AI technology is already being used across the organization, then deciding how existing governance practices should apply. AI policy decisions become much easier when a few important questions are answered prior to drafting.
In this final blog post in our Decoding Cyber Law series, we take a look at what organizations should consider when creating an AI policy and how to keep it useful as technology and legal requirements evolve.
Prefer to listen to the full podcast? You can find it here.
Before writing AI policy language, take a look at the existing technology environment in your organization. Are any employees using AI applications the organization did not provide or approve?
If so, you may already be dealing with a form of shadow IT. Employees could be using free or personal versions of AI tools without realizing their tool licenses expose your organization to risk.
Finding out what AI tools employees are using gives the organization a chance to determine the right path forward. In some cases, purchasing business licenses may be the only additional protection needed for continued AI technology workplace use.
But, the AI license is only part of the assessment. AI tools can change while employees are using them. Some store user inputs and some do not, while protections may differ depending on the license involved. Additionally, some products described as AI may not actually operate as users expect an AI system to operate.
All of this is useful context before policy drafting begins. From there, the organization can turn to a more immediate question: what information should employees be allowed to input into AI systems?
Deciding which AI tools employees can use is only part of the equation. Organizations also need to define what types of information employees can enter into those tools based on the potential for internal or external exposure. The risk of inaccurate AI-generated work product should also factor into those decisions.
It is helpful to begin by identifying what kind of provider an organization is dealing with. As I discussed in Episode 3 of the Decoding Cyber Law series, AI vendors generally fall into three categories:
Large AI foundation model providers, such as OpenAI, Anthropic, Google and Microsoft, which offer a broad range of AI services.
Specialized AI vendors who provide AI for a specific function or application.
Custom AI development partners who build custom tools for an organization’s internal use.
Each AI system itself also deserves scrutiny. Specifically note any AI products that have not been sufficiently tested or have not been in use long enough for the organization to become comfortable with their features and protections.
The AI provider type is only the first part of the assessment process. Organizations also need to consider how employees are actually using these tools. I have occasionally used AI tools for drafting and research; these are two common ways employees may be using AI in your organization.
As you read this post, keep both dimensions in mind: the type of AI provider involved and how the AI will actually be used. An AI policy needs to account for both when establishing appropriate requirements for data, risk management and employee use.
AI use does not necessarily need a separate governance approach from what is already in place. Existing organizational policies can often accommodate AI-specific requirements, while the organization's established risk management framework can guide decisions about acceptable use.
The expanded policy can then address the three areas where AI creates specific concerns:
Managing inputs and protecting privacy should be addressed directly in the AI use policy.
Organizations can require employees to use approved AI tools and make sure any AI-integrated systems are configured properly. The policy can also establish which settings are approved and how users must operate under the appropriate license agreement.
Data use and privacy requirements give employees clearer parameters for using AI. These requirements also provide a starting point for deciding how much risk the organization is willing to accept when a new AI use is proposed.
Additionally, AI use should go through the organization’s usual risk management process. The review should identify risks and consider how serious any potential harm may be.
From there, determine whether the proposed use could violate a law, regulation or contract, and if not, whether AI use risk can be managed. The organization also needs a process for deciding which AI-related risks are acceptable, and who has the authority to make those decisions.
Where compensating controls are available, the organization can determine whether they adequately mitigate the potential harm.
Risk management also must account for what happens when an incident occurs, which means AI needs a place in the organization’s existing response process.
Lastly, AI management needs an explicit place in incident response planning.
Relevant checklists should account for AI systems so they are considered alongside other systems and data during an incident. Otherwise, an AI tool could be overlooked when the response team determines what needs to be examined.
AI tool use planning establishes the process, but employees still make many of the day-to-day decisions determining how AI is used. Their judgment can directly affect what information a tool receives and how its output is handled.
Employee judgment plays an important role in AI use because users control data inputs. Designated employees may also need to review AI outputs for potential copyright concerns, hallucinations or bias.
Therefore, training needs to reinforce the decisions employees are expected to make while using AI tools.
Providing digestible segments of AI training over time helps remind employees to be vigilant as they use AI tools. As employees become comfortable with AI, it can become easier to stop thinking carefully about the implications of a particular use case or the information being provided to the system. Regular reminders through ongoing training can help keep those issues visible.
The need for continued use training connects directly to another reality of AI use. The technology employees are using today will continue to change.
An effective AI policy must be adaptable as AI tools change frequently, including the engines that power them. Laws also continue to develop, and an organization’s own compliance policies should evolve based on its operating environment and the risks associated with it.
An AI policy cannot simply reflect the tools and legal landscape that existed on the day it was written. An organization needs to revisit the policy as those conditions change and make updates when its own compliance requirements call for them.
A workable policy gives teams a place to start while leaving enough flexibility to respond as the technology continues to evolve.
Building or updating an AI policy?
ZeroDay Law helps organizations address the legal and operational considerations involved in AI governance and policy development. Contact us to learn more about how ZeroDay Law can help your organization create a sound AI policy.
Listen to the Decoding Cyber Law podcast for the full discussion.
Read more: