Blane Canada

Related question

We wrote an AI policy and nobody follows it. What are we missing?

Short answer

Training. Writing the policy is step one. If your team cannot answer what they can use a tool for, where client data goes, and who is responsible when it gets something wrong, you do not have guardrails. You have a document.

Policy and training go together, and the order matters less than the fact that neither works alone.

Consider a typical, well-intentioned AI memo. Do not input confidential client information into non-enterprise tools. Turn off model training so your inputs are not used to improve the AI. Thoughtful exploration is fine for general productivity work. Every word of that is correct.

And every word of it assumes three things that are usually not true for a meaningful share of staff. That the people who most need to hear it understand what those terms mean. That they know where to find that setting inside the tool. That they can reliably distinguish general productivity use from client-sensitive work in the moment, while under deadline pressure.

Those are three large assumptions. In most professional services firms, at least one of them is wrong for a significant part of the staff.

This is what happens when leadership discovers activity and drops in governance without an assessment. The guardrails go up before anyone knows what is being guarded, who is doing what, or where the real exposure is.

Policy needs teeth, and training is the bite.

Go deeper