The complete AI governance framework your team can deploy in 30 days.
Not just a policy — a framework. The full policy is free to read below. The kit adds the employee and vendor letters that make it enforceable, plus a step-by-step rollout plan.
What this is
This is a complete, adopt-ready AI governance framework for a mid-sized business that wants the productivity of AI without the exposure. It has six parts: the policy (readable in full below), an employee acknowledgment letter, a third-party vendor letter, a 30-day rollout checklist, a staff training quiz, and a Fortify AI leadership one-pager — and it is built to be enforceable, not aspirational.
AI Usage Policy — read it in full
1. Purpose & scope
This policy governs the use of AI tools by everyone who acts on behalf of the company — employees, contractors, temporary staff, and volunteers. It applies to any AI tool used for company work, whether company-provided or public, and whether used on a company or personal device. Its purpose: let our people use AI to do better work, faster, while making sure no confidential, regulated, or client information leaves our control through a tool nobody approved and nobody is watching.
2. Roles & responsibilities
A named policy owner (not a committee) owns this document and the approved-tools list, approves new tools, and oversees incidents. Leadership sponsors and models compliant use. Managers ensure their teams have read and signed the acknowledgment. Employees use only approved tools and report incidents. IT / Fortify AI configures and maintains the enforcement layer.
3. Acceptable use
Employees are encouraged to use approved AI tools to draft, summarize, research, translate, analyze, and automate repetitive work — provided the information is properly classified for that tool and the output is reviewed by a qualified person before use. The guiding principle: AI assists; people remain accountable.
4. Prohibited use
Never enter confidential, regulated, or client data into a public or personal AI account. Never use tools that are not on the approved list, present unreviewed output as verified, let AI make a final decision about a person without human judgment, or attempt to bypass the company’s AI monitoring or blocking controls.
5. Approved AI tools
Only tools approved in the policy may be used for company work. Our standard is deliberately strict: Fortify AI is the only tool approved out of the box, because it is secure by default. Every other tool — including Microsoft 365 Copilot — must pass an AI readiness assessment and be configured and approved in writing first. Copilot in particular surfaces whatever a user can already open, so a misconfigured OneDrive/SharePoint/Teams estate can make HR, accounting, and other files instantly discoverable; that oversharing must be remediated before rollout. Any tool not on the approved list is prohibited, and personal or consumer AI accounts may never be used for company work.
6. Data classification standard
The most important section. Public information may be used with any approved tool. Internal information: approved business-tier tools only. Confidential information: only tools contractually cleared for it. Regulated information (PHI, PII, card data, government data) is never entered into public or personal AI — only a cleared, compliant environment. Map these tiers to the regimes you answer to (HIPAA, GDPR, CCPA, PCI, CMMC).
7. Human review & accountability
A qualified person must review AI output before it is sent to a client, filed, billed, published, or used in any decision about a person. Whoever signs, sends, or acts on the output owns the result. Accountability stays with people, not the model.
8. Third-party & vendor requirements
Every vendor that touches company data must confirm, in writing, that they will not put your data into ungoverned AI, will not let providers train on your data, isolate your data, disclose any AI processing, meet your residency requirements, and notify you of incidents. New AI vendors are approved before they handle company data.
9. Data residency, retention & privacy
AI tools that handle company data must operate under reviewed contractual terms, must not retain inputs beyond what is necessary, and must meet residency requirements. Regulated data requires the appropriate agreement (e.g., a HIPAA Business Associate Agreement) before processing.
10. Monitoring & enforcement
Most organizations cannot produce a list, today, of every AI tool their team used this week — which means the usage they worry about is the usage they cannot see. Enforcement makes the policy real: visibility into what is in use, and the ability to block what should not be. See Shadow AI Discovery below.
11. Incident handling
If sensitive data is exposed to an unapproved tool, report it promptly through the defined channel. The goal is fast containment, not blame; early reporting limits exposure. The policy owner logs the incident and ties into the company’s existing breach-response process where regulated data is involved.
12. Training & enablement
Skill with AI is the difference between a toy and a tool. Every employee should receive practical coaching on using approved tools well and safely, and new hires complete it as part of onboarding.
13. Ownership & review
The named owner maintains this policy and the approved-tools list. It is reviewed at least every six months, and immediately after any material change in tools, regulation, or an incident. Each version is dated and numbered.
Never paste client, patient, financial, or personally identifiable information into a public or personal AI account. If in doubt, treat it as confidential — use only a tool cleared for that data, or ask the policy owner first.
Shadow AI Discovery
A policy you cannot see being followed is a hope, not a control. Every Fortify AI managed plan includes the enforcement layer that makes this framework real:
- Visibility — see exactly which AI tools and LLMs your team is using, across company and personal accounts.
- Control — block specific or unapproved LLMs from being accessed at all, so sensitive data can’t leave through a tool you never approved.
- Enablement — keep the tools that help, shut off the ones that put you at risk, and give every employee a compliant path that’s also the convenient one.
Get the full deployable kit
Six documents — the policy, the employee and vendor letters, the 30-day rollout checklist, the staff training quiz, and the leadership overview — bundled in a single download. Free, in exchange for a work email.
✓ Your kit is ready — grab all six documents in one download. We’ve also noted your interest so we can help if you’d like.
Download the complete kit All six documents in one .zip — the policy, both letters, the rollout checklist, the staff quiz, and the leadership overview. Download .zip ↓Prefer to grab files one at a time?
Want us to configure the enforcement layer and stand this up for you, not just hand you the documents?
Book a 30-minute consultationReady to evaluate Fortify AI?
Book a 30 minute consultation with our team. We will scope your environment, identify the two or three highest-leverage AI deployments for your firm, and outline what a Fortify AI rollout looks like.