
THE UPPER HAND
I. Write a Policy for: A good policy is not a cage
— it is a set of boundaries designed to safeguard
you and your team. Your AI policy should be as
unique as your organization’s culture, reflecting
the specific trust you’ve brokered with your team
and partners.
Your policy is yours to own, but at a minimum,
we’d recommend outlining these basic steps:
1. Allowed contexts (brainstorming,
draft 1, etc.) and forbidden ones
(final decision-making, sensitive
client research, Personal Identifying
Information).
2. Data Hygiene requirements (all client
projects pull from an independent,
protected drive).
3. Disclosures you may record any
meeting, but you disclose you are
recording. You must highlight what
work was done with AI support, etc.
PHASE 2: POLICIES AND THE STEPS TO
GET THERE (POLICIES & PROTECTION)
26
Data minimization is nonnegotiable: Before you use a tool, ask: Do I
truly need this data to get the result? If you do, anonymize first.
Replace client names with placeholders. De-identify your datasets
before they ever touch a cloud-based model.
Sanitize before you paste: Never include PII (Personally Identifiable
Information) like names, addresses, or specific financial figures in a
prompt unless you are 100% certain that you are on a secure, closed
Enterprise account.
Check your permissions: Disable “Training” in your settings. Most
major platforms allow you to opt out of having your data used to train
their models, but the default is almost always “On.”
Draft a simple “yes/no” list: Give your team a one-page guide on
what can go into AI (general research, drafting emails) and what is
strictly forbidden (donor lists, medical info, legal strategy).
Update your disclosure language: Transparency isn't a hurdle; it's a
trust-builder. Being clear about how you use secure, closed AI to
better serve them shows you are competent, not just “tech-forward.”
Update your contracts: Review your master service agreements and
vendor contracts. Ensure your legal language reflects that you use
secure, vetted AI tools as part of your internal workflows, and clarify
that this does not constitute a third-party data breach.
TL; DR Essentials
II. Create a Company Etiquette Guide: Do you
use a transcription service on calls? While you
might write the use of them into a client contract,
it’s still good manners to acknowledge it at the
start of the calls. Replying with some research that
Claude helped you with? Acknowledge it up front!
You’ve already established some of your AI
boundaries in Phase 1. In this etiquette guide, you
now want to create language around when you say
no to AI use, so nobody is ever caught off guard.
III. Make Socializing the Policy and Etiquette
Guide a “Moment”: Don’t bury this in an employee
handbook. Hold a meeting to review the policy
guidelines, take questions, and be clear that the
policy will evolve. Email the policy to your team.
Share and pin it on Slack. Share it with everyone
you collaborate with: clients, contractors, and
vendors. Showing exactly how you use AI to better
serve them proves you are both tech-forward and
professionally rigorous.
Policies aren’t meant to sit on a shelf; they are the rules of the road for your digital survival.
THE PRACTICAL GUIDE TO AI PRIVACY