“My company isn’t using AI yet.”  Yes they are.

No AI policy doesn’t mean no AI usage. It means your data is may already be exposed.

Illustration of company data and documents streaming out of an office building into an AI chatbot cloud, symbolizing unmanaged AI use and data exposure.

Sorry… that was abrupt. But clear is kind. 

They’re already using AI whether you asked them to or not.

Here’s the problem with that: if you didn’t provide a paid subscription, they may be using a free version. Free as in unsecured. As in your company’s data is being used to train the model. As in your data is leaking outside your company’s walls.

It means your data has been disclosed to a third party, which could trigger an SEC investigation if it’s non-public financial data or implicate an NDA if it’s protected confidential information.

It means attorney-client privilege has been waived if your team uses AI to work with privileged information. It means your data is now stored in the AI company’s backend, and all your cybersecurity efforts won’t prevent them from being hacked.

It means your company’s IP and trade secrets are available to anyone who asks ChatGPT the right question.

Your data is being used to generate summaries of how companies like yours operate, how employees like yours work, what businesses like yours earn and charge, how teams like yours strategize and compete.   

You need to get a handle on this.

If you’re in this boat, you didn’t jump into AI when it first started to explode. Maybe you thought it’s too new, you didn’t know where to start, it didn’t seem relevant. Those are all good reasons.

The thing is you’re exposed anyway. The majority of people who use a computer to do their job are using AI whether their employer told them to or not. And because you didn’t talk about using AI, they’re doing it in secret. They’re not sure they’re allowed to, but it’s hard to see how to get everything done without it so they’re doing it on the downlow.

Even if you want to hold back on using AI for real work, you do still need to worry about training and governance policies and a strategy, right away.

A governance policy will tell your staff which tools they’re allowed to use: the tools you’ve vetted and trust.

Training will teach them how to make sure your data stays inside your walls, how to use the tools effectively, how to avoid the hallucinations that can lead to costly mistakes.

A strategy will direct their energy to actually “do more with less” and share what they learned across the business so everyone benefits.

You need to take action to keep your company’s data secure. Doing nothing is exposing you to risk. I can help, through governance policies, tailored training, and a strategy built for how your team actually works.


I’ve spent more than 20 years in big tech solving real customer problems and driving change at an enterprise level. Now I do that for businesses of all sizes.

If you want to learn how to take a quantum leap with AI, you’re in the right place. Let’s find time to connect and talk about how your organization can become one of the few who do AI right.