Your Team is Already Using AI: Do You Have the Right Guardrails?
Updated: Sep 8

Artificial intelligence is no longer something only large companies are exploring.
Employees are using AI tools to draft emails, summarize documents, analyze information, create marketing content, take meeting notes, and complete everyday administrative work. In many organizations, that use began before leadership ever discussed an AI strategy or an AI policy.
The issue is not whether your organization should use AI.
The issue is whether you understand how it is already being used, what information is being shared, and where human judgment still matters.
AI Can Create Value — and New Risk
Used thoughtfully, AI can help smaller organizations work more efficiently. It can reduce time spent on repetitive tasks, help employees organize ideas, and expand the capacity of teams already operating with limited resources.
But convenience can make it easy to overlook risk.
An employee may paste confidential financial information into a public AI tool. A manager may rely on an AI-generated summary without checking the original document. Marketing content may include inaccurate claims.
None of these situations necessarily begins with poor intent. Most begin with an employee trying to work faster. Smarter.
That is why AI risk is fundamentally a governance issue, not just a technology issue.
Five Questions Every Organization Should Ask
You do not need a lengthy AI framework to begin managing the risk. You can start by asking five practical questions.
1. How is AI currently being used?
Leadership can't manage what it can't see. Ask employees which tools they use, what tasks they use them for, and whether those tools were formally approved.
The goal is not to punish experimentation. It is to understand your actual exposure before setting expectations that make the most sense.
2. What information should never be entered into an AI tool?
Employees need clear guidance about confidential, personal, financial, health-related, proprietary, and client information. A simple rule such as “do not enter sensitive information into an unapproved AI system” can prevent significant problems — but only if employees understand what your organization considers sensitive.
3. Which AI-generated work requires human review?
AI is known to hallucinate and can produce answers that sound confident and polished while still being incomplete, inaccurate, or entirely wrong. Any output used for financial decisions, legal or regulatory matters, employment decisions, client communications, grant reporting, public claims, or other high-impact activities should be reviewed by a qualified person.
AI may support judgment, but it should not replace accountability.
4. Who approves new AI tools?
Free trials and built-in software features make it easy for new tools to enter an organization without normal vendor review. Before adopting an AI product, someone should evaluate its data practices, security, contract terms, access permissions, reliability, and intended use.
The review does not need to be complicated, but it does need to be formalized.
5. Who is accountable when something goes wrong?
If an AI-generated report contains an error, a confidential document is uploaded, or automated content causes reputational harm, who is responsible for responding?
Clear ownership helps organizations identify problems sooner, escalate them appropriately, and learn from them instead of treating each issue as an isolated mistake.

Practical Guardrails You Can Put in Place Now
Effective AI governance should fit the size and complexity of your organization. For many small businesses and nonprofits, a reasonable starting point includes:
An inventory of AI tools currently in use
A short list of approved and prohibited uses
Clear rules for confidential and personal information
Required human review for high-impact outputs
Basic vendor and security review before new tools are adopted
Training that uses examples employees will actually encounter
A process for reporting errors, privacy concerns, or unintended results
Periodic review as tools, use cases, and risks change
The National Institute of Standards and Technology organizes AI risk management around four connected activities: govern, map, measure, and manage. The language may sound formal, but the underlying idea is practical: establish responsibility, understand how AI affects your organization, evaluate the risk, and respond appropriately.
You do not need to implement an enterprise-scale program overnight. You do need enough structure to make responsible decisions.
The Bottom Line
Banning AI altogether is unlikely to eliminate its use, and ignoring it will not eliminate the risk.
The better approach is to create reasonable guardrails that allow employees to benefit from AI while protecting the organization, its clients, its employees, and the information entrusted to it.
Do You Know Where AI Fits Into Your Risk Profile?
AI rarely exists as a stand-alone risk. It intersects with cybersecurity, privacy, vendor management, compliance, operations, governance, and reputation.
The Emery Mackenzie Business Risk Health Check™ helps small businesses, nonprofits, municipalities, and growing organizations identify emerging vulnerabilities, evaluate existing controls, and prioritize practical next steps.
Schedule a discovery conversation to better understand your organization's risks and move forward with confidence.
.png)
