Free Resource · guide

Before Your Team Uses AI: The Acceptable Use Policy Conversation

At a recent AI workshop, an attendee asked a question that stopped the room. He had heard that information shared with AI applications could become discoverable in a lawsuit. Was that true? I gave him the only honest answer an IT company can give, talk to your lawyer. But there is a second half to that answer, the part that is squarely our job, and it starts with an acceptable use policy. Here is that conversation, minus the names.

Most businesses adopt AI in the worst possible order. Employees start using it quietly, sensitive data drifts into chatbots, and only later does someone ask what the rules should have been. The workshop question about lawsuits is the moment that ordering problem becomes visible. So let me walk through the conversation the way it actually went.

Could AI conversations show up in a lawsuit?

Honestly, I do not know, and neither does your IT provider, because that is a legal question and we are an IT company. The attendee had heard about cases where information shared with AI applications became discoverable, treated as if it were no longer confidential. I am not in a position to confirm or deny that, and neither is anyone else without a law license. What I told him, and what I will tell you, is to talk to your attorney about it before you assume anything either way.

What I can tell you is what the company controls on its side of that question. And that starts with a document.

What is an AI acceptable use policy?

It is the company’s written decision about what information is allowed to be shared with AI, which tools are approved, and what those tools may do with your data. We keep a template for exactly this, and the template is the easy part. The hard part is the decisions behind it, because the risks are real: AI with access to your files could delete things, and data pasted into the wrong tool could end up exposed. We covered the delete-my-files category of risk in our guide to desktop AI risks and guardrails. The exposure category is what the policy exists for.

The policy works because it is specific. Not “be careful with AI,” but this data class can go to these tools, and this data class cannot.

Are all AI tools equally risky?

No, and your policy should say so explicitly. The major cloud AI vendors state that on paid accounts they do not train their models on your data. That is meaningfully less risk than a free consumer account, though the risk is still out there, and I would not tell a client otherwise.

Then there are the much cheaper models, including the Chinese ones. Your policy might allow those for narrow, harmless jobs, generating images was my example in the workshop, while drawing a hard line well before anything sensitive. And for the truly sensitive material, payroll data, confidential company financials, the right answer may be an offline model contained entirely at your office, one that cannot share data outside your walls. We run one internally for exactly that reason. Or the answer may be simpler still: some data should not work with AI at all.

At the other end of the spectrum, my favorite example of a zero-drama AI workload is my own website. It is public. Anyone can visit it, read it, copy it. Letting AI work on that costs nothing in confidentiality, which makes it a perfect job for AI. A good policy captures that whole range, from “any tool, go nuts” to “never.”

Can we just block AI at the network level?

We could, and it barely works, so do not build your protection on it. Copilot is already installed in your Microsoft 365 environment, so AI is in the building whether you invited it or not. There are countless AI websites, and blocking them is a losing chase. And the low-tech bypass beats every filter ever made: an employee who cannot paste a document can pick up their phone and photograph the screen.

This is why the signed policy matters more than the firewall rule. If an employee does something undesirable with an AI tool anyway, a policy that employee signed off on is something you can actually submit to help protect the company from exposure. It helps you remain legally defensible in court even when a person misuses a tool. Again, and I will keep saying it, have your attorney shape that document. Our job is the security controls behind it, theirs is the legal armor.

What about regulated industries and government work?

Look at the enterprise platforms built for exactly that, Amazon Bedrock and Azure AI Foundry. The big vendors know that compliance scenarios exist, so they offer locked-down, contained AI systems designed specifically to keep your data secure inside their environment. If you are working with government contracts or DoD requirements, those are the platforms to research rather than the consumer front doors, and that research should happen alongside your compliance obligations, not after.

So what should you actually do this month?

Three things, in order. First, book time with your attorney and ask the discoverability question directly, because everything else hangs on their answer. Second, sort your data into rough classes, public, internal, sensitive, and decide which AI tools, if any, each class may touch. Third, put that in a written acceptable use policy and have every employee sign it before the next quiet chatbot session, not after.

If step two is where you stall, that is the part that is genuinely our lane. Matching data classes to tools, standing up an offline model, configuring the guardrails, that is IT consulting work, and we do it for businesses across Houston. The legal advice is your lawyer’s. The plumbing is ours. Between the two, you get to say yes to AI without wondering what your team already pasted where.

Need help sorting your data before your team sorts it for you?

We help businesses figure out which AI tools fit which data, put an acceptable use policy template in front of their attorney, and set up the technical guardrails behind it. If your employees are already pasting things into chatbots, that conversation is overdue.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

Can our AI conversations really be used against us in a lawsuit?

We are an IT company, not a law firm, so we will not pretend to answer that. The attendee who raised it had heard of cases where shared information was treated as no longer confidential. Whether that applies to your situation is exactly the question to put in front of your attorney before your team gets deep into AI.

What should an AI acceptable use policy actually say?

At its core, it defines what kinds of company information may be shared with which AI tools, and what those tools are allowed to do with it. Public data might be open to any tool, everyday work data limited to paid business accounts, and sensitive data like payroll or confidential financials restricted to an offline model or kept away from AI entirely. Have your attorney review the final document.

Do the paid AI plans really keep our data out of training?

The major vendors state that they do not train their models on your data when you are on a paid account. That reduces the risk, but it does not remove it, and we would never tell you it does. It is one reason a policy should distinguish paid business tools from free consumer ones.

Can you just block AI on our network instead?

We could block certain AI services, but it barely works in practice. Copilot is already installed in your Microsoft environment, new AI sites appear constantly, and an employee who cannot paste something can photograph the screen with their phone. That is why the policy, signed by each employee, does the heavy lifting that a firewall cannot.

What if we handle government or heavily regulated work?

Look at the locked-down enterprise AI platforms from the big cloud vendors, Amazon Bedrock and Azure AI Foundry. They are contained systems designed specifically to keep your data secure inside their environment for compliance scenarios. If you work with government contracts or DoD, those are the systems to research, alongside your compliance officer and attorney.

Where does an IT company fit into what sounds like a legal problem?

The lawyer decides what the policy must say. We handle everything around it, sorting your data by sensitivity, matching tools to data classes, standing up offline models where they make sense, and building the technical guardrails that back the paper policy with real controls.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.