Clear rules for the responsible use of AI.

We work with senior management, HR, Legal and IT to embed the responsible use of AI across the organisation.

AI Governance

Key outcomes

An AI Policy that enables responsible use, a dedicated assessment for each AI feature in use, and ongoing maintenance of both.

AI is already in use across the organisation, including where it has not been authorised

Employees already use it

Employees use AI to draft, summarise and translate, often through personal accounts, because no guidance exists on approved tools or permitted data.

It arrives through software updates

AI features are added to licensed software, often enabled by default, and access documents, email and meetings without any prior assessment.

It exposes personal data

A CV, an email or a colleague’s name entered into an AI tool constitutes personal data, for which the organisation remains accountable under the GDPR, even when a personal account is used.

Regulation already requires organisations to ensure training, transparency and human oversight

Already in force

  • Train staff who use AI (AI Act, art. 4)
  • Avoid prohibited systems, including emotion recognition in the workplace (AI Act, art. 5)
  • Label realistic content generated or manipulated with AI (AI Act, art. 50)
  • Inform workers of the use of AI where required (Law 132/2025, art. 11)
  • Ensure intellectual work remains predominant in professional services and inform clients (Law 132/2025, art. 13)
  • Protect personal data and comply with limits on remote monitoring (GDPR, Workers’ Statute)

From December 2027

  • Ensure human oversight of systems used to recruit, evaluate, allocate tasks to or monitor workers, and inform workers and their representatives in advance (AI Act, Annex III and art. 26)

Documented rules, communicated and applied, are how an organisation demonstrates compliance with these obligations.

Compliance-only approach

A policy designed solely for compliance tends to be formal, defensive and static

Formal

It addresses obligations one by one and produces a compliant document, but leaves ways of working unchanged.

Defensive

It focuses on prohibitions, so employees either avoid AI or use it covertly through personal accounts.

Static

It reflects current tools and becomes outdated with the first update, as vendors change features and settings every month.

We work with senior management, HR, Legal and IT to embed the responsible use of AI

From the Policy organisation-wide rules

  • We set out the AI uses the organisation encourages and the conditions for using them safely, so employees can adopt AI with confidence.
  • We define the activities that require authorisation and the limited set of prohibited uses, so everyone understands the boundaries.
  • We appoint a single point of contact for requests and questions, so anyone wishing to trial a new tool knows whom to approach.
  • We draft the rules with HR, Legal and the DPO, who approve them, turning their guidance into day-to-day practice.

To feature assessments one per AI feature

  • For each feature we specify permitted activities and data, as well as exclusions, so guidance is in place before it is needed.
  • We assess each feature against vendor documentation and determine where the data is processed and stored.
  • We monitor vendors over time and update the assessments as products change.

Our five-phase approach, from discovery to rollout

  1. 01

    Discovery

    AI features already active, the data they access and client contractual constraints

    Client involvementThe point of contact and IT, with the software inventory

  2. 02

    Assessment

    An assessment for each AI feature, with the configuration changes to request from IT

    Client involvementIT responds to the technical checks

  3. 03

    Testing

    Real cases tested against the assessments, with corrections before rollout

    Client involvementOne session to validate the cases

  4. 04

    Policy

    The AI Policy, built on the findings of the previous phases, covering permitted uses, activities requiring authorisation and prohibited uses

    Client involvementHR, Legal and the DPO review the draft

  5. 05

    Rollout

    Policy and assessments approved and communicated to users

    Client involvementSenior management approves Policy and assessments

Every AI feature is assessed against the same framework

The Policy sets three common criteria, and each assessment positions the feature against each of them.

Where it runs

  1. On the device or on company systems
  2. In a governed corporate environment
  3. In a contracted external service
  4. In a personal service, excluded from work use

What it is used for

  1. Office work and personal productivity
  2. Searching and analysing information
  3. Communication and content
  4. Design and technical work
  5. Business processes and people management
  6. Automations and systems that take actions

What data it processes

  1. Public information and own content
  2. Non-confidential internal documents
  3. Client and project data
  4. Personal data of colleagues and collaborators
  5. Health, union and judicial data
  6. Credentials and technical secrets
  7. Code destined for live systems
  8. Data bound by client contracts

Our approach in detail

We identify the AI already in use across the organisation

Phase 01 · Discovery

We identify the AI already in use across the organisation

  • We start from licensed software and employee practices to establish which AI features are already active and how they are used.
  • We inventory the AI features in the software in use and identify which are already enabled.
  • Through an anonymous online survey we capture how employees use AI, including through personal accounts, with the aim of understanding current practice.
  • We identify client contracts that restrict the use of AI, as they take precedence over any internal rule.
  • We deliver this baseline as the first output, giving management immediate visibility of the organisation’s exposure.
We assess each feature against vendor documentation

Phase 02 · Assessment

We assess each feature against vendor documentation

  • A single application may include features that run locally and others that send data to the vendor or to third-party models, so each is assessed separately.
  • We review the vendor’s contract, privacy terms and documentation, and determine where data is sent and who receives it.
  • We position the feature within the framework and, where uncertain, apply the most prudent level.
  • We translate the required settings into specific requests to IT, such as disabling web search or memory.
  • We formally exclude features pending assessment, even where already enabled.
We test the assessments before rollout

Phase 03 · Testing

We test the assessments before rollout

  • Before publication, we apply the assessments to realistic requests from different roles, such as an email summary for HR or an AI-generated script for a technician.
  • We verify that each assessment provides a clear and correct answer, and flag any use it permits without justification.
  • We verify that every prohibition is enforced by a technical setting, and ask IT to apply it where missing.
  • We refine the assessments before rollout, so employees receive rules that have already been tested.
We draft the Policy and roll it out across the organisation

Phases 04 and 05 · Policy and rollout

We draft the Policy and roll it out across the organisation

  • Assessment and testing determine which uses to encourage, which to authorise case by case and which to prohibit, and the Policy sets these out in clear, accessible language.
  • The Policy leads with the uses the organisation encourages, followed by activities requiring authorisation and the limited set of prohibited uses, so it supports employees in their day-to-day work.
  • We define how outputs are reviewed before leaving the organisation and how errors are reported, so issues surface early.
  • We submit the draft to HR, Legal and the DPO for review, and present Policy and assessments to senior management for approval.
  • We publish Policy and assessments in a single location and communicate them to users; rollout marks the start of the ongoing service.

Illustrative case

Three services share the Copilot name, each with different rules

Copilot with a personal accountCopilot ChatMicrosoft 365 Copilot
What it isThe consumer service, freeThe assistant included in the business Microsoft 365 planThe paid add-on, with one licence per person
How to recognise itYou sign in with a personal Microsoft accountYou sign in with the company account and the interface says company data is protectedIt appears inside Word, Excel, PowerPoint, Outlook and Teams for those with a licence
What it readsWhat you write, outside the company contractOnly what you write or uploadOn its own, the documents, email, chats and meetings you have access to
RuleExcluded from workUsable, with web search off when the conversation contains client or personal dataUsable with limits on questions, because it reaches data without you giving it

The three services share the same name and icon, so each assessment begins by explaining how to identify the correct one.

Every deliverable in a single governance wiki

Policy, assessments and regulatory sources are handed over to the client in a wiki that employees consult and the point of contact keeps up to date. Each tool is broken down into its individual AI features, and each feature carries its own assessment.

2 Annex 1 · Tools / Assessments / Microsoft 365 Copilotacme_ai_policy
0 Work1 PolicyTextsVersionsRegulatory sources2 Annex 1 · ToolsAssessmentsAdobe Acrobat · AI AssistantAdobe Photoshop · Neural FiltersAnthropic Claude TeamAutodesk AutoCAD · AI featuresMicrosoft 365 CopilotMicrosoft Copilot ChatMicrosoft Edge · Copilot sidebarMicrosoft Teams · recapMicrosoft Windows · AI featuresOpenAI ChatGPT BusinessZoom AI Companion3 Requests
Microsoft 365 Copilot
VendorMicrosoftWhere it runsExternal service under contractWho can use itLicensed users, after trainingReview byThree months from approval
Assessment by feature
Copilot in Word · drafting and summarisingPermitted
Copilot in Outlook · email summariesPermitted
Copilot in Teams · meeting recapAuthorisation required
Web search in chatOff with client data
Agents and third-party connectorsExcluded, pending assessment

An ongoing service, on a defined schedule

  1. 01

    Quarterly

    Monitoring of approved tool vendors and review with IT of the settings that enforce prohibitions

    Client deliverableA brief report, requests to update the assessments and indicators for management

  2. 02

    Annually

    Review of Policy and assessments, including in light of new regulation

    Client deliverableThe review report and the updated Policy

  3. 03

    On request

    Assessment of new features and pilots

    Client deliverableA new assessment, or a pilot plan

Illustrative examples

The Adobe suite, feature by feature

Illustrative case

The Adobe suite, feature by feature

A suite such as Adobe brings together dozens of AI features that process data in very different ways, so we assess it one feature at a time.

  • Established Photoshop neural filters run on the device, so they can be used even with client images.
  • The same filters in beta may send the image to the Adobe cloud, and remain excluded until assessed.
  • Adobe generative features, such as Generative Fill, run in the cloud and are governed by the contract with Adobe.
  • The same menu offers third-party models, such as Gemini, GPT and FLUX, which receive the image under their own terms and which administrators cannot block on mid-tier plans.
Enabling experimentation in a controlled environment

Experimentation

Enabling experimentation in a controlled environment

Employees who discover AI want to apply it to their own work. It is in the organisation’s interest to encourage this within a controlled environment, established before experimentation begins.

  • We establish a path for anyone wishing to trial a new tool or use case, with a point of contact who responds promptly.
  • Pilots start from public or synthetic data or closed cases, so they involve neither clients nor colleagues.
  • We benchmark pilot results against standard work on real cases before they inform documents or decisions.
  • We scale adoption gradually, once agreed criteria are met, and capture lessons learned.

Value is measured in new capabilities gained and risks reduced

Growth new capabilities

  • Adopt AI feature by feature, with every authorisation backed by a documented assessment
  • Respond promptly to requests for new tools, through a defined approval path
  • Demonstrate the rules in place to clients and regulators, with documentation kept up to date

Risk risk reduction

  • Reduce the risk of client and employee data leaving contractual boundaries
  • Bring AI used through personal accounts back to approved tools
  • Avoid disruption when vendors change their products, as assessments are kept current

Getting started: a discovery phase and an initial conversation

  1. 01

    Initial call

    A 30-minute session to understand the software in use, appoint a point of contact and review existing rules

  2. 02

    Discovery

    A baseline of active AI features, the data they access and the contracts that restrict them

  3. 03

    Rollout

    Policy and assessments approved within weeks, followed by the ongoing service

Let’s discuss your priorities

Contact us