What we do
AI governance for a small or mid-sized company is mostly three things: knowing where AI is already being used, deciding what data is allowed to go where, and writing that down in language your team will actually follow. It does not require a committee or a hundred-page framework.
In detail
Decide what should never be pasted into a public model, put sensible rules in writing, and know where AI is already being used inside your company.
Start with the free audit →Before any policy is worth writing, it helps to know what is happening. Staff experimenting with personal accounts is nearly universal and rarely malicious, but it is where most real data exposure comes from. We surface it without turning it into a disciplinary exercise.
The practical question is which information can go into a commercial tool with a no-training agreement, which needs to stay inside systems you control, and which should never leave the building. Once that line exists and people know it, most of the risk goes away.
A short acceptable-use document in plain language beats a long one nobody opens. It should say what is allowed, what is not, what has to be checked by a person, and who to ask. That is usually two pages.
The rest of what we do
Find where AI can create measurable value before you invest in implementation. This is the free audit: a prioritized roadmap with the hours and dollars behind each opportunity.
Build practical agents, automations and workflow solutions around real business problems, in the systems your team already runs on.
Help your team use AI confidently in the work they already do. Most AI projects stall on adoption, not technology.
Get more from the platforms you already pay for, and stop paying for the ones you do not need.
Common questions
If anyone in your company is using AI, and they almost certainly are, then yes. It does not need to be elaborate. A short document that says what data can go where, what has to be verified by a person, and who to ask when it is unclear covers most of the real risk.
It depends on the plan and the data. Business and enterprise tiers generally come with agreements that your inputs will not be used for training, which changes the calculus considerably from a personal free account. The harder question is which categories of your data are appropriate at all, and that is worth deciding deliberately rather than per employee.
That needs a stricter answer than general business data, usually a vendor that will sign the relevant agreement, deployment inside your own environment, or a local model where nothing leaves your network. We tell you which of those a given use case requires before it gets built, not after.
The audit is free and the roadmap is yours to keep, whether you build it with us or not.
Free · No pitch · A plan you keep