Why 'waiting on AI' isn't a strategy
Per McKinsey's State of AI 2024 survey, about 72% of organizations use AI in at least one function, and McKinsey estimated back in 2023 that generative AI could add $2.6–4.4 trillion a year to the global economy. Even if your business is "waiting" — your employees aren't: they're drafting quotes, summarizing meetings and answering customers with these tools today.
Where is the real risk for a business?
Not in the model's answers — in the input. A pasted quote carries your price book and the customer; an Excel file "to tidy up" carries payroll; a meeting summary carries the negotiation. Per Cyberhaven, about 11% of what employees paste into AI tools is sensitive data, and per IBM's Cost of a Data Breach 2024 an average breach costs $4.88 million.
- Customer data — lists, contracts, commercial terms (personal data under privacy law).
- Pricing and trade secrets — price books, costs, strategy.
- Employee data — salaries, reviews, personal details.
- Intellectual property — code, formulas, proprietary processes.
The one-page AI policy: what must be in it?
- Approved tools — preferably business-tier with a no-training commitment.
- The forbidden list — based on what never to paste into ChatGPT: customers, prices, employees, code, credentials.
- The safe path — not just "don't": when a sensitive document must be worked on, clean it first (anonymization) and work on the clean copy.
- Ownership and enforcement — who approves a new tool, and who to call when something goes wrong.
Rollout checklist: six steps for a business
- Map current usage — ask employees what they already use (the answer will surprise you).
- Pick 2–3 approved tools on a business tier.
- Publish the one-page policy from the section above.
- Give employees an anonymization tool — a ban without an alternative simply doesn't hold.
- Run one hour of training: the forbidden list + a demo of the safe path.
- Update your security procedures to include an AI section.