By William Price, Founder of Bastion Cyber Group·Published ·Updated
Most organizations already have AI in use before they have a policy for it — staff using assistants in the browser, features quietly switched on in existing tools, scripts calling an API. That's shadow AI, and the first step is simply to see it.
Week one: inventory
Survey teams, review expenses and SSO logs, and check which of your existing vendors have shipped AI features. The goal is a single list of where AI touches your data and workflows.
Week two: policy and tiering
Turn the inventory into a short, enforceable acceptable-use policy and tier each use by risk. High-risk uses (customer data, code, regulated records) get guardrails first.