Know what is in use
Identify AI services, connected apps, the people using them, and the data they can access. Offer an approved route for common tasks.
Which AI tools are people using—and what are they sharing?
Give people an approved front door and a clear way to check who is on the other side.
Sensitive information can leave through an unapproved tool. A convincing message can trick someone into handing over access.
Identify AI services, connected apps, the people using them, and the data they can access. Offer an approved route for common tasks.
Warn or block sensitive transfers where policy requires it. Check app permissions and detect suspicious messages and account activity.
Confirm payment, account-change, or sensitive-data requests through a separate trusted channel. Do not share passwords or sign-in codes. Give people a simple way to report concerns.
Workplace IT + security + privacy
WHAT TO KEEP IN MINDDiscovery can miss personal accounts or unmanaged devices. Polished text alone does not prove AI involvement; blocking prompts cannot eliminate deception.
Names you may encounter in a buying conversation. Products often span several areas.
Every area depends on clear ownership, policy, and evidence.
See the governance foundation