Follow organizational AI policies and governance standards
Follow the organisation's AI policy and governance standards on disclosure, approval, retention and acceptable use, and escalate cases the policy does not cover instead of deciding alone.
Key points
- 1
Typical policy elements: which data classes may enter AI tools, which tools and plans are approved, how to request a new tool or connector, when AI assistance must be disclosed, who reviews outputs, how long content is retained, and who decides unclear cases.
- 2
Disclosure rules apply whenever AI assisted, not only when a document is mostly AI-written; do not decide privately that your editing crossed a threshold that removes the obligation.
- 3
Connectors (Google Drive, Gmail, Slack, and others) create new flows of organisational data into Claude. If the governance standard requires integrations to be assessed and registered, do that before enabling the connector even though Claude itself is approved.
- 4
Approval must be in the form the policy requires: a verbal 'go ahead' is not registration in a use-case inventory, a named accountable owner, or a review step.
- 5
When the policy is silent on a sensitive category (employee investigations, grievances, health, legal matters), treat the case as sensitive and escalate to the policy owner, HR lead or privacy team before proceeding. Silence is a gap, not permission.
- 6
Do not ask Claude to rule on whether the policy allows a use; it can help you read the policy, but the decision and accountability belong to the organisation.
- 7
Shadow AI (personal accounts, personal cloud copies of company data, unapproved browser extensions) bypasses controls and is itself a policy breach; the fix is to get access to the approved workspace.
- 8
Team and Enterprise plans give administrators controls such as SSO, role-based access, connector and model management, audit logs and a compliance API; a practical policy leans on these rather than manual prompt logging by staff.
- 9
A workable policy avoids two extremes: waiving review because the plan is 'enterprise-grade', and banning all AI use until a perfect policy exists.
- 10
Bringing an existing workflow into compliance (register it, name an owner, add review) is normally better than stopping it or papering over it with prompt instructions.
Read the source
Test yourself on Follow organizational AI policies and governance standards
Ten questions, with the answer and explanation after each one.