Skip to content
IT Works

AI deployment & governance

Putting a policy around AI a power company was already using

Staff had adopted consumer AI tools on their own. We inventoried what was in use, wrote an acceptable use policy that fit a safety-critical operator, moved the work onto commercial tiers, and trained the teams actually doing it.

Power generation · Alberta · anonymised at the client's request

The situation

What we walked into

AI use had started from the bottom up. People were pasting operational notes, procurement documents and drafts into whatever free tool they had found, on personal accounts nobody administered.

There was no acceptable use policy, so there was also no way to tell anyone they were doing something wrong — and no defensible answer if a regulator or a counterparty asked how the company controlled it.

The concern was specific rather than abstract: commercially sensitive material and operational detail leaving the tenant through a channel with no logging and no retention control.

The work

What we built

Found what was actually running

A full inventory of AI tools in active use, including personal accounts and browser extensions that had never been through any approval. The gap between what leadership believed was in use and what was in use is usually the finding that changes the conversation.

Wrote an acceptable use policy that fits the operation

Not a generic template. A policy written for a safety-critical operator: what may be put into a model and what may not, which tools are sanctioned, how output gets reviewed before it informs a decision, and who to ask when it is not obvious. Short enough that people read it.

Moved the work onto commercial tiers

Consumer and commercial AI handle data in opposite ways — the free tiers may train on input by default, the commercial ones do not. Sanctioned tooling was deployed inside the tenant with the retention and admin controls that come with it.

Configured the controls underneath

Conditional access, data classification and retention aligned to the new policy, so the rules are enforced by configuration rather than by trust.

Trained the people doing the work

Role-specific sessions built around the tasks these teams actually repeat, not general AI theory. Staff left knowing which tool to use for what, and where the line is.

The outcome

Where it landed

  • A sanctioned toolset with administration behind it, replacing unmanaged personal accounts.
  • A written acceptable use policy the company can hand to a regulator, an insurer or a counterparty.
  • Controls enforced in configuration, so compliance does not depend on everyone remembering.
  • Staff trained on the tools they use, with a defined route for anything the policy does not cover.

Got something shaped like this?

Most of this work starts the same way — finding out what is actually running before anyone proposes a fix.