Found what was actually running
A full inventory of AI tools in active use, including personal accounts and browser extensions that had never been through any approval. The gap between what leadership believed was in use and what was in use is usually the finding that changes the conversation.
Wrote an acceptable use policy that fits the operation
Not a generic template. A policy written for a safety-critical operator: what may be put into a model and what may not, which tools are sanctioned, how output gets reviewed before it informs a decision, and who to ask when it is not obvious. Short enough that people read it.
Moved the work onto commercial tiers
Consumer and commercial AI handle data in opposite ways — the free tiers may train on input by default, the commercial ones do not. Sanctioned tooling was deployed inside the tenant with the retention and admin controls that come with it.
Configured the controls underneath
Conditional access, data classification and retention aligned to the new policy, so the rules are enforced by configuration rather than by trust.
Trained the people doing the work
Role-specific sessions built around the tasks these teams actually repeat, not general AI theory. Staff left knowing which tool to use for what, and where the line is.