← All work

An Australian financial services licensee · 2026

AI usage policy, register and enforcement

Staff adopt these tools individually, so there is no purchase record and no list. The register is the quick part and it usually surprises people. The enforcement is the part almost nobody delivers.

The full argument for why enforcement is the half that counts sits on the AI governance page. This is the shorter version, and what the work looks like.

How to tell whether you have this

Ask around the firm what AI tools people use for work. Not whether they should. What they actually do.

You will not get a complete answer, and the incompleteness is the finding. Most AI tooling in a small firm arrives through individuals rather than procurement, so there is no purchase record, no contract and nothing to audit against.

Why it happens

Someone summarised a client document in a chatbot, probably in the last fortnight, almost certainly for a sensible reason and with no intent to do anything wrong. That is the ordinary case rather than the alarming one, and it is why this is difficult to address by telling people off.

The tools also arrived faster than any policy cycle could move.

How I would approach it

  1. The register first. What is in use, by whom, against what kind of data. Everything downstream depends on it, it is the quickest of the three, and it is routinely the one that surprises people.
  2. The boundary second. Classification of the data that matters, and a written decision about which categories may reach which tools. Specific enough to follow, rather than a template that says be careful.
  3. The enforcement third, and this is the part that changes your answer. The same position implemented as policy in Microsoft Purview, so it acts on the data itself rather than depending on everyone remembering what the document said.

Only the second of those is a writing exercise. A policy in a document holds if everybody remembers it. A policy at the data layer holds whether they do or not, and produces a record either way.

What I will not claim

That I have run this across a portfolio of clients. One organisation, a small licensed firm, and part of a wider compliance and IT standards engagement rather than a standalone AI programme. Guidelines, a usage register, and usage policies implemented in Purview.

What transfers is the sequence, and the fact that the enforcement half is achievable inside a Microsoft estate a small firm already pays for. Being straight about the scope is more useful to you than a broader claim, because it is the version that survives your first hard question.

What it looked like in practice

delivered

Figures from the engagement described above, not a projection of what your estate would produce. Yours will look different.

RefFoundNowWhat the figure refers to
013artefacts delivered: guidelines, usage register, enforced policy

Is this yours?

If any of the above sounds like your estate, say so and I will tell you what checking would involve. Most of these start as a short look rather than a project.

Not sure it is this one? The rest of the work covers monitoring, identity, deployment, cost, AI use and compliance documentation.

Related work

All work