Five Questions Your AI Policy Should Answer

Your employee pasted a client's financial records into ChatGPT this morning. No breach alert fired. No log entry was created. The data left your environment, entered OpenAI's infrastructure, and your firm has no contractual protection governing what happens to it there. The compliance event already occurred.
The obligation exists before the enforcement action
FINRA's supervision guidance is technology-neutral, which means it attaches to employee tool use, not to a regulator's decision to investigate that use. The AMA has taken the same position on AI governance in healthcare settings: supervision, documentation, and oversight apply to AI tools the same way they apply to any other tool a staff member picks up. Neither body waited for an AI-specific enforcement action before publishing these obligations.
The counterargument worth taking seriously is this: no regulator has yet issued a formal enforcement action naming shadow AI use as the cited violation. A compliance attorney could reasonably argue that technology-neutral language requires a specific application to a named tool category before a firm is "in violation." That argument is not frivolous.
It also doesn't hold. The obligation attaches when the tool is in use and unsupervised, not when a regulator decides to look. Firms made the same argument during early shadow IT enforcement, and the enforcement record from that period settled it: the obligation existed before the investigation, and the investigation was just how the regulator found out. Shadow AI is structurally the same problem, except the data leaving the organization tends to be more sensitive and the logging is weaker.
What employees are feeding into public AI accounts
Security vendor telemetry documents a consistent pattern across industries: employees paste source code, legal documents, and client records into personal or public AI accounts. These sessions sit outside enterprise logging. No contractual terms govern data retention by the model provider. Large language models carry documented memorization risks, where training or fine-tuning processes can cause fragments of input data to surface in outputs to other users. Adversarial extraction techniques can pull sensitive content from model outputs even when the original session has ended.
This is not a theoretical attack surface. The data moves the moment an employee hits enter.
The five questions
Founders without in-house legal or compliance staff need a diagnostic scaled to that constraint. These five questions map directly to the supervision dimensions FINRA and the AMA have already made enforceable.
First: who has access to AI tools inside your firm, and did you authorize it? If you don't know which tools your employees use, you don't know what data is leaving your environment.
Second: what data are employees feeding into those tools? Client records, source code, and legal documents are regulated inputs. If employees treat AI prompts like a search bar, regulated data is already in motion.
Third: do you have any logging or review process for AI-assisted work? Technology-neutral supervision obligations require documentation. A session that leaves no record is a session you cannot supervise.
Fourth: what do your vendor contracts actually say about data retention? "We don't train on your data" in a terms-of-service document is not a data processing agreement. The distinction matters when a regulator asks for your documentation.
Fifth: do your employees know the rules? The supervision obligation attaches to the firm. Individual worker ignorance does not transfer the liability.
I have a strong bias against compliance frameworks sold as software products. The market for "AI governance platforms" is full of vendors who charge significant fees to generate audit trails for policies the founder never actually wrote. A Word document with five answered questions and a date on it does more enforceable work than a dashboard with no underlying policy.
Where this leaves you
If you answered "I don't know" to two or more of those questions, your current AI usage is not supervised in any sense FINRA or the AMA would recognize. The compliance event is not coming. For firms where employees are already using AI tools with client data, it is already in the past.

Read next

AI as Strategy
How to Write an AI Policy Your Team Will Actually Follow
A practical checklist for small business owners who want data safety and output review rules without hiring a lawyer or IT staff.
4 min read

AI as Strategy
One-Page AI Policy Template for Founders
A one-page AI use policy covering approved tools, data restrictions, and escalation paths is the only governance measure employees will actually follow — before
3 min read

AI as Strategy
Your AI Policy Checklist for Safe Small Business Use
Half of small business founders already paste sensitive data into public AI tools. Here's the one-page policy that stops ungoverned use before it costs you.
3 min read