Fifty-one percent of corporate boards don't have any rules on AI use, Deloitte found, and the same week Anthropic had to confirm that Claude's shareable links were showing up in Google search. Here's what a policy actually needs to cover, not just gesture at.
Name the data that never goes in a prompt, specifically. "Don't share sensitive stuff" isn't a rule anyone can follow, because nobody agrees on what that means. Spell out the categories: client contracts, anything under an NDA, unreleased financials, credentials and API keys, personal data about employees or customers. Leave a category unnamed and someone will decide for themselves, and they'll get it wrong.
Make sure people actually understand what "shareable" means. The Claude story happened because a public link felt like a private handoff. Anyone who's ever generated a share link for a chat, a doc, or a dashboard needs to know that public means public: a search engine can find it the second it lands anywhere a crawler can see, not just wherever you sent it. That includes the link you posted in a forum to ask for help, not just the one you emailed a client.
Check vendor retention and training settings, tool by tool. Enterprise tiers of most AI tools keep your prompts out of training data. Consumer tiers of the same product often don't, and a policy that never distinguishes between the two is really just hoping people picked the right one. Saying "use approved tools" without confirming which settings are actually flipped on hasn't covered anything.
Name who approves a new tool, and how fast. Deloitte's own numbers make the gap obvious: 47% of boards don't even use AI in their own work, and only 8% use company-approved tools for committee business. No named approver and no real timeline means the actual policy is whoever asks first gets a yes from whoever they happen to ask.
Say what happens when someone breaks it. A policy with no stated consequence, and no way to flag a mistake without getting fired, isn't a policy. It's a memo nobody follows once things get busy. State the consequence, and make it clear that reporting a slip-up beats hiding one, because the hidden ones are the ones that actually cost you.
None of this needs new software, just decisions someone actually has to write down. If you're still working out where AI governance fits into a broader readiness plan, that's the conversation we start with clients. AI that ships, not AI that demos.

