Last month we looked at what happens when employees install AI connectors and instruction files they found on Reddit — and why a plain text file can behave like an executable. The response we heard most often from Queens business owners was some version of: fine, but what am I supposed to tell my people?
This is that answer. Not a ban. A policy — and a short one.
The instinct to ban is the expensive option
The reflex, particularly in a regulated firm, is to prohibit AI outright. It feels like the conservative choice. It isn’t, for a reason that has nothing to do with technology.
A ban doesn’t stop the paralegal pasting a deposition summary into a chatbot at eleven at night. It stops her telling you she did. You lose the one thing that actually protects you in front of a regulator: visibility into where your client data went.
Prohibition converts a manageable governance problem into an invisible one. And the firms that need governance most — law, medical, financial — are precisely the ones where invisible data movement is the thing you’re required to prevent.
Your regulator has already told you a policy is expected
This is the part most owners don’t realize. In all three of our regulated verticals, the guidance already exists, and none of it is waiting on new legislation.
If you’re a law firm
The American Bar Association’s Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, “Generative Artificial Intelligence Tools,” on July 29, 2024. It is the first national ethics guidance on lawyers’ use of generative AI, and it doesn’t invent new obligations — it maps existing Model Rules onto the new tool: competence (Rule 1.1), confidentiality (Rule 1.6), and supervision (Rules 5.1 and 5.3).
The supervision point is the one that matters here. Under Rule 5.1, lawyers with managerial authority are expected to establish clear policies on permissible AI use and supervise compliance with them. Under Rule 5.3, that extends to non-lawyer staff — including third-party contractors and providers outside the firm. A written policy isn’t a nice-to-have you get to defer. It’s how the supervisory duty is discharged.
The opinion is also explicit that before entering client information into a generative AI tool, a lawyer must assess whether that information could be disclosed to or accessed by others — inside or outside the firm — including through outputs generated by other people using the same self-learning tool. That is a technical assessment about a specific product, and it is not one a busy partner can make in the moment. It has to be decided in advance and written down. That’s what a policy is.
If you’re a financial firm under NY DFS Part 500
The Department issued an industry letter on October 16, 2024 — “Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks.” The most important sentence in it says it imposes no new requirements.
That sounds like relief. It isn’t. It’s the opposite. What it means is that Part 500 already covers AI: the risk assessment obligation, access controls, third-party service provider due diligence, and incident response all apply to AI use now, not when some future AI rule arrives. The letter removes the argument that AI sits unregulated until a dedicated standard appears. It names four risk areas specifically — AI-enabled social engineering and deepfakes, AI-enhanced attacks, theft of nonpublic information used to train models, and third-party vendor exposure — and directs covered entities to fold them into the program they already operate.
DFS returned to the subject on May 21, 2026 with a further industry letter on heightened risks from frontier AI models, again explicitly imposing no new requirements and again pointing at existing Part 500 practices. The pattern is consistent: the regulator’s position is that you already have the obligation.
If you’re a medical practice
The picture is less settled, and it’s worth being straight about that. HHS Office for Civil Rights published a proposed overhaul of the HIPAA Security Rule in the Federal Register on January 6, 2025 — the first substantial update in over a decade. It addresses emerging technologies including AI, and it would remove the “addressable” flexibility that has let smaller practices defer controls.
As of this writing it remains proposed. OCR received roughly 4,745 comments, the comment period closed in March 2025, and published finalization targets have already slipped once. Anyone telling you a confident date is guessing.
But here’s what doesn’t depend on the outcome: the current Security Rule already requires a risk analysis covering reasonably anticipated threats to ePHI. Staff pasting patient information into a consumer AI tool is a reasonably anticipated threat today. That obligation is live now regardless of what the final rule says.
What actually goes in the policy
One page. If it runs to five, nobody reads it, and an unread policy protects you from nothing.
- 1. Which tools are approved. Name them. “AI tools” as a category is not a decision. The distinction that matters is whether a tool trains on your inputs and whether your data is isolated — which is a product-by-product question, not a vendor-marketing question.
- 2. What must never be entered. In plain language, with your own examples. Client names. Patient identifiers. Account numbers. Draft filings. Anything under a protective order. Staff follow concrete examples; they do not follow the phrase “confidential information.”
- 3. Who decides on new tools, and how to ask. If there’s no route to say “can I use this?”, people will simply use it. Name a person and give them a channel.
- 4. The verification rule. Nothing generated by AI leaves the firm without a human who knows the subject matter checking it. Opinion 512 is pointed about this for lawyers — you cannot abdicate professional judgment to the tool — but it’s equally true of a billing code or a client email.
- 5. Disclosure. When you tell the client, and who decides. Whether client consent is needed depends on the tool and the data; it is not a question to improvise mid-matter.
- 6. What happens when someone gets it wrong. This is the section that determines whether the policy works. If the answer is discipline, you have built a ban with extra paperwork and people will conceal mistakes. If the answer is “tell us immediately and we’ll contain it,” you get the reporting that makes containment possible.
- 7. The date and the review interval. An AI policy written in 2024 describes a landscape that no longer exists. Put a review date on it, and keep it.
The part that isn’t a document
A policy on a shared drive is not a control. Two things have to sit under it.
The first is an inventory. You cannot govern tools you don’t know are installed. If your answer to “which AI tools are running in this office” is an estimate, that’s the first piece of work — and it’s the same asset-inventory discipline the proposed HIPAA rule would require anyway.
The second is training that names the specific behaviors. Not annual security awareness theater. Fifteen minutes on: here’s the approved tool, here’s what never goes in it, here’s who to ask, here’s what to do if you get it wrong.
There’s a broader point in the OCR enforcement posture that applies to all of this: written policies alone are not treated as evidence that a security measure was implemented. Regulators want to see that identified risks drove actual decisions — configurations changed, controls in place.
A binder is not a program.
Where to start this week
Ask three people in your office what AI tools they use. Not in a meeting — individually, with no consequences attached to the answer. Most owners are surprised, and the surprise is the finding.
Then write the page. It genuinely is one page.
