Governing generative AI without banning it
ISO/IEC 42001 and the NIST AI RMF give a usable frame — here is how to reduce it to one page.
By SpaceNet
Banning generative AI pushes its use into the shadows. Allowing it without rules exposes company data. In between, a one-page policy is often enough to get started.
Three categories of use
- Allowed: rewording, summarizing public documents, writing help with no internal data
- Supervised: internal data, only in tools approved and configured by the organization
- Prohibited: personal information, confidential client data, automated decisions without human review
Four simple rules
- Use approved tools only
- Review and own any content produced
- Report any inaccurate or inappropriate output
- Never enter credentials or secrets
References: ISO/IEC 42001:2023; NIST AI Risk Management Framework 1.0.