AI usage policy and security guidance
Drafted the AI usage policy in eight sections, including what consultants and auditors may put into personal AI accounts, tied to what data leaves the account rather than which tool is used, and a green, amber and red table of what may be entered. Revised the phishing-response guidance. Compared options for connecting Claude to SharePoint and NAS document stores: permissions, separation of client folders, and where data is processed.