top of page
Image by NASA

AI Policy & Understanding the Problem It Solves

  • 1 hour ago
  • 6 min read
How to Write an AI Policy

Artificial intelligence is moving quickly, and businesses are feeling the pressure to move with it. New tools and features are being introduced constantly, employees are experimenting with them and software companies are adding AI capabilities to products businesses already use (and pay for). What we're seeing is that leadership teams are increasingly asking some version of the same question: What should we be doing with AI?


It's an important question, but it may not be the best place to start.

We were recently invited to join a client committee focused on a much bigger question: How will AI impact their business? The conversation isn't simply about technology, it's about where AI makes sense, what problems it could help solve and how it could affect the way the business operates and grows. This is an important distinction because before investing in new technology or developing a company AI policy, businesses should first ask: What problem are we actually trying to solve with AI?


Start With the Business, Not the AI Tool


There can be a tendency to approach AI adoption by looking at what's available instead of what might be the best fit. From ChatGPT, Claude and Microsoft Copilot, to the proprietary AI solutions built into software like Clio. The questions are endless so the first step is to do a deep-dive on the problem your company wants to solve.

AI is changing too quickly for the product itself to be the strategy. Instead, this can be a good opportunity for leadership to step back and think about where the business is going with the main goal of understanding how AI can help the firm with its primary goals.

  • What work is taking up too much of an employee’s time?

  • Where are there repetitive processes that could be improved or automated?

  • What information is difficult to find or organize?

  • Where can professionals spend less time on administrative work and more time applying their expertise?

  • What does the company want to look like two, three or five years from now?


Once those questions are clearer, it becomes much easier to determine where AI may, or may not, have a useful role in your organization.


What Pain Points Can AI Actually Help You Solve for Your Business?

AI has the potential to improve efficiency in areas such as research, document review, summarization, drafting, data analysis, internal knowledge management and routine administrative work.

That said, the goal shouldn't simply be to use more AI, it should be to identify areas where the technology can produce a meaningful business benefit without introducing unnecessary risk(s), sacrificing quality or adding technology costs. All of this requires understanding both what AI does well today, and where human expertise is still essential for your business.


For example, a tool may be capable of producing a draft in seconds but that doesn't necessarily mean the draft is ready to be sent to a client, it still needs to be reviewed by a human. So, the more important question becomes what will it take to get AI-generated work to a level of quality that the business can actually use? The answer may involve better tools, better data, better processes and/or simply better training for the people using them.


AI Doesn't Eliminate the Need for Expertise

One of the biggest misconceptions about AI is that the technology itself creates the value. It doesn't. We've been using forms of AI for years, from increasingly intelligent spellcheck and predictive text to automated assistants. And as anyone who's ever had spellcheck change the wrong word knows, sometimes a human still needs to check the work.


When it comes to using AI, two people can have access to exactly the same AI platform and produce very different results. Often the knowledge, judgment and skill of the person using it is key in getting the best results because professionals still need to know whether the information they're receiving makes sense. They need to understand the context, recognize errors, ask better questions and determine whether the final result meets the standards of their business and clients.

That means AI adoption isn't only about giving employees access to technology, it also means businesses need to think about AI literacy: teaching employees how to use these tools effectively, critically and responsibly.


So How Does AI Impact the Billable Hour?

For professional services firms, AI also introduces a bigger business question. What happens when technology makes professional work significantly faster? If research, analysis, document preparation or other work that previously required several hours can eventually be completed in a fraction of that time, the impact extends beyond productivity. It may affect the economics of the firm.


For businesses built around billable hours, increased efficiency raises questions about pricing, staffing, utilization and how clients perceive value. That doesn't necessarily mean the billable hour disappears, it just means that firms might begin thinking about how they define and charge for the value of professional expertise when technology changes the amount of time required to produce the work. Those conversations belong right alongside the technology conversation, not weeks, months or years after it.


Is Your Firm Making Cybersecurity Part of the AI Conversation?

As employees begin experimenting with AI, another issue becomes increasingly important: what information is being entered into these systems?


An employee trying to work more efficiently may copy information into an AI platform without understanding where that data goes, how long it is retained or whether it could be used for other purposes. Depending on the business, that information could include:

  • Client or customer information

  • Confidential business information

  • Financial data

  • Contracts and legal documents

  • Intellectual property

  • Employee information

  • Proprietary processes or internal communications

 

Businesses therefore need to understand not only which AI tools employees are using, but also the security, privacy and data-handling policies associated with those tools. The question isn't simply, “Can employees use AI?”, it's also, “What can AI have access to?”.


We are already addressing this with many of our clients using Egnyte's MCP feature and planning future rollouts. MCP (Model Context Protocol) provides a standardized way for AI tools to connect with and access approved data and systems. In this case, it helps organizations manage and secure how AI interacts with company data. It also provides more control over what information AI tools can access, how that information is made available and stored over time.

This is a good example of why AI planning and policy isn't just about which platform employees use. Businesses also need to consider how AI is accessing company information and whether the technology behind that access is properly configured and managed.


This Is Where an AI Policy Becomes Important

A company AI policy can establish consistent expectations for how employees use artificial intelligence at work. Depending on the organization, a policy may address:

  • Approved and prohibited AI tools

  • Acceptable business uses

  • Types of information that cannot be entered into AI platforms

  • Requirements for reviewing AI-generated work

  • Privacy and security expectations

  • Client confidentiality

  • Intellectual property considerations

  • Employee accountability

  • Procedures for evaluating and approving new AI tools


An AI policy shouldn't exist simply because AI is becoming more common, the policy should reflect how the organization actually wants to use the technology. A business that hasn't thought through its goals, risks and workflows may end up with a policy that's either so restrictive that employees ignore it or so broad that it doesn't provide meaningful guidance.


Your AI Policy Should Be Part of a Larger Strategy

Your law firm, financial services company, architecture firm and creative agency may use AI very differently, so for the most part there is no ‘one size fits all’ AI strategy. These industries may also have very different obligations around confidentiality, data security, compliance and client expectations. That's why AI planning should start with the business itself by asking:

  • What problem are we trying to solve?

  • What are we trying to improve?

  • Where could AI create meaningful efficiencies?

  • Where do we still need human judgment?

  • How could greater efficiency affect our business model?

  • What information needs to remain protected?

  • What security guardrails do employees need?


Only then does it make sense to decide which tools belong in the environment and what the organization's AI policy should look like.


AI may be changing the tools businesses use but the more important question is how businesses, and the people inside them, choose to use those tools.


Ready to discuss an AI strategy or AI policy for your company?



bottom of page