AI tools
Four tools sit in this category. Pick one to see how to govern it.
The most personal information most small businesses hold gets captured in passing: a recorded call, a transcript of a meeting where someone described a health issue or a grievance, a draft email about a customer sitting in a writing assistant's history.
That is the profile of this category. Otter, Fireflies, Grammarly and Notion AI all have a person reviewing every output, and most uses carry moderate consequence. But over half of the common uses touch personal information about people who did not choose to be part of the recording or the draft, and the tools keep what they capture.
Governing these tools is less about what they produce and more about what they hold. Decide which meetings and which documents the tool may be given. Find out where the recordings and transcripts live, how long they stay, and whether they are protected at rest. Keep the review habit too: a summary of a meeting is a claim about what people said, and people who were not there will read it.
For plain writing help on internal documents the governance is light and the rhythm is annual. The step up comes with recordings, and with anything drafted for a customer.
Open a tool page to see which uses your team is likely running and where the personal information enters.
How to govern Fireflies.ai: meeting notes and transcripts captured automatically, and the consent and retention questions that follow.
How to govern Grammarly: writing assistance that reads everything your team types, including messages that contain sensitive detail.
How to govern Notion AI: drafting, summarising and Q&A across your team's knowledge base and the confidential pages inside it.