AI tools
Two tools sit in this category. Pick one to see how to govern it.
This is the AI that arrived inside software your team already had. Nobody chose it; Microsoft and Google switched it on inside Word, Outlook, Excel, Docs, Gmail and Sheets.
That changes the governance question. You are not deciding which AI to allow. You are deciding which of your files the AI can see, because Copilot and Gemini read whatever the person using them can read. The boundary you set is a boundary on your own documents, mail and spreadsheets.
Most everyday work here carries low consequence. Someone drafts, summarises or tidies a document, reads the result and moves on. The stakes rise when meeting notes and customer emails bring personal information into scope, and when anything written for customers leaves the building without a second pair of eyes.
Here is what we ask of you. Tell staff what they may open or paste in front of the AI. Keep a person checking outputs, with a firmer check on anything customer-facing. Watch for the vendor changing what the tool can do, because these two vendors change it often. Copilot recently gained the ability to run code inside a spreadsheet without asking; if your team analyses data with it, that use deserves its own entry.
Open a tool page to see how each is used and what we checked last.
How to govern Gemini for Google Workspace: the AI inside Gmail, Docs, Sheets and Meet, with reach into everything your team stores there.
How to govern Microsoft 365 Copilot: the AI inside Outlook, Word, Excel, PowerPoint and Teams, and what changes when it starts acting on your data.