Risk AssessmentHigh riskComparison recommended

AI Generative AI Policy Development Playbook

A professional services firm with 8,200 employees has no formal generative AI policy. Employees are using at least 14 different AI tools across client work, internal research, and marketing. Three incidents involving client data in AI prompts have occurred in 6 months. General Counsel needs a policy framework in 3 weeks.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: A professional services firm with 8,200 employees has no formal generative AI policy.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Generative AI Policy Development".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • Survey results: current AI tool usage by department (14 tools identified)
  • The three incident summaries involving client data
  • Client confidentiality provisions from the standard engagement agreement
  • Competitor firm AI policies (3 examples, publicly available)
  • Bar association and professional licensing guidance on AI use (where applicable)

Attachments: Documents (Documents)

The Prompt

You are an AI governance specialist developing a generative AI use policy for a professional services firm. I am attaching:

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Identify the highest-risk use patterns from the survey: which tools and use cases create confidentiality, IP, accuracy, or professional liability exposure?
2. Draft a tiered tool classification: approved (company-licensed, enterprise data handling), conditional (requires review and approval), prohibited (consumer tools with training data risks).
3. Define the specific prohibited actions: no client data in prompts without explicit client consent, no AI-generated content submitted as professional work product without human review, etc.
4. Address the three incidents: what policy provision would have prevented each one?
5. Build the employee training module outline and the governance structure (who approves new tools, who reviews incidents).

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • High-risk use pattern analysis
  • Tiered tool classification framework
  • Prohibited actions policy language
  • Incident-to-policy mapping
  • Employee training outline and governance structure

Review before you act

  • Validate this output against source files before relying on it: Identify the highest-risk use patterns from the survey: which tools and use cases create confidentiality, IP, accuracy, or professional liability exposure?.
  • Validate this output against source files before relying on it: Draft a tiered tool classification: approved (company-licensed, enterprise data handling), conditional (requires review and approval), prohibited (consumer tools with training data risks).
  • Validate this output against source files before relying on it: Define the specific prohibited actions: no client data in prompts without explicit client consent, no AI-generated content submitted as professional work product without human review, etc.
  • Validate this output against source files before relying on it: Address the three incidents: what policy provision would have prevented each one?.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Generative AI Policy Development, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface high-risk use pattern analysis; tiered tool classification framework; prohibited actions policy language; incident-to-policy mapping. Those are comparison artifacts — they only exist if more than one model runs. Risk-tier assignments and 'high-risk system' calls vary with how a model reads a use-case description. Comparison exposes those classification fights before they reach an exam.

AI GovernancePolicy and OversightRisk AssessmentHighDocuments

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.