Field note
How to enforce an AI usage policy for employees
A written rule is not a control. Here is how to make the line on what AI can touch hold, using settings you already have.
An AI usage policy for employees only works if it is enforced, not just written down. ChatGPT Enterprise, Microsoft 365 Copilot, Google Workspace Gemini and Claude for Enterprise all now ship admin settings that block AI from touching specific data or systems, turning a policy line into a setting nobody can accidentally ignore.
Open the admin console
For the AI tool your team uses most
List active connectors
Every integration currently switched on
Turn off unapproved ones
If nobody remembers approving it
Turn on DLP or IRM
For your most sensitive data category
What does "what AI is allowed to touch" actually mean?
An AI acceptable use policy usually lists its rules in prose: which tools are approved, what data is off limits, when a human checks the output before it goes out. The one line that matters most in daily practice is narrower than the whole document: what data categories and what connected systems AI is allowed to touch at all. That single boundary, drawn clearly, does more to prevent an actual leak than the rest of the policy combined, because it is the line an employee crosses without meaning to, usually by connecting a tool to Drive or Slack and letting it read everything shared with them rather than the one folder the task needed.
Why a written rule is not enough on its own
A policy that says AI must not touch client financial records is a sentence, not a control. It relies on every employee remembering it, every time, across every tool they use. The tools themselves have caught up to this problem faster than most policies have. ChatGPT Enterprise, Microsoft 365 Copilot, Google Workspace Gemini and Claude for Enterprise each now ship admin settings that enforce a version of that same rule automatically, so the boundary holds even when nobody in the room is thinking about it.
Which admin settings actually enforce the rule, tool by tool?
In ChatGPT Enterprise, connectors to services like Google Drive, SharePoint and Salesforce are switched off by default, and an admin has to deliberately turn on each one from the workspace Apps settings, according to OpenAI's own admin documentation. In Microsoft 365, Purview's data loss prevention policies for Copilot can block a prompt from being processed at all when it contains a sensitive information type such as a card number or national ID, per Microsoft's Purview documentation. In Google Workspace, DLP for Gemini and Drive's information rights management settings can stop Gemini from retrieving specific protected files even when they are shared with the person asking, according to Google's Workspace admin help center. On Claude for Enterprise, custom roles set exactly which connectors, and which individual tools on those connectors, a given team is allowed to use at all, per Anthropic's support documentation.
What should you check first this week?
Open the admin console for whichever AI tool your team actually uses most, since that is where the real exposure already sits. List every connector or integration that is currently switched on, turn off anything nobody remembers approving, and turn on the data loss prevention or information rights management setting for your most sensitive data category, even if it only covers one system to start. That one setting change enforces more of the policy than another round of reminder emails ever will.
Sources
The takeaway
This week, open the admin console for your main AI tool, check which connectors are switched on, and turn off any you did not deliberately approve.
