AI adoption was moving faster than AI governance.
A nonprofit organization with approximately 300 managed users needed a way to let people use AI without allowing every new AI website to become an unreviewed destination for company information.
The users include employees, managers, contractors, and other authorized organizational users. The count does not include the people the nonprofit serves. Company work happens on company-managed devices.
People had legitimate reasons to experiment. But every new tool raised the same questions: Who operates it? What does it retain? Could submitted information be used for model training? Can access be shut off centrally?
The initial turnaround from discovery to a governed operating model took less than eight weeks.
The approved list had two platforms. The environment had 34 AI-related domains.
The review surfaced 34 AI-related domains. Only Microsoft Copilot and licensed ChatGPT were approved. The other 32 were blocked unless and until a documented exception was granted.
Sixteen of the 34 raised additional concerns in our review and were also identified as risky by Microsoft Defender. We are not publishing individual historical scores because we do not have the evidence in front of us to quote them precisely.
Blocked does not automatically mean malicious. It means not yet approved.
A point-in-time finding, not a permanent inventory.
Do not make people choose between getting work done and following the rules.
Give them a safe default. Make exceptions possible. Keep unknown tools closed until somebody has looked at them.
Copilot in the Microsoft tenant
The standard approved environment for general business use. People work inside the organization's managed Microsoft boundary.
Licensed ChatGPT
Available to people with a legitimate business need. Approved users are placed in a dedicated security group instead of receiving access by default.
Everything else
A user can request another service. The business purpose, vendor, account controls, security posture, and data handling get reviewed before access is allowed.
Software can enforce a boundary. It cannot make the decisions for you.
MICROSOFT PURVIEW
Label the data. See the Copilot activity.
Purview supports the program through data labeling and visibility into Copilot conversations. It helps the organization understand how information moves inside the approved environment.
DEFENDER FOR CLOUD APPS
Find the services. Enforce the block.
Defender helps identify cloud applications, supplies risk information, and supports blocking against AI services the organization has not approved.
tekRESCUE REVIEW
Look beyond the catalog.
Recurring reviews of company-managed devices and authorized endpoint and browser signals help find AI activity that platform controls may miss. Experimental scripts are extending that visibility, but this is still developing work, not a magic detector.
A block list is not an AI governance program.
People need to know what they can use, what they cannot do, and how to ask for something different. Otherwise the policy loses to the deadline.
- 01AI governance plan
Who owns the decisions, how tools are reviewed, and how the program changes over time.
- 02Formal policies
Clear acceptable-use rules, data boundaries, and responsibilities for employees and contractors.
- 03Exception process
A legitimate path for a person who needs a tool beyond the standard approved environment.
- 04One-page desk aids
The short version people can actually use while they are working.
- 05User acknowledgment
Users acknowledge the applicable technology terms and receive policies as they roll out.
No static block list stays complete for long.
New AI services appear constantly. A new domain may not be categorized immediately, and somebody may reach it before a recurring review finds it. Nobody can honestly promise otherwise.
The job is to make new services visible, evaluate them consistently, block what does not belong, and create a controlled path for tools the business actually needs.
In less than eight weeks, scattered AI use became a program people could follow.
New tools appeared without review. Leadership could not make a responsible decision about services it did not know people were using.
Copilot became the safe default. Licensed ChatGPT had a controlled exception. Everything else started blocked, with a real process for legitimate requests.
Observed unauthorized AI use fell to almost nothing. We are describing that result directionally because we are not attaching a manufactured percentage to evidence that was not collected as a formal study.
Five lessons from the work.
You cannot govern the AI services you cannot see.
An approved default works better than a policy that only says no.
Licensed access should follow business need, not curiosity.
Unknown does not mean malicious. It does mean review it before company data goes in.
Detection, approval, blocking, policy, and training have to operate as one system.