Skip to main content
AI GovernanceComplianceCalifornia PrivacyManaged ITCybersecurity

Do You Need a Written AI Use Policy? A California Owner's Guide

· By Ashkaan Hassan

The Real Question Isn’t “Should We Use AI” — It’s “What Can You Prove”

Every business owner in Los Angeles has already had the AI conversation internally. Someone on the team is using ChatGPT. Someone in finance pasted a vendor contract into a chatbot to get a summary. Marketing is drafting with Claude. The paralegal found a transcription tool that is genuinely faster than the one you bought.

That ship sailed. The question that actually lands on an owner’s desk in 2026 is narrower and harder: when a client, an insurer, a regulator, or opposing counsel asks how you govern AI, what document do you hand them, and what evidence backs it up?

This post answers that. Not “AI is important.” Specifically: what changed in California law, what a defensible policy contains, which technical controls make it real instead of decorative, and how to sequence the rollout so it doesn’t stall in month two.

What Actually Changed in California — And What Didn’t

Three separate regulatory tracks matured, and they get conflated constantly. They are not the same thing and they don’t apply to the same people.

Frontier model transparency (probably doesn’t apply to you). California’s Transparency in Frontier Artificial Intelligence Act, signed in September 2025, targets developers training models above enormous compute thresholds with annual revenue above $500 million, with civil penalties up to $1 million per violation — see the enacted bill text on the California Legislature’s site. If you run a law firm or a post-production house, this does not regulate you. It matters anyway, because it establishes a disclosure norm — your clients and enterprise customers are already borrowing its vocabulary for their vendor questionnaires.

Automated decision systems in employment (probably does apply). California’s Civil Rights Department regulations on automated-decision systems in employment took effect October 1, 2025, and they reach any employer using automated tools in hiring, promotion, or other employment decisions — including resume screeners, video-interview scoring, and personality assessments. The rules extend record-retention obligations to four years for ADS data, including the criteria and models used, per the Civil Rights Department’s employment regulations. If you use an applicant-tracking system with any scoring or ranking feature, you are in scope and you likely didn’t build a retention plan for it.

Automated decisionmaking under CCPA (applies if you’re a covered business). The California Privacy Protection Agency’s regulations on automated decisionmaking technology, risk assessments, and cybersecurity audits are phased. Businesses must comply with the ADMT requirements by January 1, 2027, and the first risk-assessment attestations are due to the agency by April 1, 2028, with cybersecurity audit deadlines staggered by revenue — first for businesses above $100 million in annual gross revenue, later for smaller ones. The CPPA’s regulations page carries the operative text and timelines.

The practical read: the deadlines look far away, and the work that satisfies them is a year of accumulated documentation, not a weekend project. Businesses that start assembling evidence in 2027 will be assembling it retroactively about 2026 activity they never logged.

Your Shadow AI Problem Is Already Measurable

The strongest argument for a written policy isn’t legal. It’s that unmanaged AI use is now a documented breach vector with a price tag attached.

Verizon’s 2025 Data Breach Investigations Report found that roughly 15% of employees routinely accessed generative AI systems on corporate devices, and that the large majority of those accounts — around 72% — were registered with non-corporate email addresses. That is the entire problem in one sentence: work data flowing into consumer accounts your IT team cannot see, suspend, or produce records from.

IBM’s 2025 Cost of a Data Breach Report put the global average breach cost at $4.44 million and the U.S. average at $10.22 million, and found that 20% of surveyed organizations reported a breach stemming from shadow AI, while 97% of organizations that experienced an AI-related security incident lacked proper AI access controls.

For an LA professional-services firm, the exposure isn’t abstract. It’s a confidential settlement term in a consumer chatbot’s training-eligible history. It’s a pre-release cut description in a transcription vendor’s retention window. It’s a client’s PII in a browser extension nobody approved.

Four AI Postures, Compared

Most businesses land in one of four positions. Only two of them are defensible.

PostureWhat it means in practiceData exposureEvidence you can produce on demandEffect on the teamBest fit
Hard blockAI domains blocked at the firewall and in the browser; no approved toolLow on paper, high in reality — usage migrates to personal phones where you have zero visibilityA blocklist. No usage records, no exception logQuiet resentment; the fastest people route around youRegulated pilots with an imminent audit and no time to configure alternatives
Tolerated consumer AINo policy, no procurement, staff use free accounts on work devicesHighest. Data leaves under personal accounts with no DPA, no tenant boundary, no legal hold capabilityEssentially none. You cannot answer “who used what, on which matter”Fastest short-term productivity, largest long-term liabilityNobody. This is the default state, not a choice
Enterprise-licensed AI, ungovernedTenant-issued accounts (Copilot, enterprise ChatGPT/Claude) but no policy, no DLP, no reviewModerate. Contractual protections exist; behavioral controls don’tLicensing records and basic admin logs. Weak on purpose limitation and human reviewGood adoption, uneven judgment about what’s appropriate to inputA reasonable interim state while governance is built
Governed AI operationsEnterprise accounts plus written policy, an approved-tool register, DLP on sensitive labels, logged exceptions, and named human review for consequential decisionsLowest realistic. Sensitive categories are blocked at the data layer, not the honor systemTool register, access logs, DLP incident history, exception approvals, ADS inventory, review recordsHighest sustained adoption, because staff know what is safeAny firm handling client confidences, PHI, PII, or pre-release material

The cost conversation here is about predictability, not magnitude. Governed AI shifts spend from unbudgeted incident response and questionnaire scrambles into planned, recurring operational work. Ungoverned AI is cheap right up until it is a breach notification.

What Belongs in the Policy — And What’s Filler

Most AI policies circulating in LA right now are two pages of “use AI responsibly” and a ban on “harmful content.” That document does nothing in an audit. A policy that holds up has these components:

An approved-tool register, by name and version. Not “approved enterprise AI tools.” A living list: this tool, this tenant, this data classification allowed, this owner, this renewal date. If a tool isn’t on the list, using it is an exception requiring approval.

Data classification tied to tool permission. Map your existing labels — Public, Internal, Confidential, Client-Privileged, Restricted — to what may be entered into which tier of tool. This is the single most useful page in the document, because it converts judgment calls into lookups.

A prohibited-inputs list with real examples from your business. Generic lists get ignored. “Do not paste unredacted deposition transcripts, unreleased casting or scheduling documents, client trust-account records, or anything under a protective order into any tool not on the approved register” gets remembered.

Human-in-the-loop requirements for consequential decisions. Name the decision categories where a human must review and be accountable: employment screening, credit or eligibility determinations, client-facing legal analysis, financial reconciliation. Name the role that reviews, not “a qualified person.”

Disclosure rules. When AI-assisted work product goes to a client, a court, or a counterparty, when do you disclose? Many outside counsel guidelines and studio vendor agreements now address this directly, and your policy needs to defer to the stricter contract.

Retention and legal-hold handling. Where do prompts and outputs live? Are they within your retention policy? Can you place them under legal hold? If the answer is “we don’t know,” that is a finding waiting to happen.

An exception process with a log. Every governance program that lacks a fast exception path gets circumvented. Make it a short form, a named approver, a time limit, and an entry in a log you can produce.

Named ownership and a review cadence. One accountable owner. A scheduled review. A version history.

The Controls That Make the Policy Real

A policy without enforcement is a liability document — it proves you knew and didn’t act. In a Microsoft 365 environment, which is where most LA professional-services firms live, the enforcement layer looks like this:

Identity first. Conditional Access policies that require managed devices and compliant sign-in for AI tools, and that block sign-up with corporate email to unapproved services. This is what closes the shadow-AI gap the DBIR describes — you cannot govern a tool your employees registered with a personal Gmail.

Sensitivity labels plus DLP. Apply Purview sensitivity labels to client matter folders and finance repositories, then write DLP rules that prevent labeled content from being pasted into browser-based AI endpoints. Endpoint DLP catches the copy-paste path that network filtering misses.

Understand what your enterprise tool actually does with data. Microsoft documents that Microsoft 365 Copilot prompts and responses are not used to train the foundation models and that Copilot inherits your existing permissions — details are in Microsoft’s Copilot data protection documentation. That second half is the trap most firms hit: Copilot will happily surface an overshared SharePoint site to someone who technically had access all along. Permission hygiene is an AI control now.

Browser and extension governance. Managed browser profiles with an extension allowlist. A surprising share of AI data leakage happens through unvetted browser extensions with broad page-read permissions.

Logging you can actually query. Unified audit log retention long enough to answer a question posed a year later, and alerting on new AI-domain sign-ins from corporate identities.

An ADS inventory. Separately from the chatbots, inventory every vendor system that scores, ranks, or filters people — ATS, background-check tools, scheduling optimizers. That inventory is what the California employment rules and the CPPA’s ADMT provisions actually reach.

Map It to a Framework Your Insurer and Clients Recognize

Don’t invent a governance structure. Adopt one that appears on questionnaires.

The NIST AI Risk Management Framework organizes AI governance into four functions — Govern, Map, Measure, Manage — and it’s free, U.S.-government-published, and increasingly the default reference in vendor security reviews. Structure your policy’s sections to mirror those functions and your answers to client questionnaires practically write themselves.

If your clients are enterprise or international, ISO/IEC 42001 provides a certifiable AI management system standard that pairs cleanly with ISO 27001 if you already hold it. Certification is a real commitment; alignment without certification is a reasonable intermediate step and worth stating explicitly in your policy.

Cyber insurance applications have started asking about generative AI use, approved-tool lists, and human review of automated decisions. Answering those questions with a document rather than a paragraph of prose is materially better positioning at renewal.

The LA Wrinkles: Entertainment Law and Professional Services

Southern California businesses carry contractual obligations that outrank any internal policy, and the AI policy has to acknowledge them explicitly.

Protective orders and confidentiality stipulations. A protective order that limits disclosure of designated material to specified persons is not satisfied by a vendor DPA. If material is subject to an order, the safe default is that it does not enter any AI system that isn’t explicitly covered by your matter-level analysis.

Studio and production vendor security addenda. Content security requirements common in the entertainment supply chain generally prohibit uploading pre-release assets, scripts, and schedules to unapproved third-party services. Your approved-tool register needs a column noting whether a tool is cleared for production-sensitive material — for most firms the honest answer for most tools is no.

Outside counsel guidelines. Corporate clients increasingly include AI provisions in OCGs: disclosure requirements, prohibitions on training, sometimes advance written consent. These vary by client, which means your intake process needs to capture the AI terms per client, not per firm.

Privilege. Entering privileged material into a service whose terms permit human review for abuse monitoring is a waiver risk worth an actual analysis rather than an assumption. Enterprise agreements typically address this; consumer tiers typically do not.

Multilingual workforces. Across LA’s professional-services and production sectors, policy documents that exist only in English get ignored by part of the staff. Translate the one-page summary.

A Rollout Sequence That Doesn’t Stall

The failure mode is a beautiful policy nobody reads. This sequence avoids it:

Start with discovery, not drafting. Pull sign-in and network logs and find out which AI services your people are actually using. You will find tools you’ve never heard of. That list — not a template — is your policy’s real scope.

Give people a sanctioned tool before you take anything away. Enforcement before provisioning guarantees circumvention. Provision enterprise accounts, then restrict.

Write the data classification page first. Everything else in the policy hangs off it, and it’s the part staff will actually consult.

Turn on DLP in audit mode before enforcement mode. Watch what trips. You will discover legitimate workflows you would have broken, and you’ll fix them before anyone escalates to leadership.

Train by role, briefly. Attorneys, finance, HR, and production staff face different risks. Short, role-specific sessions beat an all-hands deck.

Stand up the ADS inventory in parallel. It’s owned by HR and operations more than IT, so it needs its own track or it never happens.

Schedule the review before you publish. A policy without a next review date is stale within two quarters, given how fast tool capabilities change.

How to Tell If It’s Working — And Where to Get Help

Good signals: your exception log has entries, meaning people are using the process rather than routing around it. DLP incidents trend down after an initial spike. New AI tool sign-ins from corporate identities are rare and investigated. You can answer a client security questionnaire’s AI section from existing documents without a fire drill. Your ADS inventory has a named owner per system.

Bad signals: zero exceptions logged, zero DLP hits, and enthusiastic self-reported compliance. That combination almost always means the activity moved to personal devices where you can’t see it.

The underlying point is that AI governance is not a legal deliverable that IT implements afterward. It’s an identity, data-classification, and logging problem wearing a compliance hat — which is exactly the work a managed IT function already does, applied to a new class of tool.

We Solve Problems runs both sides of this for our clients: the managed IT layer that enforces AI policy through identity, Microsoft 365, DLP, and audit logging, and the AI operations layer that finds the manual workflows worth automating and builds them inside those guardrails. We’re based in Los Angeles with particular depth in entertainment law and professional services, and we work with clients across the U.S. If you need an AI policy that survives a client questionnaire — and the controls that make it true — request a consultation.