Certified Blog

Your Guide to AI Risk Tolerance and Acceptable Use Policy

Did your account manager mention “AI posture” on your last call? Did you nod along even though you weren’t quite sure what they were talking about? Let’s fix that. Conversations like these are becoming more common in the everyday workplace as AI tools and their usage continue to rise. With that, there comes a certain responsibility to understand the nature of acceptable AI usage in the workplace, so that you can do your work safely and within your company’s policy.

What Is Your Company’s AI Posture?

AI posture is the combination of how much risk your business is willing to carry around AI use and the rules you’ve put in place to manage that risk.

AI Posture Combines Risk Tolerance and Policy

Break that down further, and you get two ideas. The first is risk tolerance. Put simply, it’s how much operational failure or error you are willing to accept before enforcing a stricter rule. The National Institute of Standards and Technology, the federal agency behind the leading framework for managing AI risk, defines it almost the same way: as an organization’s readiness to bear risk, shaped by its own priorities and resources rather than some universal standard everyone has to hit. A law firm and a landscaping company can land in very different places on that scale, and both can be right for their own business.

The second idea is the acceptable use policy — the document that spells out which AI tools your team can use, what they can and can’t feed into those tools, and who signs off when something falls outside the lines. NIST’s own generative AI guidance calls for exactly this kind of policy as a baseline piece of managing the risk that generative AI introduces, right alongside bigger, more technical controls.

Why This Conversation Is Happening Now

Timing matters here, and the numbers explain why your account manager raised this now instead of waiting. SHRM’s 2026 workplace survey of nearly 6,000 U.S. workers found 41% already use AI for work tasks, whether or not their employer has any policy on it. Generative AI use among small businesses jumped from 23% to 58% in just two years, according to the U.S. Chamber of Commerce’s latest small business technology report, which covers companies with fewer than 250 employees, not just the big names making headlines. Put those two numbers together, and the picture gets clear fast. Your employees are probably already using AI tools, with or without your blessing, and the businesses around you are adopting AI faster than almost any technology before it.

Only 31% of small businesses feel ready to comply with the AI disclosure and oversight rules already taking shape, per that same Chamber research. If part of your exposure runs through the EU’s AI Act specifically, we’ve broken down what that compliance actually requires in more detail elsewhere.

That gap between use and governance is the actual risk, not AI itself. A team quietly pasting client details into a free chatbot today creates exposure today, whether or not anyone’s written a policy yet.

How Do You Find Your Own AI Risk Tolerance?

Your AI risk tolerance comes down to three questions:

  1. What’s actually at stake if something goes wrong
  2. How much oversight you can realistically keep up with
  3. What your clients, regulators, or insurers expect from you.

A Quick Self-Assessment for Your Business

Answer these four honestly, and you’ll have a real sense of where your business sits.

  • A client relationship, a fine, or real money — would a mistake from AI put any of those at risk in your business? If yes, lean cautious.
  • Checking AI output before it goes out the door takes time. Does someone on your team actually have that time, every time?
  • Sensitive information — client financials, health details, anything under an NDA — ending up in a prompt should push your tolerance toward stricter, not looser.
  • If regulators or insurers in your industry care about how decisions get made, plan to document every AI-assisted call. “We trusted the AI” won’t hold up in a review.

What Your Answers Tell You

Most businesses land in one of three places.

Two or more “yes” answers usually means cautious territory — fewer approved tools, more required review, tighter limits on what data goes anywhere near an AI tool. A mix of yes and no points toward balanced territory, where general use is fine but specific situations need a second set of eyes. All “no” answers point toward a more permissive setup, though even permissive businesses still need a written policy, not just an unspoken understanding.

Size isn’t actually what drives this. A five-person shop handling Social Security numbers can land more cautious than a fifty-person company that never touches sensitive data, and that surprises a lot of owners who assume “small” automatically means “low-risk.”

Skipping this step is exactly how a lot of companies end up with a policy that doesn’t fit. SHRM’s research on HR professionals found that among organizations that already have an AI policy, only about a quarter consider it clear and built to last. More than half called their own policy too narrow, tied to tools that are already changing, and almost a quarter called theirs too broad to actually guide anyone. Knowing your own tolerance first is what keeps you out of either ditch.

What Should an AI Acceptable Use Policy Include?

A solid AI acceptable use policy spells out which tools your team can use, what data can and can’t go into them, who reviews higher-risk uses, and what happens if someone ignores the rules.

The Core Elements Every Policy Needs

Every policy worth having covers the same four bases, no matter how cautious or permissive your tolerance turns out to be.

  • Approved tools, named specifically. A vague nod to “AI” in general doesn’t tell anyone what they’re allowed to open, so people open whatever’s free and convenient instead.
  • Spell out what can never go into a prompt: Client financials, health information, anything covered by an NDA or a state privacy law, named plainly enough that nobody has to guess.
  • Naming a real person to sign off on higher-risk uses keeps review from being theoretical. A policy that says “use good judgment” isn’t a review process.
  • If nobody enforces it, it’s a suggestion, not a policy. So, state the consequences for ignoring the rules in plain language, the same way you would for any other workplace rule that actually matters.

NIST’s generative AI guidance treats a policy like this as a baseline control, not an advanced one. That alone tells you it stopped being optional the moment your team got real access to AI tools. We’ve gone deeper on the people side of this in a separate piece on managing AI ethics and usage policies, including how to train a team on rules like these instead of just publishing them.

Matching the Policy to Your Own Tolerance

Cautious, balanced, or permissive. Your tolerance from the self-assessment earlier sets how tight each of those four elements gets. A cautious business might require sign-off on every AI-assisted client communication and limit tool access to one or two approved platforms, while a permissive one might only require that sign-off for anything touching money or legal exposure, leaving everyday tasks like drafting internal emails wide open. Either approach is defensible on its own terms. Guessing at the strictness level instead of basing it on your actual tolerance is the part that gets businesses in trouble.

This is exactly the kind of mapping our ITSO team works through with clients every week, matching the policy to the business instead of handing over a generic template and calling it done.

If your business already works with us on managed compliance services, this conversation is probably an extension of work that’s already underway, not a brand-new project.

Putting Your AI Posture Into Practice

AI posture is just risk tolerance and policy working together, and now you’ve got a real answer for both. The self-assessment gave you an honest read on where your tolerance actually sits, and the four core elements give that tolerance a real shape instead of a generic policy borrowed from somewhere else.

Trouble usually doesn’t come from the businesses using AI. It comes from the ones who never stopped to figure out where they stand before their team started using it anyway.

Already a Certified CIO client? Ask your account manager for our AI acceptable use policy template — basically a fill-in-the-blank version of everything you just figured out above.

Not working with us yet? Request the template through our client portal, and we’ll get it to you.

Either way, if you’d rather talk through your specific AI posture with a real person first, reach out to our team and we’ll work through it together.