People already use AI at work. Blocking everything pushes activity into personal accounts and private chats. Forcing a heavy committee process has the same effect. Small teams need governance that is light enough to follow and strict enough where it matters: what tools are allowed, what data can enter them, when a human must review an outbound action, and what gets logged.
Publish an approved shortlist
Name the tools people may use for work. Include what each is for, where data is processed, and who owns the account. Update the list when something better arrives. Ambiguity is what creates shadow use.
If a tool is not on the list, the path should be a short request—not a months-long procurement theater. Speed of approval is part of security.
Classify the data, not the job title
Two classes cover most small-team reality: public or already-external material, and anything customer, employee, financial, or otherwise restricted. Restricted data stays out of consumer tools unless you have a contract, retention rules, and a named owner.
Write examples. “Paste a redacted FAQ draft” is clearer than “do not upload sensitive information.”
Review actions that leave the building
Drafts, summaries, and internal suggestions can move quickly. Sending email, changing records, posting publicly, or calling a write API should require a person to confirm. Separate preparation from execution.
That single rule prevents most of the expensive failure modes without slowing everyday drafting.
Log enough to learn
Keep a simple record: who used which tool, for which workflow, and whether an external action was taken. You do not need a full SIEM on day one. You do need a way to investigate a bad output or a leaked prompt.
NIST’s AI Risk Management Framework frames this as mapping context, measuring risk, and managing it with proportionate controls—not with ceremony.