Resources
Reference material I keep coming back to, along with notes on what each source actually covers and where it stops being reliable.
AI Data Governance
Where to check AI vendor data protection. Each of these pages is the vendor's own and is kept current, but each one documents the enterprise or commercial tier. Find the page for the exact tier your organization actually bought, because that is the version that governs you.
OpenAI
Trust portal and enterprise privacy page. Covers the API and ChatGPT Business, Enterprise, Edu, and Team. The free and Plus consumer tiers differ.
trust.openai.com ↗ openai.com/enterprise-privacy ↗Anthropic
Privacy Center and Trust Center. Enterprise and API tiers are not trained on by default. The consumer Free, Pro, and Max plans require opting out, and the Team plan runs under the consumer terms.
privacy.claude.com ↗Microsoft
Enterprise data protection for Microsoft Copilot. Under enterprise data protection, prompts and responses are not used to train the foundation models. The consumer Copilot is a different product, and the main risk is permissions and oversharing rather than training.
learn.microsoft.com ↗Data governance and generative AI on Vertex AI. Vertex AI does not use customer data to train foundation models by default. Consumer Gemini differs.
docs.cloud.google.com ↗Generic documents you can adapt for your own organization. They are starting points rather than legal advice, and they need to be checked against the tools and contracts you actually have.
Sample Generative AI Policy
A sample policy in editable Word format, meant to be rewritten for your own organization.
Download DOCX ↓Sample AI Access Decision Guide
A sample decision guide in editable Word format, meant to be rewritten for your own organization.
Download DOCX ↓