INTELIGÊNCIA ANALÓGICABlogSign in

AI Governance Protocol

Phase 1, open · 25 Aug 2026

Sources checked on 25 Aug 2026 · next check: 24 Sep 2026

Implementation Guide — AI governance over a weekend

Start here. This is the thread that ties the documents of the AI Governance Protocol into a sequence you run yourself, without depending on anyone to get started. The templates are the parts; this guide is the assembly order. By the end, your company moves from zero governance to the floor: a written rule, classified data, a team informed on the record, a limit actually running, and a booked review.

What you get out of it: the team starts using AI knowing what it may do — those held back by fear get moving, and those already using it start doing it properly. Protection is the consequence; use is the reason.

Who it is for: the owner or manager of a small or mid-sized company (or the IT person advising them).

⚠️ This is not legal advice. This guide installs a method; the parts touching monitoring, disciplinary measures and personal data need a lawyer's review before they apply in your company. The guide points to where — it does not replace the review.

Time: a weekend to get everything ready — plus a few days for the team to sign the acknowledgment, which depends on people replying rather than on you.

Track it with the implementation checklist — this guide explains why and how; the checklist marks what is done.


Before you start — the idea in one sentence

AI governance is not magic software, nor a legal doorstop. It is four simple things in the right place: a rule (what is allowed), a classification (with which data), an agreement with the team (on the record) and a limit (a technical barrier). This guide installs all four. The principle underneath: the human in command — AI suggests, the person decides and answers for it.

One honest thing, worth saying up front: no control closes 100%. There will always be the personal phone, mobile data, and the creativity of whoever wants to get around it. The guarantee is in layers, and the last one is human — the policy and the culture. The goal here is not perfect protection; it is getting out of the dark and making the risk governable.


Step 1 — Write your policy (Saturday morning)

Why: without a written rule, everyone invents their own — and "what is allowed" becomes a matter of opinion. The policy turns opinion into an agreement.

How:

  1. Open the AI usage policy template.
  2. Fill in your business's confidential terms — the names that hurt if they get out: {{revenue, margin, the new project, the largest client}}. This is the step that makes the policy yours. A generic policy protects nothing in particular.
  3. Define the company's approved AI tool (the one you recommend people use for work).

Common mistake: copying the policy and not filling in the secrets. You end up with a good-looking document that protects nothing that matters.

✅ Done when: a written policy exists, with your secrets listed by name.


Step 2 — Classify your data (Saturday afternoon)

Why: the policy says "do not leak confidential data" — but the team only complies if it knows what is confidential. The classification is the ruler the policy applies.

How:

  1. Open the data and profile matrix.
  2. Part A — data: fill in real examples for each level (public, internal, confidential, restricted/personal data). Rule of thumb: when in doubt, go up one level. Erring upwards costs little; downwards is a leak.
  3. Part B — profiles: for each department, define whether it may use AI, which tool, and the highest data level it may paste. Whoever is not in the matrix does not use it until they are added — default deny.

Common mistake: trying to classify everything. Start with the confidential and personal data — those are what matter. The rest is handled by the rule of thumb.

✅ Done when: anyone can look at a piece of data and say whether it may go into an AI.


Step 3 — Announce it and collect the acknowledgment (Sunday morning)

Why: a policy nobody read governs nothing — and without a record that it was communicated, there is no backing for monitoring (that is the legal basis: legitimate interest, not covert surveillance).

How:

  1. Send the team announcement. Tone of care, not of enforcement — "we want you to use it, safely". If it reads as a threat, the team hides its usage and shadow AI gets worse.
  2. Collect the acknowledgment from each person.
  3. Open a channel for questions — the "come talk to me" in the announcement needs somewhere to go.

Common mistake: publishing the policy on a shared drive and calling it communicated. Communicating means actively telling people and recording that you did.

✅ Done when: everyone has been told, and there is a record (the acknowledgment) that the policy was communicated.


Step 4 — Switch on the minimum limit (Sunday afternoon)

Why: a rule without a barrier depends on goodwill alone. A technical limit — even a simple one — moves leaking from "trusting nobody will" to "they cannot".

How: pick the level that is possible today (not the ideal — the possible). Details in the containment playbook:

  • Minimum (any company): point people to the approved tool and block what you can of personal accounts. It leans on the policy — but it is a start.
  • Intermediate (with a firewall): block the "AI" category at the firewall and allow only the approved corporate tool.
  • Advanced (with IT): put up a gateway — a door that applies the profile matrix and stops confidential data before it leaves. Needs a technical team.

Remember: no level closes 100%. The missing layer is always the policy plus the culture (steps 1 and 3). That is why they come first.

✅ Done when: there is at least one barrier between confidential data and an ungoverned AI.

If you have nobody to do this, this is the step that usually needs help — and there is no harm in stopping here. Steps 1 to 3 stand on their own: the rule exists, the data is classified, and the team has been informed on the record. The technical limit is the part that depends most on the infrastructure the company already has, and needing someone from IT for the intermediate level onwards is normal.


Step 5 — Book the review (15 minutes, Sunday evening)

Why: the threat changes every week — a new tool, a new leak, a new rule from the regulator. Governance that is never reviewed ages and becomes theatre.

How:

  1. Put the review in the calendar every [cadence] (or whenever a new tool shows up). Use the same value in the policy and in the matrix.
  2. Name who re-reads the policy, the matrix and the containment. A review without an owner does not happen.

✅ Done when: the review has a date and an owner — not "when there is time".


Weekend over — what you have now

Not perfect governance. It is the floor — and the floor already changes everything: you moved from "I have no idea what my company asks of AI" to "we have a rule, we know which data we protect, the team has been informed on the record, there is a limit running, and a review is booked". Most companies are still in the first state.

Where to go from here, when it makes sense for your size:

  • Raise the technical limit one level. If you stopped at the minimum today, the containment playbook shows the next one — and it almost always uses tooling the company already pays for.
  • Widen the matrix. Start with the departments left out and the data you postponed.
  • Keep the review you booked. It is the step most people skip, and the only one that stops all of this from becoming old paper in six months.

Governing is not a project that ends. It is a routine that starts — and you have just started it.

Data Classification & Access Profiles — [your company]

Editable model. Phase 2 artifact of The Analog Method. This is the ruler the AI Usage Policy applies: what each piece of data is worth, and who may use what.

Status: model v0.1 — not legal advice. Personal-data categories follow the regime in your jurisdiction annex. Effective: [date] · Owner: [owner].


Part A — Data classification (what may enter an AI)

Before deciding who uses AI, decide what may go into it. Four levels. Fill the examples with the client's real operational data, in their own words.

Level What it is Examples at [your company] May it go into AI?
Public already public, no risk marketing material, website, catalog ✅ Yes, any approved tool
Internal day-to-day, not sensitive drafts, general text, questions ✅ Yes, approved tool
Confidential (business) commercial or operational secret {{e.g. revenue, margins, Project X, key contract}} ⚠️ Only in the governed corporate tool; never a personal or consumer account
Restricted (personal data) personal data of clients or staff {{e.g. national ID, health data, payroll}} 🚫 No, unless there is a lawful basis and a tool that guarantees the processing

Rule of thumb: when torn between two levels, use the higher one. Erring upward costs little; erring downward is a breach.

Part B — Access profiles (who uses what)

Not every department deserves the same latitude. For each profile define: whether they may use AI, which approved tool, and the maximum data level they may paste. This is what a gateway enforces technically — here, on paper, it is the agreement.

Profile / department May use AI? Approved tool Max data level Notes
{{Leadership}} {{tool}} Confidential
{{Sales}} {{tool}} Internal no contracts or agreed pricing
{{Finance}} {{corporate tool}} Confidential never client personal data without a lawful basis
{{Operations}} {{tool}} Internal
{{Interns / contractors}} ⚠️ limited {{tool}} Public supervised only
{{Default — not listed}} 🚫 denied by default default deny: whoever is not in this matrix does not use AI on company data until added

⚠️ Until a governed corporate tool exists (step 4 of the guide), the ceiling for everyone is Internal — including the board. This is not excessive caution: without the technical limit, "Confidential allowed" means confidential data going into an account you do not control. Raise the ceiling after the barrier is up, not before.

Principle: default deny. A profile nobody thought about does not get access by accident. It is safer to open up gradually than to discover the hole afterwards.

How to maintain it

  • Review every {{6}} months, or whenever a new tool or department appears.
  • Every exception request ("can I use X?") becomes a new row here. The matrix is alive, not a decree.
  • This matrix feeds both the policy (the may/may-not) and, where one exists, the configuration of the governed gateway (profiles + data levels). Same agreement, two places.

Fill-in notes (internal — not part of the published version)

The hard part is Part A, not Part B. Owners can name departments instantly and freeze at "what counts as confidential." Unblock them with the question that works: "if a competitor read this tomorrow, would it cost you money?" — that is the Confidential line. "If a client saw their own data in a stranger's hands, would they leave?" — that is Restricted.

Do not try to classify everything. Start with confidential and personal data; those are the ones that matter. The rest resolves itself with the rule of thumb, and a matrix that tries to be exhaustive never gets finished.

You have the map and the ruler. Four steps remain.

With the guide read and the matrix filled in, your team already knows what may go into an AI — and you have seen where the gap is. What does not exist yet is backing: the written rule naming your own secrets, the agreement signed, and a limit that actually stops things.

The remaining four steps — usage policy, team announcement, acknowledgment form, the technical containment, plus the checklist and the jurisdiction annex — are US$ 29, once.

See the full Protocol