Acceptable AI Use for Austin and Central Texas businesses
Written rules for the AI tools your team already uses and the tools you are about to add. Business information stays in approved systems.

Rules the team can follow before a tool goes live
Acceptable AI Use fits organizations that need a clear line between approved assistants, public sites, and tools that still need a decision. That includes clinics, manufacturers, professional firms, and other teams in Austin and Central Texas.
This is the rulebook. AI Readiness is the review of identity, sharing, devices, and data boundaries. Use both when the team is already pasting business information into public tools.
What the rules cover
The rules name what is allowed, what is not, and what still needs a review. Each data class has an owner, an approved tool, and someone who can answer questions.
Approved workplace assistants
Approved assistants are the tools the company has reviewed and can stand behind. Microsoft 365 Copilot on the company account is the usual example. Enterprise versions of other assistants can sit on that list after the same review.
Staff use those tools for drafting, summarizing, and finding files they can already open. The assistant inherits existing access, so approval follows a look at identity and sharing, not a license click alone.
A short pilot comes first. The tool goes to the people who should have it. The rest of the company waits until the rules and the access picture are clear.
Consumer and unsanctioned tools
Free ChatGPT-style sites, personal Copilot accounts, and unreviewed browser extensions are easy to try. Consumer terms often allow the vendor to keep or train on what is pasted in.
Those tools can be used with public information when the rule set allows it. They are not a place for patient information, HR, legal, client, or proprietary files.
A written exception names the tool, the data, and the owner when one is needed. Personal experiments on public sites stay personal.
Data classes
Public marketing copy can use a wider set of tools. Internal files stay in approved assistants. Patient information, HR, financial, legal, client, and proprietary work stay in the tightest class.
Each class has an owner, an approved tool, and someone who can grant an exception. That mapping is what a person follows when a new meeting assistant appears.
The list is reviewed when tools change, not once a year and forgotten. Staff should be able to find it without asking around.
Staff rules and vendor notes
Staff use the approved tool, share only what the work needs, and check the output before it goes to a client or a patient file. Mistakes are reported through the same support relationship the team already uses.
Vendors on the approved list have company accounts, written terms, and a named owner. BAAs are executed where the services we run require them.
The same relationship that runs helpdesk can answer “is this tool approved?” so the rule set is used, not filed.
How we apply them
The rules live with helpdesk and devices. Sharing defaults, mailbox settings, approved apps, and the staff guide all point to the same list.
Public sites stay out unless an exception is written. Copilot is added when identity and sharing can support it. EHR, line-of-business platforms, and legal obligations stay with their owners.
See AI Readiness when the environment still needs a look. See Microsoft 365 when the work sits in that system.
Related work
Start with a review
A review of your needs and growth plans looks at current AI use, data classes, and which tools should be approved. You leave with a draft rule set and a picture of how the relationship would run.
From there, your team has an ongoing support relationship, not a one-off project.
FAQ
Is this only for clinics?
Does this approve every AI tool?
What about public ChatGPT-style sites?
Do we still need AI Readiness?
Give the team rules they can follow.
Approved tools, named data classes, and a clear line for public AI sites.

