Most San Francisco businesses aren’t debating whether to adopt AI anymore. The question is how to do it without creating data exposure, compliance risk, or security gaps that are harder to close once employees are already in the habit of working around them. This blog covers the practical governance steps that make AI adoption both useful and safe, covering data rules, access controls, policy, and how IT and leadership need to work together.
Why AI Governance in San Francisco Matters Now
Speed is the problem. Teams move fast with new tools, and without guidance, employees often reach for whatever AI application is easiest, such as a free ChatGPT account, a browser extension, or a third-party app not on anyone’s approved list. The consequences are measurable: according to LayerX Security’s Enterprise AI and SaaS Data Security Report 2025, around 18% of enterprise employees regularly paste data into generative AI tools, and more than half of those paste events include corporate information. Generative AI has become the leading channel for unauthorized data movement, accounting for 32% of all corporate-to-personal data exfiltration.
This is happening right now, and most IT teams have limited visibility into it. Businesses in legal, financial services, and other regulated sectors face additional exposure. A single confidential document pasted into a public AI tool can create a compliance event, not an IT inconvenience.
What Data Should and Shouldn’t Go into AI Tools
Before employees use AI tools for anything substantive, businesses need clear written guidance on data classification. That means defining what categories of information cannot be entered into external AI systems, such as client records, financial data, contracts, employee information, strategic plans, and any data covered by your compliance obligations.
Most employees do not know what the boundaries are. Research from NCSA’s 2024-2025 Cybersecurity Attitudes and Behaviors Report found that only 48% of employees had received any AI security training at all. Policy solves this problem. A data classification policy can help an employee make a quick decision before pasting something into a prompt box.
Alongside policy, businesses should evaluate which AI tools are approved and what their data handling terms say. Free-tier products from major AI vendors often reserve the right to use submitted content for model training, a meaningful distinction when the submitted content includes client communications or internal financial data.
AI Security Means Applying the Same Controls You Use Elsewhere
AI tools are software, so they should be managed the same way as any other business application with proper account provisioning, role-based access, and multi-factor authentication. In practice, many businesses skip these steps because AI tools feel informal or experimental. That approach creates risk fast.
According to a 2025 survey covered by Kiteworks, 83% of organizations lack automated controls to prevent sensitive data from entering public AI tools, and 86% have no real visibility into their AI data flows. Without access controls, IT teams cannot monitor what is being submitted, cannot enforce policy, and cannot respond when something goes wrong.
The practical checklist for San Francisco businesses looks like any SaaS rollout: who gets access and at what level, whether business accounts are being used rather than personal ones, whether MFA is enforced, and whether logging or monitoring controls are in place. It’s standard IT hygiene, applied to a new category of tool.
AI Policy Should Help Teams Work, Not Block Them
A common concern is that putting governance around AI tools will slow people down or signal that leadership does not trust the team. The opposite framing is more accurate. A clear AI policy removes the guesswork employees face every day and replaces it with a consistent answer.
Good AI governance tells employees which tools are approved, what they can be used for, what data stays out, and what to do when they are unsure. Employees work with more confidence when boundaries are defined. The business also benefits from AI in a sustained way, rather than lurching between encouraging adoption and imposing restrictions after something goes wrong.
Access with appropriate controls is what separates businesses using AI productively from those either avoiding it entirely or accumulating exposure they cannot see.
Connecting AI Strategy, IT Support, and Cybersecurity
Most businesses assume AI governance has to live either inside IT or inside leadership. In practice, it needs both. IT needs to understand what tools employees want to use and what the security implications are. Leadership needs to communicate expectations and own the policy decisions. Without that coordination, you get gaps like tools in use that IT does not know about, policies that nobody enforces, and risks that nobody is accountable for.
Centarus helps San Francisco businesses connect AI strategy, IT support, and cybersecurity so that adoption decisions are made with the right information. That means building policies that reflect how teams work, applying security controls that account for AI-specific data flows, and giving leadership a clear view of where risk exists before it becomes a problem.
Build a Safer Path to AI Adoption
If your business is exploring AI, Centarus can help you put the right governance, security, and IT foundations in place before risk becomes a problem. Book a session with Dale to talk through where to start.



