How An Enterprise AI Platform Can Help Protect An Institution’s IP
Husein Sharaf leads Cloudforce, a Frontier AI Firm based in the DC-metro, recently named Microsoft’s global Education Partner of the Year.
gettyNearly every institution I talk to describes its AI governance posture in roughly the same way: “It’s a work in progress.” I used to accept that answer. Then I started asking a different question in those meetings: Where did your staff’s prompts go this morning?
I have yet to get a complete answer.
That is the immediate problem. An institution without approved, enterprise-wide AI access remains exposed while its evaluation continues. Employees are already using public tools to draft grant proposals, summarize constituent correspondence, review procurement language and sharpen negotiation memos. Much of that activity sits outside the institution’s contracts, identity controls and audit logs.
The available research points in the same direction. A 2025 Mindgard survey of more than 500 cybersecurity professionals found that 56% knew employees were using AI without approval, while another 22% suspected it. Only 32% said their organizations actively monitored AI usage.
Leadership may still be evaluating, but the workforce has moved on.
Employees rarely wait for procurement to finish a review before asking a chatbot for help. They use whatever is already open in a browser, especially when a deadline is close and the approved options are unclear.
The contractual terms matter here. Public and consumer AI services can give providers broad rights to use prompts or outputs, depending on the product, account type and settings. Enterprise agreements commonly provide stronger confidentiality and data-use protections. An employee using a personal account may, therefore, place institutional information under terms that leadership never reviewed.
That outcome comes from ordinary work. Someone needed help, found a useful tool and clicked through.
People usually turn to AI for the work that requires the most thought. That may include a curriculum refined over several years, research data ahead of publication, an emergency response protocol or a budget strategy under review. These materials carry real institutional value, and they are exactly the materials employees are most tempted to paste into a prompt.
This is usually a governance failure, not malicious behavior. A financial aid officer tries to meet a deadline. A county program manager cleans up a report. A department chair prepares for a board meeting. A city procurement lead reviews a difficult response.
They are doing their jobs with the tools available to them. Leadership decides which tools are available.
Blocking public AI sites on the institutional network can reduce visible usage from managed devices. It leaves several obvious paths open, including personal smartphones (which all have very capable cameras and AI apps that are happy to snap photos and video of protected content in a manner that is entirely undetectable by any security software that exists today), home computers, browser extensions and accounts accessed outside the institution’s network.
The result is less visibility. Usage shifts into places where security teams have fewer logs and fewer practical controls. A ban can still have a role for specific high-risk services, though it works best when employees already have a useful, approved option.
The practical response leaders should embrace involves broad access to approved AI services inside an environment covered by enterprise terms. Institutions should be able to manage identity, review usage, set data controls and document how providers handle prompts and retained data.
A PDF policy can help establish expectations. It cannot provide the tool employees need at 4:45 p.m., when a council briefing, grant submission or board packet is due.
There is a simple test leaders can run this week. Ask the CIO or CISO for the AI services employees use most, then request four things for each service:
2. The provisions covering training, retention and deletion of institutional data
3. The identity and access controls applied to employee accounts
4. The usage records available to security, legal or compliance teams
Any missing information identifies a specific governance gap. It can also give leadership a practical sequence for fixing it.
The same exercise should cover the platform layer. Models will change as capabilities, pricing and institutional needs change. A governed environment can give employees access to the right model while preserving consistent controls around identity, data and oversight.
Boards often hear that leadership is proceeding carefully and continuing its evaluation. That can be accurate while sensitive information is already moving through unmanaged tools.
A 2025 Metomic survey of more than 400 security leaders found that 68% of organizations had experienced data leakage tied to employees sharing sensitive information with AI tools. Only 23% had implemented comprehensive AI security policies. These figures deal with broad enterprise data, but I’ve found the operating problem is familiar across every industry vertical.
Institutions should make a reasonable platform decision, establish contractual protections, provide access and improve the controls over time. Waiting for a perfect answer leaves employees to make hundreds of small, undocumented platform decisions on their own.
Leadership should be able to answer a basic question today: Which AI tools are our people using, where is institutional data going and where does the value of our intellectual property accrue in the long term?
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


