Skip to main content

AI readiness for Missouri businesses

Your people are using more AI than you think.

Client files pasted into unapproved AI tools leave the office, and you can't pull them back. Some of those tools are software you already pay for. Take the short check. You'll see where you stand in about a minute.

What is shadow AI, and is it happening at my company?

Shadow AI is staff using AI tools the company never approved. It's usually already happening. We do this work with businesses in St. Louis, Franklin County, and across Missouri.

When we pull the list of AI tools a company's staff are signed into, it's always longer than the owner expected.

Some of that is people on personal ChatGPT. Some of it is tools that were already on: Copilot in Microsoft 365, Gemini in Google, meeting notetakers that join and transcribe without anyone deciding they should. Nobody at your company chose to turn those on. Microsoft and Google did.

When someone pastes a client file, a password, or unpublished work into a public chat, that data leaves the office and you can't pull it back. The second risk is AI getting things wrong: an invented number in a quote, or a citation that doesn't exist in a client letter. Either one goes out with your name on it.

Banning the tools doesn't stick, because people already use them to get work done. You need a written rule, a short list of approved tools, and a way to see which ones people are signed into.

Every STR employee is CJIS certified and has passed a federal background check. That's the standard for handling criminal justice data, and we hold it whether a client needs it or not. If your contracts say where client data is allowed to live, or who is allowed to see it, an AI tool that quietly ships it somewhere else — that's a contract problem, not just an IT one.

Where does my company stand?

Seven questions. You get a score on this page in about a minute. There's no account to create.

Question 1 of 7

0 answered

Is there a written rule for AI at work?

What can STR do about it?

Here's what we handle for our clients:

We see which tools people use from the security tools already running on your machines. Nothing new gets installed on anyone's personal phone. We block what you don't want with web filtering and application control.

See which tools people use

We can see which AI tools people are signed into today, including ones nobody brought up in a meeting.

Write the rule

The sample policy below is yours to take. Putting your name on it, fitting it to your contracts, and getting it in front of your people is part of the monthly work.

Block the ones you don't want

We can stop unapproved tools in the browser and on company computers.

Give people approved tools

We help you put the business versions of Copilot, Claude, and ChatGPT in place, set up so the team can use them.

Automate real jobs

Once the rule and the files are in place, we can automate real work. That's project work.

Is our data ready for Microsoft Copilot?

Usually it isn't. Microsoft Copilot readiness starts with the files. Copilot can read every file a signed-in person can already open.

ChatGPT and Copilot inherit every permission your users already have. If a folder is shared with the whole company today, Copilot can find it and summarize it for anyone who asks.

Cleaning up file sharing and permissions comes before you turn Copilot on. How long that takes depends on the company. We do that cleanup with you, then set up the business versions of Copilot and ChatGPT.

Does my business need an AI acceptable use policy?

Yes. If anyone on the team uses ChatGPT, Copilot, or a meeting notetaker for work, you need one. An AI policy for small business can stay short: approved tools, what people may not paste, and who checks the output before it leaves the office.

Free AI acceptable use policy template

This sample is yours to adopt. Put your company name on it and give it to your people. Seeing which tools people use, and blocking the ones you don't want, is work we do with the companies we support.

Download the sample PDF

AI Acceptable Use Policy

Sample for public use. Replace [Company] with your name.

Purpose

This policy says how [Company] may use artificial intelligence so people can get work done without putting client data, company data, or the business at risk. AI may help with work. It does not replace a person's judgment, and it does not remove anyone's responsibility for the result.

Read the rest of the sample

Scope

This policy applies to every employee, contractor, and temporary worker, and to every AI tool used for company or client work. That includes chat tools, writing assistants, image tools, meeting summarizers, browser extensions, and anything similar that is added later.

Principles

1. Sensitive information stays out of tools that are not approved.

2. A person is accountable for every output that is used.

3. Only approved tools are used for company work.

4. If you are not sure, you ask before you paste.

1. Acceptable use

People may use approved AI tools to:

Draft, summarize, or edit content that is not confidential

Brainstorm ideas, outlines, and first drafts

Research public information

Analyze data that has been approved and stripped of anything sensitive

Speed up repetitive work, with a person still checking it

A person must review the output before it is used in client communication, an operational decision, or anything financial, legal, or safety-related.

2. Prohibited use

People may not:

Put client data, personal information, health information, payment data, passwords, or security details into an AI tool unless that tool has been approved for that use

Put pricing, contracts, unpublished work, or other company intellectual property into a public or personal AI tool

Let AI make a decision on its own about a client, money, hiring, safety, or compliance

Use AI to skip an approval, an audit step, or a security control

Use a public AI tool to train a model on company or client information

Use a personal AI account for company or client work

3. Data handling

Do not enter the following unless the tool is approved and the use is written down:

Client records or personally identifiable information

Health information

Financial or payment information

Passwords, keys, or how our systems are set up

Internal process, pricing, or unpublished work

You may use public information, anonymized data, and content that has been explicitly approved for AI.

Meeting recordings and transcripts count as company data. Do not drop them into a tool that stores or trains outside [Company].

Treat every AI answer as unverified until a person checks it.

4. Tool approval

Only tools that IT (or the owner, if there is no IT person) has approved may be used for company work.

Approval should look at how the vendor handles data, whether it trains on what you type, how long it keeps it, who can see it, and whether that fits the company's legal and contract duties.

Free consumer tools and browser add-ons are not approved by default. A new tool needs a yes before anyone uses it for work. Approved tools should be reviewed again when the vendor changes how data is used.

5. Accountability

AI output is a draft. The employee who uses it owns the accuracy and the outcome. Mistakes, odd results, or a suspected leak get reported to a manager the same day.

6. Training

People complete a short AI briefing before they use approved tools. It covers what they may do, what they may not paste, and the fact that AI can be wrong or biased. The briefing is updated when the tools change.

7. Enforcement and review

Use that does not follow this policy can mean loss of access to AI tools and other discipline, up to termination, depending on what happened.

[Company] will review this policy at least once a year, when the law changes, or when a new kind of AI tool is brought in. Changes are given to everyone this policy covers.

Questions go to [IT contact or owner].

How long does it take to get ready?

Most companies get through this in six months or less. We'll use this as a framework and adjust it to your company.

Write the rule, see the tools, and stop the unsafe ones.

  • Write the acceptable-use rule.
  • See which AI tools people are signed into.
  • Block the ones you don't want.
  • Give people a short staff briefing.
  • Decide what you're measuring so you can tell later what saved time.
  • Set up basic sign-in and logging: who can get in, and what gets recorded.
  • Write a short list of first jobs worth doing: search, drafts, summaries, and admin work. Pick work that's useful, where the data is safe enough, and where a person can check the result.

Clean up the files, then use approved tools for real work.

  • SharePoint permissions and tagging, so Copilot and ChatGPT only see what they should.
  • Approved tools only.
  • One or two of those first jobs go live, with a person checking the work.

Automate real work, and keep what saved time.

  • Find real business processes worth automating. That's project work.
  • Review the policy.
  • Keep the work that saved time, and drop the work that didn't.

Questions about AI readiness

What is shadow AI, and is it happening at my company?

Shadow AI is staff using AI tools the company never approved, including personal ChatGPT and features Microsoft or Google turned on. When we pull the list of tools a company's staff are signed into, it's always longer than the owner expected.

Does my business need an AI acceptable use policy?

Yes, if anyone uses ChatGPT, Copilot, or a meeting notetaker for work. An AI policy for small business names the approved tools, what people may not paste, and who checks the output before it goes to a client.

Is our data ready for Microsoft Copilot?

Usually it isn't, until SharePoint permissions are cleaned up. Microsoft Copilot readiness starts with the files: if a folder is shared with the whole company, Copilot can find it and summarize it for anyone who asks.

How long does it take to get ready?

Most companies get through this in six months or less. The plan is a framework we adjust to each company: write the rule, clean up the files, then automate real work.

Who do you help with this?

We do this work with businesses in St. Louis, Franklin County, and across Missouri.

What does the free AI readiness check include?

Seven questions and a score on this page, plus a free AI acceptable use policy template you can put your company name on. You don't need an account.

Want a deeper look?

Book a first conversation. We'll tell you if we're a fit.

Let's Talk