Take Control of AI in Your Organization
February 6, 2026 | By Joseph Contreras and Nathan Harounian
Share This:

Artificial intelligence (AI) is rapidly changing the way work gets done across nearly every industry and business sector.
Simply put, AI refers to computer systems capable of performing tasks that typically require human input. Varied in their level of autonomy, these engineered or machine-based systems can, for explicit or implicit objectives, infer from the input they receive how to generate outputs that can influence physical or virtual environments.
Many small businesses and nonprofits are using AI tools to boost efficiency by taking notes in meetings, summarizing reports, drafting communication, analyzing data trends, and providing customer service through chatbots.
As organizations navigate this new world, it’s important to consider the tradeoffs posed by AI. Here are some things to consider:
Balance AI Benefits with Potential Risks
With AI advancing rapidly, this innovation comes with risks, including:
- Data security: Most AI tools rely on cloud-based storage, meaning data entered into an AI tool is sent to and processed on remote servers maintained by a third party rather than stored locally on your own devices. This cloud-based model can help make AI tools easy to use, but it also raises important questions about where the data lives, how long it stays there, and who has access to it. These concerns can also extend to whether an AI tool is using your information to train itself or other AI models.
- Accuracy: Summarization or translation tools can misinterpret context or produce inaccurate outputs. It’s important that humans review any AI outputs before sharing them.
- Ethical concerns: AI systems can demonstrate bias due to training data or model design that can affect the outputs.
Evaluate Your AI Liabilities
Take these steps to better understand how AI may impact your current systems and processes:
- Thoroughly review all contracts and policies to determine where you may have existing or potential conflicts. Where is AI use already restricted? Where is new guidance needed?
- Review the terms and conditions of your software to make sure privacy settings are properly configured. Many software versions are now incorporating AI features and functions.
- Determine how you will protect confidentiality and follow privacy laws and rules, such as HIPAA for health information privacy. Many health care organizations have strict requirements surrounding personally identifiable information (PII) and personal health information (PHI) from clients that also must be factored into the decision to use AI. PII refers to data that can uniquely identify an individual, such as names or social security numbers, while PHI includes health-related information that is protected under HIPAA.
Set Boundaries for Your Data
Once you understand how your systems are interacting with AI on a macro level, you can drill down to determine what organizational data should interact with AI day to day. Consider these questions:
- What types of information can AI always access (e.g., public-facing materials such as press releases)?
- What types of information can AI access on a case-by-case basis (e.g., meeting notes and project files)?
- What types of information should AI never access (e.g., PHI and PII)?
Be Selective with AI Software
New AI tools are popping up all the time, especially software for specific tasks like data analysis and graphic design. Consider these questions to select AI software for your organization:
- What tasks do you want to automate with AI?
- Which tool best supports those tasks?
- What are the limitations of the tool?
- What does the AI tool do with your inputs? Is it storing your data? Is it using your data to reinforce itself?
- Are there steps you can take to anonymize your data and increase privacy? For example, can you identify primary or secondary keys within your data that you can randomize or redact before inputting your data into AI software?
Develop an AI Policy
After these initial considerations, the next step would be to develop a policy for AI in your organization. Your policy should define what AI means for your organization and detail permissible and non-permissible internal and external uses of AI.
Make sure your internal policies account for a security breach or data leak, and emphasize the accountability associated with using AI in the workplace.
Answer these questions within your AI policy:
- What does your firm define as AI?
- Which types of AI usage are permissible all the time? Which types are conditionally permissible? Which types should folks avoid completely?
- What role do your clients or partners play in your AI usage policy?
- What is the protocol for AI-associated incidents? Who needs to be informed and who addresses the issue?
Due to the rapid evolution of AI, make your policy a living document and revisit it every couple of months.
Do you want an AI thought partner as you navigate these topics in your organization? Transform Health is here to help. Book a free discovery call today.
Transform Health is an Inc. 5000-ranked national private health care consulting firm with a mission to drive systems change to build healthy communities.