Most companies think their AI risk is a policy problem. It’s a guessing problem.

Before every session we run at Train in Your Lane, we ask one scenario question. Someone sends you a spreadsheet with a full customer list and asks for a summary. Do you put it into AI?

At a franchisor’s home office, 42 people answered. Twenty-eight of them either said they wouldn’t touch AI for that at all, or said some version of “I honestly don’t know what’s safe here.” That’s two out of three. Coaches, accountants, IT, marketing. People who handle customer data all day.

Nobody was being careless. They were being uncertain, and uncertain people do one of two things. They freeze and stop using a tool the company is paying for, or they paste and hope.

Both cost money. Only one shows up in a headline.

Why the people who use AI most are not the people who know the rules best

You’d assume the power users have this figured out. They don’t.

We ran the same question with a marketing agency network. 22 executives, 19 of them in AI several times a day. Safety clarity was low there too. Heavy use taught them what the tool could do. It didn’t teach them what the company allowed, because the company hadn’t said.

That’s the pattern everywhere. Comfort with the tool and clarity on the rules are two separate things, and most training only builds the first one.

What “safe” actually means, in plain English

Three questions cover most of it.

Is this data ours, or is it someone’s? A customer’s name, a franchisee’s P&L, an employee’s home address — that’s someone’s. Your internal meeting notes are yours. Most people have never been asked to sort the difference out loud.

Where is this tool sending it? A free consumer chatbot, a paid business account with data controls, and the AI feature inside your existing software are three different places with three different agreements. Most employees can’t tell you which one they’re in. Some can’t tell you there’s a difference.

Can I do the same job with less? This is the one nobody teaches. You almost never need the whole spreadsheet. You need the structure, or five anonymized rows, or the totals with the names stripped out.

That third question is the whole training.

The exercise that fixes it in an hour

We put a real, messy document in front of the room. A customer list. An intake form. Something with names, emails, dollar amounts.

Then we make them clean it before they’re allowed to use it. Strip the identifiers. Replace names with roles. Keep the shape of the data, lose the identity of the data. Then run the task.

Two things happen. People discover the tool works just as well on the anonymized version, which kills the “but I need the real data” objection. And they discover that cleaning it takes about ninety seconds, which kills the “I don’t have time” objection.

Then we write the rules together, in the room, on the wall. What’s fine. What’s never. What you ask about. Usually it’s under ten lines. Under ten lines is a policy people follow. Forty pages is a policy people sign.

Does it hold?

We asked the agency group a week later. Same safety question, one to five scale.

Sixteen of sixteen said four or five.

One four-hour session, and one of those hours was this. A week before, most of them couldn’t have answered the customer-list question without guessing.

That’s the return on four hours — and it starts, every time, with people understanding what the tool actually is before they’re handed rules about it.

What to do before you book anything

Ask your team the customer-list question. Don’t announce it, don’t put it in a policy email. Just ask ten people, in person, what they’d do.

If you get ten different answers, you don’t have a compliance problem yet.

You have one on the calendar.

Or skip the guessing and let us run the readiness check for you.

book a discovery call — free · 30 minutes

By Published On: September 3, 2026Categories: Company News