What a family office should ask before staff use AI

By Avihay Zanetti Published 2026-10-01 Updated 2026-10-01 AI Governance

Why does a small office need a written AI policy?

Because your people are probably using AI already, with or without your knowledge, and because the questions come from outside: a counterparty asks how you handle their documents, an insurer asks about controls, a family member asks who can see what. A one-page policy lets you answer in a minute. Without it, every answer is improvised.

You do not need to adopt a framework to write one, but public frameworks give you a vocabulary. The NIST AI Risk Management Framework 1.0 (January 26, 2023) is voluntary and organized around Govern, Map, Measure and Manage. NIST followed it with a Generative AI Profile, NIST-AI-600-1, on July 26, 2024, to help organizations identify risks specific to generative AI. ISO/IEC 42001, introduced in December 2023, is a certifiable standard for an AI management system. A small office does not need certification, but its themes (risk assessment, oversight of third-party tools, continuous improvement) overlap with the questions below.

If an SEC-registered adviser sits inside or beside your office, the SEC Division of Examinations' fiscal year 2026 examination priorities say it will review the accuracy of firms' statements about their AI capabilities and whether they have policies and procedures to monitor and supervise their use of AI. Many single family offices are not registered, so whether that applies to you is a question for counsel.

What are the ten questions to answer before staff use AI?

Write one or two sentences for each. If you cannot answer one, that is the first item on your list.

  1. Which data classes exist, and which may reach an AI tool? Sort your records into red, amber and green (table below). The rest of the policy hangs on this.
  2. Which tools and which plans are approved? Name the product and the plan tier. A tool on a free personal account is a different decision from the same tool on a business plan.
  3. What happens to what staff type? Find out from the provider's current terms how long inputs are kept, who can access them, and whether they may be used to train models. Record the date you checked.
  4. Who approves a new tool or a new use? One named person, a short request, a quick answer. Without this, staff approve for themselves.
  5. What do the vendor's terms and security documents say? Ask for the data processing terms and any security attestation, and have counsel review anything that touches red data.
  6. What do we owe clients, family members and counterparties? Check nondisclosure agreements, side letters, investor documents and engagement terms for limits on outside tools or on sharing information with third parties.
  7. What counts as an incident, and what happens next? Define it, for example red data entered into an unapproved tool. Say who is told, how fast, and who decides whether anyone outside is notified.
  8. How are staff trained? A short session at onboarding and a refresher each quarter beat a long document nobody opens.
  9. What do we log? Keep a list of approved tools, approval decisions, incidents and policy changes. Decide whether to keep prompts at all, since a log can itself hold sensitive data.
  10. When do we review? Quarterly is a sensible start while tools and terms change quickly. Put the date in the calendar and name the owner.

What do red, amber and green data look like in a family office?

Your counsel and your own obligations decide where the lines fall. Treat this as a starting point, and move an item up a level when in doubt.

LevelExamplesRule
GreenPublic filings, published articles and reports, your office's public biography, generic templates with no names, invented scenarios.Allowed in an approved tool. A person still checks the output.
AmberInternal drafts and agendas, general correspondence, summaries of deals with names removed, staff scheduling, internal process notes.Approved business-plan tools only, names removed where possible, retention settings checked, a person reviews every output.
RedAccount numbers, tax identification numbers, passwords and keys, privileged legal advice, family medical or children's details, identity and onboarding documents, deal materials under a nondisclosure agreement.Not entered into any AI tool unless a named person approves in writing and counsel has reviewed the tool's terms.

What does a one-page AI policy for a small office look like?

Copy this skeleton, fill the brackets, and cut anything that does not apply. It is a starting draft for you and your counsel, not a finished legal document.

AI use policy for [Office name]
Owner: [name]. Version date: [date]. Next review: [date].

  1. Purpose. This page says how our people may use AI tools while keeping family, client and counterparty information private.
  2. Scope. Everyone who works for or with [Office name], on any device used for our work.
  3. Approved tools. [Tool, plan, who may use it]. Anything not listed is not approved.
  4. Data rules. Green: allowed. Amber: approved tools only, names removed where possible, a person reviews the output. Red: never entered into an AI tool unless [name] approves in writing.
  5. Human review. A person checks every AI output before it is sent, filed or relied on. AI does not send messages or move money.
  6. New tools or uses. Ask [name]. Answer within [number] working days.
  7. Incidents. Tell [name] right away. We record what happened, what data was involved and what we did.
  8. Training. Every new team member before first use, and everyone each quarter.
  9. Records. [Name] keeps the approved tool list, approvals, incidents and policy versions.
  10. Review. Every quarter, or sooner if a tool's terms change.

Acknowledged by: [name, date].

Who should I ask, and what is this guide not?

This is a planning guide, not legal advice. Questions 3, 5 and 6 belong with counsel. Question 7 belongs with counsel and your IT or security provider. Your insurance broker can tell you whether your cyber or professional policies address AI tools. Your principal, or whoever runs operations, should own the page itself.

If you are the principal and have not used the tools yourself yet, start with the first 30 days for a principal, then write the policy. For an organization-wide view of the same decisions, read AI governance for non-technical CEOs, and for a standing home for them without a full-time hire, the center of excellence blueprint. If you want help setting this up, see executive AI coaching or fractional CAIO engagements.

Sources

Frequently Asked Questions

Do we need a policy if the office has only a few people?

A short one, yes. A single page is enough to start, and it is easier to follow than a long document. The point is that everyone gives the same answer when asked.

Is the NIST AI Risk Management Framework mandatory?

No. NIST describes it as voluntary. It is a public reference you can point to when someone asks what you follow.

Should we ban AI tools until the policy is finished?

That is a decision for the principal and counsel. My view is that a ban often moves use to personal accounts, which you can see even less, so approving one tool and one plan quickly is usually the stronger first step.

Who should own the policy?

One named person with authority over staff and direct access to the principal. In a small office that is usually the principal or whoever runs operations.

Two ways to work together

If this is on your desk, a 30 minute conversation is the easy next step. Private executive AI coaching if you want to build your own fluency, or a fractional CAIO engagement if you want a leader inside your team.

Prefer to write first? Send a note.

Not ready for a call? Take the 8 question AI leadership snapshot. No email needed.