How I use AI

I help organizations and government agencies write AI use policies. It would be strange not to publish my own.

Version 1.2, Aug. 15, 2026

Why this page exists

AI consulting is part of my practice. If I am going to sit across the table from a client and help them decide what their people can and cannot do with these tools, you should get to see the rules I hold my own firm to.

And "we don't use AI" is not a credible sentence in 2026. The tools are in the research, the drafting and the editing, and pretending otherwise would be dishonest. Even autocomplete in Outlook or Gmail, or a pass through Grammarly, is some form of AI. A disclosure label at the bottom of a page does not solve the problem either. It tells you nothing you can act on, and by the fifth one you have stopped reading them. So this page does what we tell clients their policies should do. It gets specific about where a model shows up in the work, where one does not and what we refuse to put into one.

The most important part is that a real-live human reviews every deliverable before it ships.

The question I tell clients to ask

When I work with clients, I tell them to ask every one of their vendors two questions: how do you use generative AI, and do your AI tools train on the data we give you? Any vendor should be able to answer both in plain terms. Here are mine.

We use AI to help write the rough first draft, to work through basic and complicated research tasks, to compile facts with citations so they can be verified and to build system diagrams when the work needs one. And no, our tools do not train on the data we give them. Most importantly, a real-live human reviews every line before anything ships to a client. Our critical thinking, experience and expertise go into our deliverables, and the AI tools at times help us deliver them faster.

What goes in, and what never does

Bluntly, most AI policies skip this, and it is the part we would press on if we were evaluating a consultant. The data question comes before the model question.

The platform side first. Every AI tool we use runs on a business account with enterprise terms, no training on our inputs and retention workflows that flush data quickly. We do not use consumer chatbots or consumer AI tools, and that distinction matters.

The data side is stricter, because enterprise-ready AI tools and their terms are not permission to paste all client information into them. Client findings stay out. Anything carrying a TLP restriction stays out (TLP is the Traffic Light Protocol, the labeling system the security community uses to control who can see shared threat information). Client-specific threat indicators stay out. And when AI touches client-facing work, we take the client out of it first: the model sees "a water treatment client" or "an election office," never the name, the network or the details that would identify one.

Incident response is the one exception, and it is a narrow one. When a client hands us logs during an incident, we may use these tools to help review them, inside that enterprise deployment. Even then, credentials, personal information and anything TLP-marked stays out.

Where a model shows up

A draft usually starts with me talking. Wispr Flow turns the talk into a rough transcript, a model helps me find the structure in it, and I fix what I said. The tools include Adobe Creative Cloud, Claude, ChatGPT, Canva and occasionally OpenAI's open-weight gpt-oss model.

For research, a model summarizes the standard, the rule or the vendor documentation and points me at the parts that bear on the question in front of me. Then we read the source. We check every statistic, citation and quote that reaches a client or gets published here against the original, because models produce references that look right and do not exist.

We use models to help us edit sections of documents, to cut, to tighten and to find the places where we may have written around a point instead of making it directly.

A real-live human makes and owns every judgment call.

What stays ours

The ideas and the analysis. Findings, risk ratings and the recommendation at the end of an engagement come from the consultant who did the work, and never from a model. We do not ask a model to fill a gap in what we know and then hand you the answer as though we knew it. We do not generate client examples, case studies or testimonials, and any engagement we describe is one that happened.

The people who work with me

Foundation Consultant Group is me plus subcontractors. This policy binds my subcontractors too, and it is part of their subcontractor agreement. Subcontractors tell me how they used these tools on an engagement, and their output gets the same human review mine does.

Two worth reading

I did not invent this kind of page. The Center for Democracy and Technology publishes its own generative AI usage policy: short, readable and honest that its people use the tools, with a person standing behind every use. I point clients to it regularly. And Katie Harbath's "How I Use AI to Make My Newsletter, and What I Won't Let It Do" walks through her whole process, tools and limits included. She does amazing work. Both set the standard this page is trying to meet.

Questions

If you are evaluating us and need more detail than this page gives, ask. Engagement agreements can carry specific terms on AI use, including terms stricter than what is written here. Reach us through the contact form.

Version 1.2, published Aug. 15, 2026. This version added the section on client data, the reasoning behind the rules and two outside references, and it now says "we" where the whole firm is on the hook, not just me. If I update it again, the version and the date change here and I will say what moved.