Reference note
Enterprise AI Security Checklist
A practical governance baseline for identity, data handling, integrations, retention, and high-impact AI actions.
Research area
Identity
Controls that apply across approved enterprise AI services and the identity systems used to access them.
Personal-account use for company work
Keeps company data within approved workspaces and organizational oversight.
Authentication paths that bypass SSO or MFA
Prevents weaker sign-in methods from undermining centralized authentication. Preserve controlled emergency access.
Unrestricted user consent to third-party applications
Prevents users from granting unreviewed access to corporate email, files, and other sensitive data.
Stale accounts, sessions, and tokens
Reduces opportunities to exploit abandoned access after departures or role changes.
Unnecessary standing administrator access
Limits the damage caused by compromised accounts or administrative mistakes.
Research area
Claude
Claude organization settings, project sharing, connectors, memory, and Claude Code permissions.
Optional model-training or data-sharing enrollment
Prevents voluntary sharing beyond approved commercial data protections. Commercial data is not used for training by default.
Memory and past-chat search
Reduces reuse of sensitive information across conversations. Review existing stored information separately.
Unnecessary broad project sharing
Limits internal exposure of project content. Claude's Public projects setting concerns organization-wide visibility.
Unapproved connectors and unnecessary write or delete actions
Reduces third-party data exposure and unauthorized changes to connected systems.
Claude Code permission-bypass mode
Preserves permission checks before commands and tools execute.
Research area
ChatGPT
ChatGPT Enterprise workspace controls for data use, memory, sharing, apps, connectors, and external actions.
Optional model-improvement sharing, where applicable
Prevents optional contribution of business information to training. Enterprise data is excluded from training by default.
Persistent memory
Reduces storage and reuse of sensitive context across conversations. Disabling memory does not substitute for reviewing stored information.
Unnecessary sharing of chats, files, and GPTs
Limits exposure beyond intended audiences. Review existing shares separately.
Unapproved apps, plugins, and MCP connections
Prevents unreviewed integrations from accessing company data or connected systems.
Unnecessary external actions and unrestricted action destinations
Reduces data transfers to unapproved services and consequential actions without appropriate oversight.
Research area
Microsoft 365 Copilot
Workplace Copilot and Copilot Chat controls. This section does not cover GitHub Copilot.
Personal or consumer Copilot use for company data
Keeps business use within the approved work-account experience and applicable enterprise protections.
Allow web search in Copilot
Prevents generated search queries from being sent to Bing for sensitive workflows; disabling it also removes web grounding.
Unapproved agents and extensions
Reduces exposure to unreviewed functionality, integrations, and data access.
Unrestricted consent to Microsoft Graph and third-party permissions
Prevents excessive access to organizational information and actions.
Excessive SharePoint and OneDrive permissions
Reduces the sensitive content Copilot can surface through users' existing access. Fix permissions at the source.
Research area
Gemini / Google Workspace
Managed Workspace access, conversation history, connected apps, consumer activity, and Gemini Live capture permissions.
Gemini access for unapproved users or organizational units
Limits deployment to approved users and managed Workspace services.
Gemini conversation history
Reduces saved conversation history where retention requirements permit. History off does not mean zero retention or immediate deletion of existing history.
Unnecessary Connected Apps
Limits access to Gmail, Drive, Calendar, GitHub, and other connected services.
Consumer Keep Activity for permitted personal-account use
Limits future consumer activity use for model improvement. Managed Workspace accounts follow different controls.
Unnecessary Gemini Live microphone, camera, and screen sharing
Reduces accidental capture of confidential conversations, surroundings, and on-screen information. Assess recording retention separately.
Research area
Organization-wide governance
Policy controls that apply across vendors. These recommendations synthesize documented capabilities into an organizational security baseline.
Unapproved AI services, browser extensions, and integrations
Reduces unmanaged AI use and data flows outside approved oversight.
Submission of prohibited sensitive data
Prevents credentials, secrets, regulated information, and confidential material from entering unauthorized systems.
Autonomous high-impact actions without approved oversight
Reduces harmful external communications, production changes, payments, access changes, and destructive operations.
Indefinite retention without documented justification
Reduces unnecessary accumulation of sensitive information while preserving legal holds and required records.
Unreviewed activation of new features and expanded permissions
Prevents new capabilities from introducing unassessed access or data exposure.
Protective controls
Keep enabled
MFA, SSO, security audit logging, monitoring, data-loss prevention, and required compliance retention.
Operational follow-through
Implementation record
Record who owns the control, where it is enforced, how it was verified, and when any approved exception expires.