1. Purpose
This policy governs the use, development and deployment of AI across TFG. AI may support productivity, analysis, content, data products and workflows, but does not replace professional judgement. Users remain accountable for the accuracy, legality, suitability and client impact of work produced with AI.
2. Scope
The policy applies to all personnel, operating companies, AI tools, models, copilots, agents, prompts, connectors, retrieval systems, automation, embedded AI features and AI-generated outputs used for TFG business.
3. Approved use
Use approved enterprise tools for business activity.
Follow client contracts, documented restrictions and information classification.
Use only the minimum information required for the task.
Review and verify outputs against authoritative sources.
Disclose material AI use where contract, law, policy or professional context requires it.
Record owner, purpose, sources and lifecycle status for deployed agents and applications.
4. Prohibited use
Entering client-prohibited, restricted, credential, security-sensitive or special-category information into an unapproved AI service.
Using consumer or personal AI accounts for confidential TFG or client work.
Allowing an agent to take high-impact external action without defined approval and rollback controls.
Presenting fabricated citations, unverifiable claims or synthetic data as factual.
Using AI for unlawful discrimination, deceptive impersonation, unauthorised surveillance or rights-infringing activity.
Circumventing safety, access, logging, content or client controls.
5. Prompt and data handling
Prompts and outputs are information assets. They must be classified according to their content, stored only where approved, shared on a need-to-know basis and retained according to the approved schedule. Source permissions must be corrected before connecting Copilot or an agent; AI must not be used as a workaround for weak access governance.
6. Agent governance baseline
Control
Minimum requirement
Ownership
Named business owner and technical owner.
Purpose
Documented use case, users, value and prohibited uses.
Identity and access
Managed identity where supported; least privilege; no shared credentials.
Data
Approved sources, classification, lawful basis, retention and deletion.
Actions
Allow-listed tools/actions, human approval for high impact, rollback/disable route.
Evaluation
Accuracy, source quality, harmful output, prompt injection, privacy and security testing.
Observability
Usage, errors, actions and security events logged where architecture supports it.
Lifecycle
Status recorded as concept, test, live, suspended or retired; periodic review.
7. Microsoft service controls
Use Microsoft 365 and Entra permissions as the primary access boundary for Microsoft Copilot experiences.
Use sensitivity labels, retention, DLP, audit and Purview AI capabilities where licensed, configured and appropriate.
Review oversharing and stale access before enabling broad AI discovery.
Use approved Copilot Studio/Azure environments, connectors and deployment pipelines for built agents.
Do not state that a control is active solely because Microsoft offers it; configuration and evidence are required.
8. Human oversight
Human review is required for client recommendations, media investment, regulatory or legal content, public statements, sensitive people decisions, financial commitments, contractual interpretation and actions that change production systems or external platforms.
9. Incident and reporting
Unexpected disclosure, harmful output, prompt injection, unsafe action, model/provider issue, excessive access or policy breach must be reported immediately under the Incident Response Plan. The affected tool or agent may be suspended while investigated.
10. Governance and assurance
The AI Governance Committee maintains the approved-tool register, risk tiers, agent inventory and exceptions. High-risk or client-facing deployments require documented approval. Training is mandatory for users of approved AI services. This policy is reviewed at least annually and following material legal, supplier, model or architecture change.
11. Microsoft reference basis
Microsoft Cloud Adoption Framework: governance and security baseline for AI agents.
Microsoft Purview guidance for data security and compliance controls for generative AI.
TFG Information Security Policy, ISMS Scope, GDPR Policy and Incident Response Plan.