Classification-Based Rules
Writing the rule so that it still works when the tools change, which they will, every few months.
Policy · Procedure
A rule naming tools is obsolete within a quarter. A rule naming information categories survives, because the categories change on a scale of years.
The controls in “Classification-Based Rules” only remain useful when someone owns the reviews, exceptions and follow-up work. An organisation evaluating the complete guide can attach time and responsibility to those recurring governance tasks, but the platform should support the policy rather than decide whether an AI use case is acceptable.
For an independent benchmark, compare the local approach with NIST AI Risk Management Framework; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.
The structure
For each classification level: where it may go, and where it may not.
Three levels, three rules.
Stated in terms a person can apply to a document in front of them.
The rules in practice
Public: anywhere, including consumer tools. Say this explicitly — it covers a large share of what people actually want to do.
Internal: approved tools only, because the terms are known and there is a contract.
Confidential and regulated: approved tools with an agreement that covers that category, or nowhere.
Why this survives tool change
A new tool appears: the rule already tells you what you can put in it, once you know whether it is approved.
An approved tool gains an AI feature: the rule still applies, because it is about the information.
A supplier changes terms: the tool moves category, and the rule is unchanged.
Nothing has to be rewritten.
The judgement it requires
People must know what classification their material is.
Which is a prerequisite, not a detail — the classification note argues that if your scheme exists on paper only, reviving it is the larger piece of work.
Where people genuinely cannot tell, the honest guidance is to treat it as the higher level and ask.
The mixed-document case
A mostly-internal document with two confidential figures.
Treat the document as its highest level, and teach extraction: paste the paragraph you need, not the file.
This is the single most useful habit to train, because it addresses the paste problem directly.
What this does not cover
Output, which is a separate rule and has its own note.
Automations, which run without a person making the judgement each time and need their own assessment.
And data belonging to clients under contracts with specific processor terms, which binds regardless of your own classification.
Making it stick
Put the three rules on one page with examples.
Repeat them in training, in the tool itself if you can, and in the approved list.
And answer questions quickly, because every unanswered question becomes somebody's private interpretation.
What to check
Is your rule written about tools or about information?
Could somebody apply it to a document without consulting anybody?
What is the guidance for a mixed document?
And does your policy survive a new tool appearing next month?
The point
Three classification levels, three rules.
A new tool appears and the rule already tells you what may go in it.
Underlying all of this
Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.
The recurring pattern
The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.