An AI footprint audit: every AI tool in production or in use, what data each one touches, what permissions each one has, what the vendor's actual data-handling policy says, and where the gaps are. The unsexy work of just knowing what you have.
A data-handling architecture for AI workflows: what classes of data can go to which model, what has to stay on-prem or in your tenant, what gets redacted before a prompt, how outputs get logged and reviewed. A real spec, not a poster.
A vendor-diligence pack for your top five AI tools: data-residency, sub-processors, DPA terms, training-on-prompts settings, retention windows, audit-log capability. The questions your procurement team should have asked at purchase.
A governance model: a written acceptable-use policy, an approved-tool list with rationale, an incident response runbook tuned for AI incidents (prompt injection, vendor breach, hallucinated action), an executive-review cadence.
A 60-day remediation plan ranked by exposure. The two or three things to fix first, with owners, dates, and what 'done' looks like.