AI Data Boundaries
How AI tools accessing district data are inventoried, configured, and scoped.
Capture progress
1 of 4 fields captured
Maturity preview · Initial

AI practice

Sanctioned and shadow. Without an inventory, AI data-boundary controls are theoretical — you can't bound exposure for tools you don't know are in use.

Tenant-level controls on M365 Copilot / Google Gemini / Adobe Express AI / other sanctioned AI products. The single highest-leverage technical control in this sub-domain — once enforced, district inputs no longer feed vendor model training.

Who can use which AI tools, with which data class. Different from Cyber IAM (which controls access generally) — this asks specifically about AI-tool access scope and data-sensitivity gating.

AI capabilities change month-to-month — new copilots, new data-handling defaults, new agent surfaces. Static inventory becomes stale fast; review cadence keeps controls current.

Notes