Is your org’s AI policy integrated into the IT security policy, or does it exist as its own separate policy?
AI policy is integrated into IT security policy19%
We have a separate AI policy, but IT security policy includes section on AI security53%
AI policy and IT security policy are completely separate26%
Something else (explain in a comment)1%
77 PARTICIPANTS
There's a 3rd angle in here and that's data classification and handling, which is often a policy distinct from IT Security.
Data classification has an impact on AI as there are certain types of informaiton or data you don't want/can't have an AI accessing.
To this end, the 3 policies should be seperate but cross referencing each other where appropriate.