01 / AI product leadership
Making AI practical in a regulated workplace
Giving employees a useful way to work with AI, while accounting for sensitive information and the responsibilities of a regulated industry.
Review personal or confidential details before sharing your prompt.
A clear path to review and continue- My role
- Discovery, priorities, security coordination and rollout.
- Context & stage
- Employee-facing application
AI’s benefits, without leaving people to navigate the risks alone.
This was an internally developed general AI chat application, similar to Claude. It gave employees access to AI with safeguards designed to reduce the risk of exposing personally identifiable information (PII) or leaking confidential business and client data.
The point wasn’t just to introduce another tool. It was to make AI useful to people while accounting for the responsibilities of a regulated workplace.
Product leadership, from the need through rollout.
I led the product work from identifying the need and setting priorities through coordinating security, engineering and rollout. I worked with stakeholders to decide what we should deliver and what needed to be in place before people could use it.
The engineering team built the application. My responsibility was to keep the work focused on employees’ needs while bringing business, security and technical perspectives into the decisions.
The guardrails had to work for people, too.
The hardest decisions were about putting guardrails in place without making the application frustrating or limiting its usefulness. We wanted the smooth, feature-rich experience people expected from leading AI tools, while managing the risks of a regulated workplace.
Useful enough to adopt.
Careful enough for the context.
What had to stay in balanceEmployee needs, risk requirements and delivery priorities.
A control was not just a security requirement. It also affected how someone could work with the application. My role was to keep those effects part of the product discussion, rather than treating the employee experience and risk requirements as separate conversations.
What reached employees
Employees had an internal general-purpose AI chat application with safeguards intended to reduce sensitive-information exposure. The outcome described here is that capability, not a quantified reduction in security incidents.
The recurring product question was how to preserve usefulness while accounting for the environment people were working in. That tension was central to the work, not something to resolve once and forget.
Let’s talk.
If you’re looking for someone to lead software and AI products, I’d like to hear what your team is working on. If you need help making a process work better or figuring out where to start, I’m open to consulting conversations too.
yorence@whetstonedigital.io