✦ Switch to AI view
AI Services — Governance

AI Acceptable Use Policy & Governance for NH & MA Businesses

A written AI policy your staff will actually follow, built after we find out which tools they are already using — and mapped to the Massachusetts and New Hampshire rules that apply to you.

Serving New Hampshire & Massachusetts — remote nationwide
AI Acceptable Use Policy & Governance for NH & MA Businesses
Why Switch

Governance That Fits Your Business

Not a 90-page binder nobody reads. A short, enforceable policy sized to your actual risk.

Usage Audit First

We find out which AI tools your staff already use before writing a rule about any of them. Governing what you assume is happening is how policies end up ignored.

Mapped to Real Statutes

Massachusetts named AI in an Attorney General advisory. New Hampshire declined to pass an AI law. We tell you which of that reaches you and which does not.

A Named Person Owns It

Every AI-influenced decision stays owned by a human being with a name. The tool drafts; the person is accountable.

Pricing

How AI Policy Work Usually Gets Sold

Most providers hand you a generic template, or quote a consulting project without telling you whether you needed one.

RNITS

In-plan from $100/user

Typical Provider

Quote on request

Shadow-AI usage audit before drafting
Always first
Rarely offered
Policy templates in the base plan
Included
Billed as consulting
Mapped to named state statutes
Yes
Generic "regulations"
Published plan pricing
Yes
Rarely
Compliance audit support
Enterprise plan
Extra engagement
Will say you do not need this
Yes
Almost never

Self-service template policies and a cybersecurity risk assessment are in every plan, including Standard at $100/user/mo. A full framework build is scoped as a project and quoted before you commit — we do not put a number on that page because it moves with headcount and how regulated you are.

What's Included

What Lands in Your AI Acceptable Use Policy

The specific sections we write, not a list of themes.

Approved & Prohibited Tools

A named list of which AI tools are sanctioned, which are banned outright, and who approves an addition.

Data Classification Rules

Which categories of information may never be pasted into a public model — client records, PHI, card data, credentials, unreleased financials.

Vendor & Contract Review

What to check before a tool enters your environment: data retention, training on your inputs, and whether the vendor will sign a BAA if you need one.

Human Review Triggers

The decisions where AI output cannot ship unreviewed — anything affecting hiring, credit, pricing, medical care, or a legal position.

Framework Alignment

Policies mapped to NIST AI RMF functions and to the HIPAA, CMMC, SOC 2, or PCI DSS obligations you already carry.

Incident & Audit Trail

What to do when data goes somewhere it should not, and the documentation an auditor or insurer will ask to see.

Details Illustration of an AI policy document protected by a shield and balance scale

Almost everyone who calls us about AI governance wants one document, even when they do not use the term for it: an AI acceptable use policy telling staff which tools they may use and what they must never paste into one. That is two pages, not a program, and you can have it inside a month.

The part almost nobody covers is which rules reach a New Hampshire or Massachusetts business in the first place. It is less than you have probably been told, and one piece of it catches NH companies who have never heard of it.

Which rules actually reach a NH or MA business

Compliance is where IT providers do their worst selling, usually as vague warnings about “AI regulations” attached to a quote. The specifics matter, and they cut both ways.

New Hampshire has no AI law covering private businesses. HB 1725 would have established a Responsible AI Governance framework — an AI Council, consumer protections, a regulatory sandbox, and Attorney General enforcement with civil penalties reaching $200,000 per violation. The committee recommended it inexpedient to legislate and the House agreed in February 2026. It is dead. RSA 5-D covers how state Executive Branch agencies use AI, not how your company does. If a provider implies New Hampshire mandates an AI policy, that is a sales tactic.

Massachusetts named AI explicitly, and it reaches users, not just vendors. In April 2024 the Attorney General issued an advisory stating that existing Massachusetts law already applies to AI developers, suppliers, and users. Three pieces matter for a small business deploying tools rather than building them:

  • Chapter 93A, the Consumer Protection Act, on unfair or deceptive practices — which the advisory extends to claims you make about an AI system’s reliability or freedom from bias.
  • Chapter 93H and the data security standards under 201 CMR 17.00, on safeguarding personal information about Massachusetts residents.
  • Chapter 151B, the anti-discrimination law, where an AI-influenced decision produces a discriminatory outcome in hiring or comparable areas.

And 201 CMR 17.00 attaches to the data, not the state line. This is the one that catches New Hampshire companies. Any business holding personal information about a Massachusetts resident is covered, wherever it sits, with no size or revenue exemption. So a Nashua or Salem firm with Massachusetts customers — or Massachusetts employees on payroll — needs a written security program that New Hampshire itself never asked for, and an AI tool quietly ingesting that data is squarely inside its scope.

Sector rules bind regardless of geography. A medical practice still answers to HIPAA, card payments still fall under PCI DSS, and firms fielding customer security questionnaires still need SOC 2 evidence. AI does not create a separate obligation there; it creates a new way to breach the one you already have.

We are not lawyers and none of this is legal advice. We will tell you which of it touches your business in a first conversation, for free.

Shadow AI is what you are really governing

The risk is rarely a deliberate policy violation. It is a well-meaning employee on a deadline.

Someone pastes a client list into a free chat tool to reformat it. Someone drops a patient summary in to shorten it. Someone uploads last quarter’s unreleased numbers to build a slide. None of them are being reckless — they are being efficient with a tool that is one browser tab away and has no warning label. That is why we run the usage audit before drafting anything: a policy written against imagined behavior regulates a company that does not exist.

The audit usually surfaces tools leadership had no idea were in play, and it changes what the policy needs to say. It also tells you something more useful than a compliance answer: which work your staff are trying to speed up. That is often where AI automation pays off, and a governance engagement is a cheap way to find it.

Where this service ends

Worth being blunt about the boundaries:

  • We write policy; counsel reviews it. We identify which rules appear to apply and draft against them. For most small businesses the legal review that follows is a short one rather than a project, but it is not ours to skip for you.
  • We cannot certify you to ISO/IEC 42001. The AI management system standard published in 2023 requires an accredited third-party body. We can align a framework to it and support the audit; the certificate is not ours to issue.
  • We are not an AI vendor. We do not resell a platform, so the approved-tools list is not a product recommendation dressed up as a policy.
  • We will not build a program you do not need. Two sanctioned tools and no regulated data means a page and a signature line, and we would rather say so than scope a project.

AI governance vs. the services next to it

Four pages here describe adjacent AI work, which is easy to confuse. The honest division:

ServiceWhat it coversWhen it is the right page
AI governance (this page)The rules: approved tools, data handling, accountability, audit trailYou need a written policy, or you do not know what staff are using
AI trainingTeaching staff to use the tools well and judge the outputThe tools are sanctioned; the skills are the gap
AI enterprise deploymentSelecting, integrating, and running AI across your systemsYou are rolling AI out and need it to fit your stack
AI automationBuilding specific workflows that remove repetitive workYou have a named process worth automating

Governance comes first in practice, because the other three all raise the question of what staff are allowed to feed a model. It is also the cheapest of the four to get wrong quietly.

What it costs

Governance-adjacent work sits inside the managed plans rather than being sold as a separate line:

  • Standard, $100/user/mo — self-service template policies, cybersecurity risk assessment, identity and access management, real-time change documentation, and security awareness training.
  • Premium, $125/user/mo — adds bi-annual simulated phishing, annual vulnerability scanning, and a monthly executive report.
  • Enterprise, $150/user/mo — adds compliance audit support, advanced reporting for compliance, and a documented business continuity plan. This is the tier for businesses facing audits, security questionnaires, or regulated data.

Full inclusions are on the plans page. A bespoke framework build for a larger or heavily regulated environment is scoped as a project and quoted before you commit. We publish the plan numbers because comparison shopping a provider is close to impossible when nobody will put a figure in writing first.

Working with us in New Hampshire and Massachusetts

We are based in Tyngsboro, MA, which puts us inside the border zone this page keeps coming back to: onsite service within roughly 150 miles covers most of New Hampshire and Massachusetts, and a good share of our clients hold data on both sides of the line. Most are businesses between 1 and 100 employees in healthcare, legal, financial, manufacturing, and construction, where AI exposure is really a data-handling question with a compliance consequence attached.

Policy work pairs naturally with AI training, so the rules and the tools land together, and with vCISO if you want someone accountable for security decisions without hiring an executive.

If you want to know which AI tools are already running in your environment, the free cyber security audit covers that. Or get in touch and we will walk through which rules reach you before anyone talks about scope.

How It Works

How We Build Your Framework

Four to eight weeks for most small businesses, built with your leadership rather than handed down.

1

1. Find the shadow AI

We inventory what is in use across departments, including the tools nobody told you about. This step usually changes the policy that gets written.

2

2. Scope what applies to you

We work out which obligations reach your business, and say so plainly where the answer is that none of them do.

3

3. Draft something readable

A short policy in plain language with a signature line, not a binder. If your staff cannot recall the rule, it is not a control.

4

4. Roll out and review

Paired with AI training so staff learn the rules alongside the tools, then revisited as your tool list and the law change.

FAQs

Common questions

What should an AI acceptable use policy actually contain?

Six things, and it fits on a page or two: the named list of approved and prohibited AI tools, which categories of data may never be entered into a public model, who approves a new tool, which decisions require human review before anything ships, what to do when data goes somewhere it should not, and who owns the policy. Anything longer tends to go unread, which defeats the point.

Does New Hampshire have an AI law we need to comply with?

Not for private businesses, as of August 2026. HB 1725 would have created a Responsible AI Governance framework with an AI Council, a regulatory sandbox, and Attorney General enforcement carrying penalties up to $200,000 per violation. The committee recommended it inexpedient to legislate and the House agreed in February 2026, so it is dead. RSA 5-D governs how state Executive Branch agencies use AI, not how your company does. Any provider telling you New Hampshire law requires an AI policy is selling.

We are in New Hampshire. Does the Massachusetts AI advisory apply to us?

Quite possibly. In April 2024 the Massachusetts Attorney General issued an advisory stating that existing state law applies to AI developers, suppliers, and users — so merely deploying a tool counts. The data security piece it points to, 201 CMR 17.00, attaches to the data rather than the state line. If you hold personal information about a Massachusetts resident, whether a customer or an employee on payroll, you are covered wherever your office sits. Businesses in Nashua, Salem, or Pelham are the most likely to be caught by this and the least likely to have heard of it.

Do we need this if we only use ChatGPT and Microsoft Copilot?

Usually yes, but the policy should be short. Two sanctioned tools still need a data-classification rule, because the realistic failure is an employee pasting a client list or a patient record into a consumer-tier chat window. What you probably do not need is a governance program. We will tell you which side of that line you are on before quoting anything.

How much does AI governance cost?

Self-service template policies and a cybersecurity risk assessment are included in every plan, starting with Standard at $100 per user per month. Premium is $125 and Enterprise is $150, which adds compliance audit support and advanced compliance reporting — the two things auditors and cyber insurers ask for by name. A full framework build for a regulated or larger environment is scoped as a project and quoted before you commit; we do not publish a number for it because it moves with headcount and regulatory load.

How does AI governance relate to HIPAA, CMMC, or SOC 2?

It fills a gap those frameworks predate. The HIPAA Security Rule already requires written policies covering technology use, and AI tools fall inside that requirement without being named in it — so a medical practice with no AI policy has a documentation gap, not a new obligation. The same logic applies to CMMC and SOC 2 evidence. AI governance closes the gap rather than adding a parallel program.

Is this legal advice, and can you certify us to ISO 42001?

No to both, and we would rather say so up front. We are an IT and cybersecurity provider, not a law firm — we will tell you which rules appear to reach your business and recommend you run the final policy past counsel, which for most small businesses is a short review rather than a project. ISO/IEC 42001, the AI management system standard published in 2023, requires an accredited third-party certification body. We can build a framework that aligns with it and support the audit; we cannot issue the certificate.

Coverage

Onsite across New Hampshire & Massachusetts, remote nationwide

Headquartered in Tyngsboro, MA. Onsite support within 150 miles, remote support available in our target markets nationally.

Get Started

Talk through your IT and security priorities with RNITS.

If you are comparing providers or planning your next step, RNITS can help you sort out the work and the order it should happen in — zero obligation.