Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsApprove workplace AI tools for a specific use—not as a blanket yes or no. A service used to draft text from public information can pose different risks from the same service connected to company files or used to make decisions about employees or customers. A repeatable process should identify the tool and intended use, assess risks, set permissions, test the real workflow, record the decision, and revisit it when circumstances change.
How do I approve AI tools for work?
Use a documented, risk-based workflow. NIST’s AI Risk Management Framework (AI RMF) organizes risk work around Govern, Map, Measure, and Manage; it is voluntary guidance, not a universal legal checklist. The framework was published in 2023, and NIST says version 1.0 is being revised. Its 2024 Generative AI Profile offers suggested actions rather than a guarantee that a system is safe.
- Record the request. Identify the service and version or configuration, business owner, intended users and purpose, connected systems, expected outputs, data entered or retrieved, and what could happen if an output is wrong or information is exposed. Note whether it is a third-party service, an embedded feature, or a locally operated model.
- Classify the use and information. Identify affected people and list data the workflow might submit, retrieve, or expose: personal, confidential, regulated, customer, employee, source code, or other sensitive information. Consider whether the task is reversible and low impact or could affect rights, safety, employment, finances, or significant business decisions.
- Review the service and vendor. Examine data collection and use, retention and deletion, model-training terms, access controls, incident handling, service terms, security documentation, subprocessors, and integrations. Choose proportionate due diligence; possible measures include procurement review, service-level agreements, software bills of materials, and attestation reports.
- Set approval authority and conditions. Name the business owner and involve the functions the use requires—often security, privacy, legal, procurement, compliance, or IT. Specify the approved tool, user group, purpose, permitted data, duration or review condition, and safeguards.
- Test the actual workflow. Use representative tasks, users, and data constraints. Evaluate capability, limitations, reliability, privacy and security behavior, and consequences of errors. Record the test conditions and what the results do and do not demonstrate.
- Record and communicate the decision. Document approval, conditional approval, or rejection; the rationale; residual risks; accountable owner; authorized settings and users; required training; and review triggers. Give employees plain-language instructions on the approved tool, allowed information, prohibited uses, output verification, and how to report problems.
- Monitor and revisit. Review incidents, relevant access logs, user feedback, vendor or model changes, new uses, and whether controls remain effective. Reassess when a material change could alter risk.
NIST’s framework is intended to support risk management across an AI system’s lifecycle and to be adapted to an organization’s context. Its suggested actions do not determine the legal requirements for a particular employer; those depend on jurisdiction, industry, workforce, and use.
What AI tools can employees use at work?
Employees should use tools and configurations that have been approved for their specific tasks and data conditions. A tool’s general approval does not automatically authorize every feature, integration, user group, or use case. Third-party generative AI may affect multiple organizational functions, and controls may need to differ for a foundation model, a fine-tuned model, or an AI feature embedded in another product.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Set conditions that employees can follow in practice:
- Which service, version, account, and configuration are authorized.
- Which employees or teams can access it, and for what work purpose.
- Which categories of information may be entered, retrieved, or connected.
- Which activities are prohibited or require separate review.
- Whether a person must verify outputs before using or sharing them.
- How long access lasts and what changes trigger renewed approval.
Match the approval path to risk rather than applying one identical process to every request. Public-information drafting or low-risk experimentation may fit a lightweight path. Sensitive data, external actions, or decisions affecting people may call for specialist review, narrower permissions, more testing, and closer monitoring. This tiered approach is an implementation choice based on risk; NIST does not prescribe a fixed tier structure.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How do we stop employees from putting sensitive data into AI?
Combine clear rules with controls that make the approved route practical. First define what counts as sensitive information in your organization and which approved tools, if any, may handle it. Then align access settings, connected systems, employee guidance, and review procedures with those boundaries.
- Restrict access: grant access only to authorized users and specify permitted data conditions. NIST’s AI RMF Playbook recommends documenting authorization, duration, type, and access controls for training sets or production data containing personally sensitive information.
- Check service terms and controls: understand data use, retention, deletion, training terms, integrations, and incident procedures before permitting sensitive information.
- State practical do-and-don’t rules: tell employees what information must not be submitted, which approved tool to use instead, and where to ask questions or report an accidental disclosure.
- Train users and review signals: explain the approved workflow and how to verify outputs; review incidents, feedback, and access information where appropriate.
No single control guarantees that sensitive information will never be entered or exposed. Choose safeguards proportionate to the data and impact, and reassess them when the service, configuration, or use changes.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Who should approve workplace AI tools?
There is no single approval role that fits every organization. Assign a business owner who is accountable for the purpose and outcomes, then bring in reviewers according to the data, system connections, and possible impact. Security, privacy, legal, procurement, compliance, and IT are common functions to involve; not every request requires every reviewer.
Use a written decision record so employees and reviewers can tell what was approved and why. Include the scope, authorized users and settings, permitted purposes and data, safeguards, test evidence, residual risks, decision owner, and conditions for review. For a higher-impact or less reversible use, require more specialist input and stronger evidence before release than for a low-risk task using public information.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How should an employer test and monitor an AI approval?
Test the service in the context where employees will actually use it—not only against a vendor demonstration or a general benchmark. NIST warns that generative AI pre-deployment testing can be inadequate, nonsystematic, or mismatched to real-world deployment. Benchmark results or anecdotes alone may not establish validity or reliability for a particular task.
Define representative tasks and constraints, then record what was evaluated: output quality and limitations, reliability, privacy and security behavior, and the impact of errors. Use findings to set conditions, such as limiting the task, requiring human review, or withholding approval until risks are addressed. After release, monitor incidents, user feedback, relevant logs, vendor and model changes, and control effectiveness. Renew approval when a material change changes the risk profile.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
What the federal AI example does—and does not—mean
Executive Order 14110 directed federal agencies to limit access, as necessary, to specific generative AI services based on risk assessments, while establishing use guidelines and enabling safeguarded access for experimentation and routine tasks with low risk of affecting Americans’ rights. That is an agency-specific direction, not a legal mandate for every private employer. Its risk-based approach can inform an employer’s own process, but applicable obligations depend on the employer’s circumstances and jurisdiction.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

