Home / Standards / AIGS 300
Exposure Draft

AIGS 300 Usage and Access

The organization knows who uses which AI, through which surface, and whether that use is sanctioned, and it says plainly where it cannot see.

Document
AIGS 300, Exposure Draft ED-2026-300
Status
Founding draft, open for member comment
Working Group
TWG-300 Usage

1. Objective

To give the organization an accurate picture of AI use, sanctioned and unsanctioned, so that access can be governed and risk can be prioritized, without overstating what is known.

2. Scope

AI use through enterprise copilots, agent platforms, developer assistants, model APIs, and AI services reached through web browsers or endpoints.

Enterprise copilots and agent platformsusage and admin logs Developer assistantsseat and activity reports Model APIs and gatewaysgateway and billing records Browser and endpoint AI surfacesonly where a sensor is deployed
Each layer is reported as measured or not measured; gaps are never filled with assumptions.

3. Requirements

300.1The organization shall maintain a register of sanctioned AI services, models and tools, with the purposes and data classes each is approved for.
300.2The organization shall collect usage information from each sanctioned surface, identifying the user or non-human identity, the AI system and the time of use.
300.3The organization shall detect use of unsanctioned AI services on the surfaces it can observe, and shall record the response taken (approve, redirect, block or accept risk).
300.4The ability to build, publish and share AI agents shall be granted by role on a least-privilege basis and reviewed at least quarterly.
300.5Every usage report shall state its coverage: which surfaces were measured, which were not, and why. A surface without a deployed sensor shall be reported as "not measured", distinct from "no use found".
300.6Where usage data is used to rank individuals or tools by risk, the ranking shall be presented as a triage order, not as a probability of wrongdoing, and the factors behind each rank shall be shown.
300.7Monitoring of individuals shall comply with applicable employment, privacy and works-council requirements, including notice to employees where required.

4. Evidence

  • Sanctioned AI register with approval records.
  • Usage reports with stated coverage.
  • Unsanctioned-use findings and responses.
  • Builder and publisher role reviews.
  • Employee monitoring notice and legal review records.

5. Metrics

MetricDefinition
Surface coverageIn-scope AI surfaces measured, divided by all in-scope surfaces.
Sanctioned shareObserved AI use on sanctioned services, divided by all observed AI use.
Builder privilegeUsers able to publish agents, divided by all users.

6. Basis for conclusions

The most common reporting error in AI usage is silence mistaken for safety: a surface with no sensor shows no findings. Requirement 300.5 makes coverage explicit. Requirement 300.6 reflects the base-rate problem in behavioral analytics: without labeled incidents, risk scores cannot be calibrated as probabilities and should be used to order attention, not to judge people. Requirement 300.7 recognizes that workplace monitoring is regulated in many jurisdictions.

7. Questions for respondents

  1. Should browser-level visibility be required, or remain risk-based?
  2. Is a quarterly builder-privilege review practical at scale?