A risk assessment of any AI tools is conducted prior to introduction. Location of processing, Information Assets being processed, use of information within the AI engine (training), segregation, resistance to OWASP top 10 for AI (https://genai.owasp.org/), etc..