Part of Dean Dorton’s Cybersecurity Risk & Compliance Practice 

Are You Using AI Safely? 

Your employees are already using AI. Your vendors have embedded it in the tools you depend on. Your workflows are increasingly automated by systems that make decisions, take actions, and interact with your most sensitive data-often without anyone fully understanding the exposure. 

The question is no longer whether your organization uses AI. It’s whether you’re using it in a way you can stand behind when something goes wrong. 

Most organizations can’t answer that question yet. Not because they aren’t serious about it-but because AI adoption moved faster than the guidance did. 

That’s where we come in. 

What We Help You Do 

Dean Dorton helps organizations put the right structure around AI-practical, proportionate, and built for how you actually operate. Whether you’re a 30-person firm wondering if your staff’s ChatGPT use is a liability, or a regional health system navigating AI in clinical workflows, the core challenge is the same: you need confidence that AI is working for you, not creating risks you can’t see. 

We work with you to answer six questions every organization deploying AI should be able to answer: 

  1. What are your people allowed to do with AI? 
    We update your acceptable use policies to explicitly address AI-what tools are approved, what data can be used, and what the boundaries are-so your team can move fast without the exposure. 
  1. Do you know what’s inside the AI tools you’re already using? 
    Many organizations are unknowingly exposed through the vendors and platforms they already trust. We assess third-party AI tools and vendors to surface risks you may not know exist. 
  1. Have you mapped your AI risk? 
    We conduct structured risk assessments aligned to the NIST AI Risk Management Framework-giving you a clear picture of where your exposure is and a prioritized path to address it. 
  1. Are your AI systems configured to prevent autonomous harm? 
    AI agents and automated workflows can cause real damage when they operate outside appropriate boundaries. We review access controls, permission structures, logging, and  safeguards-so no AI tool in your environment has more access than it should. 
  1. Have you actually tested your AI security? 
    We conduct offensive security testing of large language models and AI systems, aligned to the MITRE ATLAS framework-prompt injection, data leakage, model abuse, and configuration vulnerabilities-so you know where the gaps are before someone else finds them. 
  1. Who is responsible when something goes wrong? 
    We help you establish clear ownership of AI risk-identifying who makes decisions, who sets the rules, and who is accountable when the unexpected happens. 

This Isn’t Just for Large or Regulated Organizations 

AI risk doesn’t scale with headcount. A 40-person accounting firm using an AI assistant that retains client data is exposed. A nonprofit using a productivity tool that trains its model on your inputs is exposed. A manufacturer whose AI agent has unconstrained access to operational systems is exposed. 

The risks are real regardless of size. The response just needs to be proportionate. 

We work with organizations across healthcare, financial services, education, professional services, manufacturing, and nonprofit-tailoring our approach to your size, your industry, and where you actually are in your AI journey. 

What Good Looks Like 

When we’re done, you should be able to say: 

  • We know who owns AI risk in our organization 
  • Our people know what they can and can’t do with AI tools 
  • We’ve reviewed our vendors and know what they’re doing with our data 
  • We have documented, defensible AI risk management-ready for an auditor, a regulator, or a cyber insurer 
  • Our AI systems are configured securely and we’ve tested them 
  • We can scale AI adoption with confidence 

That’s not a compliance exercise. That’s running AI the right way. 

Start with a Conversation 

You don’t need a fully formed project to reach out. Most engagements start with a single question, are we doing this safely? Contact us to start the conversation and figure out the right path forward.