HomeSecurity, Governance, & Risk

Enforcing AI Policy Creates Employee Privacy Risks That IT Can't Govern Alone

August 30, 2026

Sandy Jacolow, SVP and CTO at Empire State Realty Trust, on why prompt logs can expose sensitive disclosures and how shared oversight keeps them with the right reviewers.

Enforcing AI Policy Creates Employee Privacy Risks That IT Can't Govern Alone
Credit: CIOnews

Get the latest from CIOnews.

Enterprise AI, governance, risk, and leadership insights for CIOs, CTOs, CISOs, and technology leaders.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
"How do you make sure the system knows this is an HR matter? Somebody from IT shouldn't look at that, because then you get into all kinds of GINA regulations and ADA regulations."

Sandy Jacolow

SVP & CTO
@
Empire State Realty Trust

An AI policy is cheap to write and expensive to enforce. The moment a company starts recording what employees type into a model, those logs stop being a security artifact alone. Its security policy and its HR policy start reaching for the same records, and someone has to decide who governs what.

Sandy Jacolow is Senior Vice President and Chief Technology Officer at Empire State Realty Trust, the REIT that owns and operates the Empire State Building, where he leads technology across property management, leasing, and development. Over four decades in real estate technology, he ran IT at Silverstein Properties through the construction of World Trade Center towers 3 and 4 and held CIO roles at Meridian Capital Group, Newmark, and Clarion Partners. He chairs the real estate working group for InfraGard's New York chapter, and most of his attention now goes to cyber.

"When you're capturing the prompts people put in, you could have somebody using AI to draft an email to HR about a health issue. If that prompt gets flagged and someone reviews it, you now have a security policy touching an HR policy," Jacolow said. The collision isn't hypothetical for a publicly traded company that already screens queries before they reach a model. Once the logging exists, the question of who is allowed to read a flagged prompt turns into a governance problem with legal weight behind it.

  • Where the logs lead: Jacolow's team runs prompt guards that inspect queries in real time, blocking attempts to pull salary data or talk the model into working around the rules. The same pipeline that catches a policy violation also captures an employee's private disclosure, and that's where security and HR start to overlap. A flagged health prompt puts an IT reviewer in front of information protected by the genetic-information law and the ADA, which is not a place an IT reviewer should be. "How do you make sure the system knows this is an HR matter? Somebody from IT shouldn't look at that, because then you get into all kinds of GINA regulations and ADA regulations," Jacolow said.

  • Build the committee first: His answer was structural, and he stood it up before a flagged prompt forced the issue. Empire State Realty Trust runs an AI committee that reaches well past IT, pulling in the CFO, general counsel, and head of HR, because the decisions cut across all of them, down to defining what counts as proprietary information. It mirrors the cross-functional committee model other enterprises are landing on for the same reason. "You can't just raise the issue. You have to come back with a solution or a recommendation," Jacolow said. "It has to be a comprehensive engagement, because things are moving too quickly to keep up with alone."

  • The controls underneath: Policy sits on top of a stack of enforcement. Non-enterprise versions of AI tools are off limits, and access to AI sites is blocked at the firewall and VPN until a manager signs off on a business reason. Developers work in a separate Microsoft tenant against a copy of production data, so experimentation never touches live systems, part of the guardrails around the model that turn a written rule into something operational. "It's a very strong, multifaceted approach. It's a use policy, it's sandboxes, it's prompt guards," Jacolow said.

Technical controls only work if people respect them, and awareness campaigns tend to fade into background noise. Jacolow's team went the other way, making the consequences of ignoring security concrete enough that employees have a personal reason to pay attention.

  • Tie it to comp: The move that changed behavior most was tying phishing-test results to compensation. Fail more than three and it shows up in a mid-year and year-end review, with a possible hit to the bonus, and internet access gets curtailed in the meantime. Roughly half the company now flags suspicious messages to the help desk rather than risk clicking, and employees compare notes when someone slips. "That made it real for people, because now they're vested in it too," Jacolow said. It helps that the chairman raises cyber unprompted, including once in the middle of a holiday-party toast.

The reason the committee and the controls exist ahead of any incident is speed. Each model release changes what the guardrails actually cover, so a policy that fit last month may already be out of date. Jacolow's team rewrites its AI policy every month, keeping it in step with the enforceable controls beneath it rather than treating governance as a document to publish once.

"No matter what we do, AI will move faster than any governance we can come up with. It's literally an everyday change," Jacolow said. Waiting for a flagged prompt to surface the HR question means answering it in a hurry. Building the committee before it lands is what lets the answer hold up.

research report

From the Edge to the Core:
Bringing Agentic AI to the Heart of the Enterprise.