Answer yes if AI is used to deliver or support any part of the service(s) you provide to clients, whether or not it is marketed as a distinct feature or the client is aware of it (e.g. an AI copilot, automated triage, generative content, or AI used internally in service delivery, such as AI-assisted QA or support processes).
A regular review of how AI models and services are used within your organisation to provide services to clients — what workflows are supported, the client data used with those services, and how the results of AI processing are used — can help inform security and risk management controls
Typically an organisation’s Information Security function can assist, but there are numerous consultancies or individual consultants that will be able to assist in crafting a policy that meets your business and technical requirements.