goJumboGPT

AI AI at work: policies, tools and what to watch

Writing an AI policy your team will actually follow

What a usable workplace AI policy contains: approved tools, data rules, disclosure, human review and accountability, with a short template you can adapt.

6 min read How we write

The short answer

  • A policy that only says no does not stop AI use, it moves it to personal accounts where the company cannot see or control it.
  • The structure that works is a short list of approved tools plus a short list of data that must never be entered, on one page.
  • Name one accountable human for every AI assisted output that leaves the organization, because the tool cannot carry responsibility.
  • Disclosure rules should be specific about when to say AI was used, not a blanket requirement people will quietly ignore.
  • Include a route to request a new tool, or staff will use unapproved ones rather than wait for a process that does not exist.

An AI policy works when an employee can read it in four minutes and answer one question: can I paste this into that tool. Everything else is supporting detail. The reason most policies fail is not that they are too lax or too strict, it is that they are written as a prohibition with no alternative, so a person facing a deadline uses their personal account on their phone and nobody ever knows. A workable policy therefore has two halves that must both be present: here are the tools you may use, and here is what must never go into any of them.

Start with what you are actually protecting

Before writing rules, sort your information into three buckets, because the whole policy hangs off this.

Red is data that must never be entered into any AI tool: customer or patient identifiers, health records, payroll and bank details, credentials, unreleased financials, anything under a confidentiality agreement, and personal data you hold about identifiable people where you have no lawful basis for that processing.

Amber is data that may be used only in an approved tool on a business plan with training turned off: internal drafts, non public project documents, anonymized extracts, supplier correspondence.

Green is anything already public or generic: published marketing copy, general questions, code with no proprietary logic, rewriting your own prose.

Most disputes inside a company are really disagreements about which bucket something is in. Writing five or six concrete examples per bucket resolves more arguments than a page of principles. The background on how providers handle what you send is in AI and your personal data.

The seven sections a policy needs

  1. Scope. Who it covers (staff, contractors, temps), and what counts as an AI tool, including features quietly added to software you already pay for.
  2. Approved tools. A named list, with what each is approved for. "Approved for drafting and summarizing internal documents" is more useful than a bare product name.
  3. Data rules. The red, amber and green lists, in plain words, with examples.
  4. Human review. Which outputs cannot be used without a named person checking them: anything sent to a customer, anything published, anything that affects pay, hiring, credit, health or legal position, and any code that reaches production.
  5. Disclosure. When AI use must be declared, to whom, and in what words.
  6. Accountability. The person who sends the output owns the output. State it once, plainly.
  7. Requesting a new tool. Who to ask, what they need to know, and how long an answer takes. Give a real service level, such as ten working days.

A template you can adapt

Copy this, replace the bracketed parts, and delete anything that does not apply to you. It is a starting point, not legal advice, and anything with regulatory weight should be checked by someone qualified in your jurisdiction.

AI use at [Company]

  1. You may use [Tool A] and [Tool B] on your work account for work tasks.

No other AI tool may be used for work without approval from [role].

  1. Never enter into any AI tool: customer or patient identifiers,

health information, payroll or bank details, passwords or keys, unreleased financial results, or material covered by an NDA.

  1. Internal drafts and non public documents may be used in the

approved tools only. Do not paste them into personal accounts.

  1. Anything that goes to a customer, gets published, affects a person's

job, pay, health or legal position, or runs in production must be reviewed by a named person before it is used. That person is responsible for it.

  1. Tell people you used AI when: the output is presented as your own

professional analysis, the recipient would reasonably expect a human wrote it personally, or a client contract requires it. You do not need to declare spell checking, rewriting your own sentences or translation for internal comprehension.

  1. Recording or transcribing a meeting requires everyone on the call to

be told before it starts. [Add your local rule here.]

  1. To request a new tool, email [address] with the task, the data it

would touch, and the vendor. You will get an answer within [10] working days.

  1. If you think you entered something you should not have, tell [role]

the same day. There is no penalty for reporting it promptly.

That last line matters more than it looks. If reporting a mistake is punished, mistakes get hidden, and a silent exposure is far more expensive than a reported one.

Sector overlays

Some industries need a layer on top, and the rules differ by country, so treat these as prompts to ask a question rather than answers.

SectorThe extra constraint
HealthPatient data is special category data in the EU and UK, and protected health information in the US, so a business associate agreement or equivalent is normally required before any tool touches it
LegalClient confidentiality and privilege, plus bar and regulator guidance on competence and supervision of AI output
FinanceRecord keeping, suitability and advice rules, plus model governance expectations from your supervisor
EducationStudent data protection, assessment integrity, and rules on automated decisions affecting a learner's progress
Public sectorProcurement rules, transparency duties, and in the EU the deployer obligations for higher risk systems

If you operate in the EU, or serve EU users, screening, scoring and monitoring of people carry specific duties. Hiring is the common example, and it is treated as a high risk use with documentation, human oversight and logging expectations attached. See high risk AI systems under the EU AI Act for what that means in practice, and AI in hiring for the employment case specifically. The duties that fall on the model providers themselves, rather than on you as the organization deploying a tool, are set out in the rules for general purpose models.

Make it stick

A policy nobody has read is decoration. Three things turn it into behavior. First, put the red list somewhere people see it while working, not only in a handbook: a pinned message, an intranet card, a line in the tool itself. Second, run one 20 minute session with real examples from your own work, including two that are genuinely ambiguous, and let people argue about them. Third, review the approved tool list every quarter, because vendors change terms and add features, and a stale list is how shadow use restarts.

What to do first

Write the red list this week, even if nothing else is ready, and send it round in a single message. It is the part that prevents the expensive mistakes, and it takes an hour. Then name one approved tool, because a policy with rules but no sanctioned option is the exact condition that produces the behavior described in AI at work and shadow AI. Before you sign for that tool, check the terms against the list in AI vendor contracts, particularly whether your data trains their models and how long it is kept.

Common questions

How long should the policy be?

One page of rules plus one page of examples is enough for most organizations under a few hundred people. If it runs past three pages, people will skim it once and never open it again, which defeats the point.

Do we need a separate policy or can we amend the ones we have?

Either works, but the data rules usually belong in your existing information security and data protection policies, so they are enforced by the same process. A short standalone AI page that cross references them is often the easiest to keep current.

What happens if someone breaks it?

Treat a first accidental breach as a training issue and fix the exposure: find out what was entered, ask the provider to delete it if the plan allows, and check whether it triggers a breach notification duty. Repeated deliberate misuse is a conduct matter like any other.

Should we let people use free consumer AI accounts?

Not for anything containing customer, employee or commercially sensitive information. Consumer tiers commonly retain conversations and may use them to improve the service, and you have no business agreement setting retention or deletion terms.