Your staff are already using AI tools, whether or not you have said they can. A short policy tells them which tools are approved and what must never be pasted into them. One page that people read beats ten that they don't.

Start with what is allowed

Name the tools the business has approved and paid for. If you only say what is banned, people will use personal accounts and you will have no visibility at all.

Say what must not go in

Be specific: customer personal information, health or financial records, passwords, unreleased financials and anything covered by a confidentiality agreement. Give examples from your own business.

Explain why accounts matter

Free and personal accounts may use what is typed in to train their models. Business plans generally don't, and they give you admin control. This is the main reason to pay for licences.

Keep a person responsible

AI output can be wrong and can sound certain while being wrong. The person who sends the email or signs the report is responsible for checking it. Say so plainly.

Cover customer-facing use

Decide whether staff can use AI to write to customers, and whether you will tell customers when they are dealing with an AI. Check what your contracts and professional obligations say.

Deal with meeting recordings

AI note takers record and transcribe meetings. Set a rule about telling participants, about which tools may be used, and about where the transcripts are kept.

Make it easy to ask

Name someone staff can ask about a new tool. People follow a policy when getting a yes is easier than working around it.

Review it often

The tools change every few months. Review the policy twice a year and whenever you adopt something new.

Want AI tools rolled out with guardrails? Managed AI

All resources