AI Usage Policy - [company name]
This policy applies to everyone working at [company name], whatever the contract: employees, contractors and subcontractors with access to our data.
01 AI tool register
At [company name] we use only the tools listed below. Adding a new one needs approval from [full name / role].
| Tool | What we use it for | Who has access | Type of data | Account |
|---|---|---|---|---|
| [e.g. ChatGPT] | [e.g. first drafts, summaries] | [e.g. marketing] | [e.g. public data only] | [company / personal] |
| [ ] | [ ] | [ ] | [ ] | [ ] |
We review the register every [period, e.g. quarter]. A tool nobody uses comes off the list and its access is revoked.
02 Permitted and prohibited uses
AI may be used for:
- [e.g. drafting text that a person then edits]
- [e.g. summarising our own meeting notes]
- [e.g. help with code that goes through review]
AI must not be used for:
- making decisions about people without a human in the loop: hiring, performance reviews, dismissal, granting or refusing a benefit
- [e.g. producing documents we sign as expert opinion]
- [ ]
A decision that affects someone's situation always belongs to a person. AI can prepare the material; it cannot make the final call.
03 Data rules
Never enter into an AI tool:
- personal data of clients, employees or candidates: names, addresses, phone numbers, ID numbers, anything copied from identity documents
- anything covered by trade secret protection: contracts, quotes, financial figures
- data our clients entrusted to us, unless our contract with them allows it
- code or configuration containing keys, passwords or access credentials
Before you paste anything, ask one question: would I show this to a stranger outside the company? If not, do not paste it.
When you genuinely need to work on real data, use [e.g. a tool on a company account with training on our data switched off], or strip the identifying details first.
04 Human review of the output
Every piece of work produced with AI is checked by a person before it leaves the company or becomes the basis of a decision. Check three things: whether the facts and figures hold, whether anything was lifted from someone else's work, and whether it sounds like us.
The person who sends or publishes the material is responsible for that check. Not the tool vendor, and not whoever asked the tool for it.
Language models state wrong answers with exactly the same confidence as right ones. Fluency is not evidence that something is true.
05 Labelling AI-generated content
We tell people when they are dealing with an AI system or with machine-generated content, in the situations the law covers:
- when a client is talking to a chatbot or a voice assistant rather than a person
- when we publish image, audio or video that was generated or significantly altered by AI and shows real people, places or events
We do not label every task done with AI. The fact that a text was drafted with a tool and then edited by a person does not trigger a labelling duty.
06 Skills and training
Anyone using AI at [company name] gets an introduction covering the rules in this document, the limits of the tools they work with, and how to report a problem.
| Who | Scope | Deadline | Record |
|---|---|---|---|
| [e.g. whole team] | [e.g. basics and data rules] | [date] | [attendance sheet] |
| [ ] | [ ] | [ ] | [ ] |
Keep a record of training. When a materially different tool arrives, run the introduction again.
07 Reporting incidents
Report immediately to [full name / address] if:
- data went into an AI tool that should not have
- work produced with AI contained an error and reached a client
- a tool behaved in a way you cannot explain
- you suspect someone gained access to our account in a tool
No one gets in trouble for reporting. Hiding it is the problem. An incident flagged within the hour can usually be undone; the same incident found a month later usually cannot.
We log reports with the date, what happened and what we did about it. Where personal data is involved, [full name] decides whether it must be reported to the supervisory authority within 72 hours.
08 Responsibility and review
| Area | Who is responsible |
|---|---|
| Tool register and approving new tools | [full name] |
| Training and its records | [full name] |
| Incidents and contact with the authority | [full name] |
| Reviewing this document | [full name] |
We review this document every [period, e.g. six months] and whenever a new tool arrives or the law changes. Put the review date at the top.
Breaking these rules is treated as a breach of employment duties. Before that, we check whether the rule was clear and whether the person had the introduction - if not, we fix the document and the training, not the person.
Approved by: [full name, role, date]