Staff are already using AI tools to draft emails, summarise meetings, or write code, whether or not there's a policy for it. The risk is specific: many free AI tools use what's typed into them to improve their models, which means anything pasted in could be stored, reviewed by a person, or surface in someone else's answer later.
Find out what's already happening
Before writing a policy, find out how people are actually using AI, as fact-finding, not as a way to catch anyone out.
- Which tools do they use day to day?
- What for: drafting, brainstorming, debugging code?
- Which of that is internal, and which touches client work?
Draw a clear line on what's off-limits
Never paste into a public AI tool:
- Personal data: names, addresses, anything that identifies a customer or employee.
- Customer contracts or other legal agreements.
- Passwords or any credentials.
- Real financial figures: revenue, margins, budgets.
- Proprietary source code.
Give people a safe way to use AI
Staff usually reach for the free tool because there's no approved alternative. Fix that:
- Pick one paid or enterprise tool with real privacy terms.
- Give people a workflow that lets them use AI for drafting and brainstorming without touching sensitive data.
- Keep a short list of tools that are actually approved.
Write it on one page
Five sections is enough:
- Allowed uses: what AI is fine for.
- Forbidden data: the list above, in plain language.
- Who to ask if someone isn't sure.
- What happens if the policy is ignored.
- A review date, since this will need revisiting.
Make the rule concrete, not abstract
Two examples people can actually use:
- Instead of pasting a client's full contract in to summarise it, paste a generic, anonymised description of what the contract is trying to achieve.
- Instead of pasting a raw sales spreadsheet, ask the tool to build a report template and fill in the real numbers yourself.
And one rule that applies to everything AI produces: it can state something confidently and be wrong. A person checks and edits anything AI writes before it goes out under the company's name.
A one-page policy that names what's off-limits and gives people a safe alternative is what actually gets followed, rather than one people work around.


