2. Scope
This policy covers every AI tool used for work, whether the company provided it or an individual adopted it - chatbots and assistants (ChatGPT, Claude, Copilot, Gemini), AI features inside other software (meeting summarizers, email drafters, code assistants), image/voice/video generators, and automated agents.
3. Approved tools only
- Use only AI tools on the company's approved list, under company accounts: [link to approved tool list].
- Never use personal AI accounts for work material. Personal accounts train on, retain, or expose company data outside company control.
- New tools - including AI features switched on inside tools we already use - require approval from [approver role] before use with work material.
4. Data you must never enter into an AI tool
- Client, customer, or patient personal information, account details, or deal terms.
- Confidential business information: source code, credentials, contracts, financials, product plans.
- Material non-public information of any kind.
- Anything you could not lawfully post publicly, unless the tool is explicitly approved for that data class.
5. You own the output
- AI output is a draft, never a deliverable. A qualified person must review AI-assisted work for accuracy, bias, and completeness before it leaves your hands.
- Never cite AI-generated facts, quotes, cases, or figures without independent verification. AI systems invent plausible-sounding falsehoods; professionals have been sanctioned for filing them.
- The person who sends, files, or publishes the work owns it - "the AI wrote it" is not a defense.
6. Prohibited uses
- No final decisions about people - hiring, promotion, discipline, termination, compensation, lending, housing - by AI alone. Automated tools may assist, but a person makes and documents the decision.
- No AI-generated voice, image, or video of a real person - colleague, executive, client, or anyone else - without their written consent and [approver role] approval.
- No using AI to impersonate, deceive, surveil coworkers, or bypass security controls.
- No entering another company's confidential information without authorization.
7. AI in hiring and people decisions
Federal agencies (EEOC, DOJ, CFPB, FTC) have stated jointly that existing anti-discrimination law applies in full to automated systems. If [Company] uses AI in recruiting, screening, or evaluation, [HR/legal owner] must confirm required bias audits and candidate notices (for example, NYC Local Law 144, Colorado SB26-189, Illinois AI Video Interview Act) before the tool is used.
8. Records and disclosure
- AI-generated notes, summaries, and communications that document business activity are company records - retain them under [records policy].
- Regulated teams: AI use does not change books-and-records or communications-retention obligations (SEC/FINRA rules apply to AI-assisted content the same as any other).
- Never claim AI capabilities the company does not have, internally or publicly. Regulators have fined firms for "AI washing."
9. Vendors
Before adopting a vendor product with AI features, [approver role] reviews what the AI does with our data, whether it trains on it, and what happens on renewal. A vendor's silent AI feature is our exposure.
10. Incidents
Report suspected AI misuse, data leakage into an AI tool, deepfake or impersonation attempts, and material AI errors to [security contact] immediately. Reporting a mistake fast is a win; hiding one is a violation.
11. Training
All employees complete AI safety training within [30] days of hire and annually thereafter. Completion, scores, and attestations are recorded and available to auditors and clients on request. (The EU AI Act makes AI literacy a legal duty for providers and deployers of AI systems; U.S. examiners increasingly ask for the same evidence.)
12. Enforcement and review
Violations may result in loss of AI tool access and discipline up to termination. [Owner role] reviews this policy quarterly against new law and new incidents, and re-issues it when either changes.
Effective date: [date] | Owner: [name, role] | Questions: [contact]