What it means
A sales team may use a chatbot to outline a proposal, while a payroll employee may be tempted to paste salary records into the same tool, and those are different risks. A useful policy lets people distinguish approved assistance from prohibited disclosure.
NIST's Generative AI Profile gives organisations a risk-management framework rather than a universal one-page policy, and the UK Information Commissioner's Office explains data-protection considerations for AI; its UK legal guidance is an example of jurisdiction-specific requirements, not a global rule for every business. Start with a list of permitted tools and account types, because personal accounts and company-controlled versions may have different terms and settings.
Name permitted tasks, such as brainstorming or summarising non-confidential material, and the uses that need extra review. Classify information before staff enter it into a tool, since public marketing text and confidential customer records must not be treated alike, and remember that a vendor promise about privacy does not replace review of its contract, retention settings, subprocessors and available controls.
Personal data needs attention to applicable law and company obligations, and the exact legal requirements depend on where the business operates and whose information it handles. Explain whether staff may upload customer, employee, financial, legal or unpublished product information, specify who can turn on integrations that connect tools to drives, email or customer systems, and define retention and deletion expectations where settings and contracts permit.
Require human review of material outputs, because fluent text may contain invented citations, inaccurate figures or claims unsupported by source records. For code, check security, licensing, tests and maintainability; for images and copy, review intellectual-property, consent, brand and contractual restrictions before external use.
Say when AI assistance must be disclosed to a customer, manager or reviewer, and keep accountability with the person and team that approve the final work, since a tool is not an authorised signer or a substitute for professional judgment. Set approval paths for high-stakes uses, such as employment decisions, medical content, financial advice or legal communications, and describe how staff verify factual claims: check original documents, current figures and named sources instead of citing a chatbot answer.
Set limits for automated publication or messages, because drafting assistance and sending unreviewed content are different permissions, and cover meetings and recordings so staff know when transcription or summarisation tools are allowed and when consent or notice may be required. Record incidents through the existing security and privacy process, because a mistaken upload should be reported promptly, not hidden because the employee fears blame.
Train staff on real examples, since a policy that no one understands tends to drive unapproved use underground. Assign an owner to approve tools and revise the policy because models, products and contractual terms change, and review logs or samples only where lawful and proportionate, explaining monitoring clearly rather than assuming employees expect it.
A blanket ban can be appropriate for a narrow sensitive workflow but may fail as a substitute for workable rules across the company, so measure adoption and incidents, not just signatures. For a small firm, a short table of approved tools, banned data, review duties and an escalation contact may be more usable than a long manual, while a larger organisation may need team-specific annexes with one common data and approval standard; when a use is unclear, pause the sensitive input or external release and ask the designated owner.
In practice
Real-world examples.
Example
A marketing employee drafts a public event description in an approved company AI account, then verifies every date, price and speaker name against the organiser's confirmation email. The text is reviewed by a colleague before it goes on the website. The tool saved drafting time, but a named person still owns the published result.
Example
A payroll employee needs help wording a letter about a pay adjustment. Instead of pasting identifiable salary records into an unapproved chatbot, the employee asks for a template using invented figures and completes the personal details by hand in the payroll system.
Example
An engineer in a software company uses generated code to speed up a small feature, then runs the full test suite and checks the licence terms of any suggested library before merging it into a customer-facing product. The pull request records that AI assistance was used, as the company policy requires.
Case study
Seen in the real world.
This fictional case follows Alder Services, an invented consultancy. A worker used an unapproved tool to summarise a client file, and a manager later noticed that the summary contained details that should not have left the client folder. Alder reported and assessed the exposure, introduced approved accounts, trained staff and added a review owner. The case is invented; no real outcome or legal remedy is claimed.
Alder's first draft policy was a one-line ban, and staff kept using personal accounts because they had no approved alternative. The revised policy listed approved tools, banned data types and an escalation contact, which gave employees a route that was quicker than working around the rules. Six months later the firm reviewed incident reports and adoption figures rather than counting signatures, and adjusted the policy where staff reported confusion.
Watch out
Common mistakes.
- Assuming a tool's privacy settings are identical across account types.
- Treating AI output as verified evidence.
- Writing a ban without giving staff a usable approval route.
Questions
People also ask.
Is one policy enough for every use?
A core policy helps, but high-risk teams may need specific rules.
Can staff paste customer data into approved tools?
Only if company permission, contract, settings and applicable obligations allow that use.
Who checks an AI-assisted document?
The accountable person or team checks facts, rights and suitability before release.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%