Here is the uncomfortable part. If you employ more than about four people, somebody is already pasting work into an AI tool. Not maliciously. They are trying to get a job done, the tool is free, and nobody told them not to.
The Information Commissioner's Office is clear that using a third-party tool does not move your data protection obligations somewhere else. If an employee puts customer details into a free consumer account, that is your organisation processing personal data through a processor you never assessed. A policy will not make that risk vanish, but it will stop it happening by accident, and it will demonstrate you took reasonable steps if anyone asks.
This does not need to be a twenty-page document. One page is genuinely enough, and one page gets read.
The short version
- Name the tools you approve. Everything else needs a conversation first.
- Draw one bright line: what must never be pasted in, no exceptions.
- Say plainly that a person is accountable for anything AI helps produce.
- Give one named person to ask, and make asking easy.
- Put a review date on it. Six months.
The five things a policy has to answer
Everything else is padding. If your document answers these, it works.
- Which tools are approved? Vague permission produces twelve different tools and no oversight.
- What must never go in? The one rule everybody will actually remember.
- Who is responsible for the output? The person who sends it. Always.
- What has to be disclosed? To clients, to colleagues, in writing.
- Who do I ask? A name, not a department.
The template
Copy this, change the bracketed parts, and put it in the staff handbook. It is written to be read by everyone in the business, not by a lawyer.
[Company name]: Using AI at work
Version 1.0 · [date] · Review by [date + 6 months] · Owner: [name]
Why this exists. AI tools can save real time and we want people using them. This page sets out how to do that without putting our clients' information, or our reputation, at risk.
1. Approved tools. You may use [tool] and [tool] for work, on your [company account / business tier account]. If you want to use something else, ask [name] first. It is usually a yes, and it takes a day.
2. What never goes into an AI tool. Do not paste, upload or type any of the following into any AI tool, approved or not:
- Anything that identifies a client, customer, patient or employee: names, addresses, email addresses, phone numbers, account or reference numbers
- Health, financial or HR information about any individual
- Login details, passwords, API keys or card numbers
- Anything covered by a client NDA or marked confidential
- Unpublished commercial information: draft accounts, tender pricing, acquisition talks
If you need AI's help with something in this list, remove the identifying details first. "Draft a reply to a customer whose order is three weeks late" works perfectly well without the customer's name.
3. You own the output. AI produces first drafts, not finished work. Whoever sends it, publishes it or acts on it is responsible for it being correct. Check every fact, figure, name, date, quotation and legal statement before it leaves the building. "The AI wrote it" is not a defence and will not be treated as one.
4. Tell people when it matters. You do not need to declare that AI helped tidy up an internal email. You do need to say so if AI has materially produced something a client is paying us for, if a client has asked, or if their contract requires it. Never present AI-generated work as the output of a named person who did not write it.
5. Things that need a human decision. AI does not decide anything about a person's job, pay, discipline, recruitment, or their access to a service we provide. It can help you prepare. It does not make the call, and it must not be the only reason given for one.
6. If something goes wrong. If you think you have pasted in something you should not have, tell [name] the same day. Nobody is in trouble for reporting it quickly. People are in trouble for hiding it.
7. Ask. If you are not sure, ask [name] on [channel]. There are no daft questions here and everyone is learning this at the same time.
Three details worth getting right
Approve the right account tier, not just the right tool
"ChatGPT is approved" is not a complete instruction. The free consumer tier and the business tier have historically handled your data very differently, particularly on whether conversations are used for training. Naming the tool without naming the tier permits exactly the thing you were trying to prevent. This is covered in more detail in Is it safe to put company data into ChatGPT?, and the practical difference between tiers is in Free vs paid ChatGPT.
Make the safe path the easy path
If the approved tool requires a request form and a two-week wait, staff will use the free one on their phone. Buy the licences before you publish the policy. A policy that is more work than the workaround is a policy that documents your intentions rather than your practice.
Write the redaction habit into training, not just the policy
"Remove identifying details first" sounds obvious on paper and is not obvious at 4:30pm on a Friday. Show people what it looks like once and it sticks. There is more on making this stick across a team in How to train your team to use AI.
What to do this week
Realistically, an afternoon:
- Ask your team, without blame, which AI tools they are already using. Expect surprises.
- Pick one or two to approve, on business tiers, and buy the licences.
- Fill in the template above. Do not add to it.
- Spend fifteen minutes at a team meeting walking through the never-paste list with real examples from your own work.
- Diary the six-month review now.
That is it. It is not the most interesting afternoon you will spend this quarter, and it removes most of the risk that anyone will ever have to talk about.
If you want to see the redaction habit and the checking habit demonstrated on real work, the free AI Breakfast Club webinar runs online every other Friday morning, and the open floor afterwards is where the awkward governance questions usually come out.