What to Include in an Employee AI Use Policy

3–5 minutes

read

Illustration of an employee receiving practical guidance for using a business AI tool.

An employee has twenty minutes to finish a customer proposal. They open an AI tool, paste in part of a draft and ask it to improve the wording.

Whether that is an approved use depends on several details: the account, the information in the draft, the tool's access and the rules your company has established.

“Use AI responsibly” will not help the employee resolve those details.

I would write employee guidance around the decisions people need to make while doing their work. It should be easy to find and specific enough to use.

Describe approved uses, accounts and tools together

An approved product is not necessarily approved for every activity.

Specify the account or deployment that employees should use, the tasks permitted within it and the conditions attached to approval. Explain where staff can check the current list and how to request a new use.

For example, approval to edit public marketing copy should not be interpreted as approval to upload customer contracts or connect a shared drive.

If a tool adds a feature or integration, give people a route to ask whether the existing approval covers it.

Explain data rules in recognizable terms

Employees need examples they can relate to their role: public product information, unpublished pricing, customer contacts, support records, interview notes, source code and access credentials.

Your Security, privacy and legal owners should determine the relevant restrictions. The policy should translate those decisions into clear instructions for each approved use.

Do not rely on a slogan such as “no sensitive information.” Explain what the company considers sensitive and where to ask when the classification is unclear.

Also distinguish permission to access a document for one's job from permission to submit it to an external AI service. That second activity needs its own review.

Give employees an output review task

Illustrative scenario: A salesperson uses an approved assistant to draft a proposal from a standard product description. The draft adds a claim that the platform supports a particular integration.

The employee should have a clear instruction to verify product capabilities against approved information before sending the document. Reading for grammar alone would miss the issue.

NIST's Generative AI Profile identifies confidently presented false or erroneous content as a risk, often called hallucination or confabulation. Source: NIST AI 600-1, section 2.2.

The review checklist should fit the task. For a proposal, it might include features, pricing, customer references, commitments and confidentiality. For code, it would require an appropriate technical review. For decisions affecting people, involve the relevant specialists in defining the process.

Be clear about actions and integrations

Guidance should address more than prompts and text.

Can employees connect an assistant to email, meeting recordings, a document repository or a customer system? Can it send messages or change records? Who approves those permissions?

A useful policy tells staff when a new connection or automated action requires another review. It also identifies who can grant and revoke the access.

Product settings and organization-level controls should support the instructions wherever feasible. A policy is difficult to follow if the approved account and the unapproved account look identical in daily use.

Provide a reporting route that people can use

Tell employees what to do if they submit restricted information, receive a problematic output or notice an unexpected action.

They need a reachable contact, an immediate escalation route where appropriate and instructions for preserving useful details without spreading sensitive material further. Incident handlers should determine the correct response.

Avoid promising that deletion from a chat interface removes every copy from every system. Data handling and deletion capabilities need to be checked for the specific service and deployment.

A reporting instruction should encourage prompt disclosure so the right people can investigate.

Test the guidance with actual tasks

Before finalizing the document, ask several employees to work through realistic examples.

Can they decide which account to use? Can they recognize information that needs another review? Do they know who checks an unsupported claim and where to report a mistake?

Record points of confusion and improve the instructions. Training should include role-relevant examples and a way to ask questions after the session.

I would keep a concise quick-reference guide alongside the fuller policy. Give both an owner, version and review date. When approvals change, update the guidance and notify the affected teams.

Use the free readiness check to identify where employee guidance needs attention, or explore the assessment.

Related reading

Discover more from Ruchira Agrawal

Subscribe now to keep reading and get access to the full archive.

Continue reading