Document
AI Use Policy
— begins —
1. Purpose & scope
This policy sets out how people at [Company] may use artificial intelligence tools — including chat assistants, writing and image tools, coding assistants, and automation platforms — in their work. It applies to everyone who does work for [Company]: employees, contractors and anyone acting on our behalf. It covers AI tools we provide and AI tools staff use themselves for [Company] work. The aim is simple: get the benefit of these tools without putting client data, confidentiality or our reputation at risk.
2. Approved tools
Use the tools on our approved list for work tasks. As of [date], the approved tools are: [list, e.g. the paid team plans of specific assistants]. Paid business or team plans are preferred over free consumer accounts, because they generally offer clearer data-handling terms and let us turn off training on our data. If you want to use a tool that isn’t on the list, ask [approver] before putting any [Company] or client information into it. Free personal accounts should not be used for anything that includes client, customer or confidential information.
3. Acceptable use
AI tools are fine for drafting, summarising, brainstorming, rewriting, research starting points, and getting unstuck on technical work. Treat everything they produce as a first draft, not a finished answer. You are responsible for what you send, publish or ship under your name — check facts, figures and quotes before they leave the building, because these tools can state wrong things confidently. If a task requires professional judgement (legal, financial, medical, safety, HR decisions), AI can help you prepare but a qualified person makes the call.
4. What not to put into AI tools
Do not paste the following into any AI tool unless it is on our approved list and configured not to train on our data: client or customer personal information (names tied to contact details, financial details, health information, identity documents); confidential business information (contracts, pricing, unreleased plans, credentials or API keys); and anything covered by a confidentiality agreement. When in doubt, leave it out or ask [approver]. A safe default is to anonymise — remove names and identifying details before using a tool to help with a task.
5. Client & customer information
Handling personal information carries obligations under the Privacy Act, and those obligations don’t change because a tool is involved. Only put client or customer personal information into an approved tool that we’ve confirmed keeps it confidential and doesn’t use it to train public models. Don’t upload whole client databases or export sets of customer records into a tool for convenience. If a client has told us how their data may or may not be used, that instruction overrides this policy — follow it.
6. Disclosure
Be honest about AI’s involvement where it matters. If a client asks whether AI was used in work we did for them, answer truthfully. Where AI has materially produced something a client or customer would reasonably expect to be human-made — and being open about it is the fair thing to do — say so. Don’t present AI-generated work as bespoke human effort in a way that would mislead. Internal drafts don’t need a disclaimer; client-facing deliverables where the method matters do.
7. Human review & accountability
A person is accountable for every output that leaves [Company]. AI can draft it; a named human reviews and approves it. That means someone reads the email before it sends, checks the numbers before they go in the report, and tests the code before it ships. The tool is not the author and is never the excuse — “the AI wrote it” is not a defence for an error we send to a client. Build the review step into the task, not after the fact.
8. Prohibited uses
Do not use AI tools to: create or share content that is misleading, discriminatory, harassing or unlawful; impersonate a real person without their consent; generate work you then pass off as another person’s; bypass a client’s stated restrictions on AI use; or make final decisions about someone’s employment, credit, or access to a service without a human review. Don’t use AI to produce material we couldn’t stand behind if a client saw exactly how it was made.
9. Approvals — who signs off on what
[Approver, e.g. a named manager or director] owns this policy and the approved-tools list, and is the first point of contact for questions. New tools, new use cases involving client data, and any exception to this policy need their sign-off before you proceed. Team leads are responsible for making sure their people have read this policy and follow it. If you’re unsure whether something is allowed, the answer is to ask first, not to ask forgiveness.
10. Reviewing this policy
AI tools and their terms change quickly, so this policy is reviewed at least every [six/twelve] months, and sooner if a tool changes how it handles data or a new use case comes up. The current version and date live at [location]. When it changes materially, [approver] lets the team know. Suggestions to improve it are welcome — a policy people actually understand is worth more than one that’s technically complete and never read.
Not legal advice. This template is a starting point for internal use, not legal advice, and it isn’t tailored to your circumstances. Laws and tool terms change. Have it reviewed by someone qualified before you rely on it, and check it against your own obligations and any client agreements. [Company] and Better Automations accept no responsibility for how it’s used.
— ends —