A workplace AI policy should answer the question employees actually have: Can I use this tool for this task, with this information, in this way?
Many policies describe principles but stop before the decision. They mention privacy, security, accuracy, and human oversight without explaining what a person should do on a Tuesday afternoon when an AI tool could save an hour.
The following sections turn those principles into usable policy choices.
Scope and ownership
State who the policy applies to, which work it covers, and who owns it. Include employees, contractors, temporary staff, and external collaborators where appropriate.
Name the team responsible for questions and approvals. “Contact the business” is not a route. “Ask the privacy team at this address” is.
Approved tools and accounts
List the tools people may use and whether they must use company-managed accounts. Explain how a new tool is reviewed and what someone should do when its status is unknown.
Do not rely on product names alone. Access level and account type can change the protections available to the organisation.
Information categories
Define information in words employees recognise. Useful categories might include:
- public information;
- ordinary internal material;
- personal or customer information;
- confidential business information;
- credentials, security details, or highly restricted records.
For each category, say whether it can enter an approved tool, requires approval, or must not be used.
Permitted and prohibited purposes
Examples help people map policy to work. Drafting, summarising, translating, brainstorming, coding, research, customer communication, recruitment, and automated decisions can carry very different consequences.
A prohibited-use section should be specific enough to guide behaviour. If high-impact decisions or unsupervised external publication are not permitted, say so directly.
Human review
Describe what review must happen before an output is relied upon or shared. The reviewer should have the knowledge and authority needed to correct or reject it.
Where the risk is higher, name the evidence that should be retained: the source checked, the approver, the date, or the final decision.
Regional coverage
An organisation may choose different rules for work connected to different regions. The policy should make clear which regions it covers and what happens when the location is unknown or outside that coverage.
Employees should not have to infer a jurisdiction from a customer’s email address. Include a clear route for uncertainty.
Outcomes and next steps
Each policy check should produce a direct result:
- continue with named safeguards;
- obtain approval from a named team;
- do not use AI for this task;
- provide more information before a decision can be made.
The explanation matters. A bare red or green label teaches nothing and makes exceptions harder to manage.
Versioning and records
Policies change as tools, contracts, laws, and company practices change. Preserve each published version and connect completed decisions to the version that produced them.
This avoids rewriting history. It also lets the organisation explain why an earlier check reached a different answer without pretending the old policy never existed.
Put the policy where the decision happens
A document remains important, but a document alone is easy to forget. Pair it with a short, task-specific check that asks only for facts that influence the answer.
Create a Can I Use AI? workspace to publish a workplace policy, guide employees through proposed AI uses, and keep a versioned record of completed checks.
This checklist is general operational guidance. It does not replace legal, privacy, security, employment, or sector-specific advice.