1. Purpose and scope
This policy covers every use of generative AI tools for work, on any device, including personal accounts used for work tasks.
- It applies to all employees, contractors and interns.
- It covers text, image, audio, video and code generation, and any assistant built on top of them.
- Where a client contract sets stricter rules, the contract wins.
2. Approved tools
Only tools on the approved list may be used with company information. Anything else needs a short review first.
- The approved list names the tool, the plan we pay for, the owner and what it may be used for.
- Requesting a new tool means naming the task it solves and the data it would see; the owner responds within five working days.
- Free personal accounts may not be used for company work, because the data terms differ from our paid plans.
- Browser extensions and unofficial clients that proxy our data through a third party are not approved.
3. What may never go into a tool
Treat every prompt as if it could be read by someone outside the company.
- Never paste in: customer records or personal data, health or ID data, credentials, keys or tokens.
- Never paste in: unreleased financials, salary or HR case detail, legal advice, or anything under NDA.
- Never paste in: source code from repositories marked restricted, or third-party code we are not licensed to share.
- Anonymise examples instead: replace real names, account numbers and addresses with placeholders.
- Where a tool offers a setting to exclude your input from model training, it must be switched off and the decision recorded per tool.
4. Human review
AI drafts. People remain accountable for what leaves the company.
- Anything that reaches a customer, a regulator, a contract or a public channel needs a named human reviewer before it goes out.
- Facts, figures, quotes, citations and legal or medical statements must be checked against a primary source.
- Generated code must pass the normal review and test process; no exceptions for speed.
- Decisions about people — hiring, performance, discipline, credit or access — may not be made by a tool, only informed by one.
5. Transparency and attribution
Colleagues and customers should be able to tell where AI was involved.
- Label AI-assisted drafts internally so reviewers know to check harder.
- Disclose AI use to customers where they would reasonably expect a person, such as support conversations.
- Do not present generated images or voices as real people, events or endorsements.
- Respect third-party rights: do not prompt for a living artist's style or a competitor's protected material for published work.
6. Accounts, access and spend
AI tools are treated like any other business system.
- Accounts use company email with single sign-on where the plan supports it, and are removed when someone leaves.
- Seats are reviewed monthly; unused paid seats are cancelled.
- API keys live in the company secret store, never in code, documents or chat messages.
- Each approved tool has one named owner who answers questions and watches for pricing or terms changes.
7. When something goes wrong
Mistakes are expected. Hiding them is the problem.
- Report a suspected data disclosure to the policy owner the same day; there is no penalty for reporting promptly.
- Report material errors that reached a customer so the correction and the cause can be recorded.
- The policy owner keeps a short log of incidents and what changed as a result.
- Repeated deliberate breaches are handled under the normal disciplinary process.
8. Ownership and review
This policy is short on purpose so it can stay current.
- Owner: [name, role]. Approved by: [name, role]. Version 1.0, dated [date].
- Reviewed every quarter alongside the approved tool list and the spend review.
- Every employee confirms they have read it at onboarding and after each material change.