Guides · Updated 2026-09-06

Generative AI Policy for Employees: 10 Plain-English Rules

Most employees do not read policies; they read the summary and remember the rules that were explained to them by a person. A generative AI policy for employees therefore needs two layers: a full document that HR and management can rely on, and a single page of rules that everyone actually knows. This guide focuses on that second layer, the rules themselves, and the questions staff ask most often when they are first written down.

The free generator writes both the full employee policy and the one-page summary of rules, ready to circulate and sign.Start the free generator

What you can and cannot paste into an AI tool

The single most important rule concerns input. Whatever you type or upload into a generative AI tool leaves your control, and on many consumer plans it may be stored, reviewed by the vendor or used to train future models. The employee version of this rule should be concrete: if it is public or purely internal and contains no personal or client data, you may use it in an approved tool. If it is confidential, use it only in the approved company-managed tool that the policy names for that purpose. If it contains personal data about identifiable people, financial account details, credentials, health information or anything under an NDA, do not paste it into any AI tool without written approval.

A useful habit is to anonymise before you prompt. Replace names with roles, strip account numbers, and describe the situation rather than pasting the document. Most drafting and summarising tasks work just as well with the sensitive details removed, and removing them takes seconds.

Personal accounts versus company accounts

Company work should be done on company-managed AI accounts. Company accounts let the business turn off training on inputs, apply retention settings, enforce multi-factor authentication and remove access when someone leaves. Personal accounts do none of that, and they mean the business cannot answer a client who asks where their data went. If your employer has not provided a company account for a tool you need, ask for one rather than using your own.

The reverse also matters. Do not log into personal AI accounts on company devices for personal use in a way that mixes the two, and never store company outputs in a personal account's history where they will outlive your employment.

Verification: AI output is a draft, not an answer

Generative tools produce fluent, confident text that is sometimes wrong. They invent citations, misstate figures, produce code that does not run and summarise documents in ways that drop the one clause that mattered. The rule is simple: you are responsible for anything you send, publish or act on, whether or not AI drafted it. Check facts against the source. Check numbers by recalculating. Run the code. Read the summary against the original if the decision matters.

For anything that goes to a client, a regulator or the public, a second pair of human eyes should see it. That is not a comment on the tool; it is the same standard that applies to any first draft.

Labelling and disclosure

Be honest about AI use where it is relevant. Internally, that means telling a colleague when a document was AI-drafted so they know to check it. Externally, it means following the disclosure rules in the policy: AI-generated images, audio and video that could be mistaken for real should be labelled, chatbots should say they are automated, and clients who have asked about AI use in their work should get a straight answer. In the EU these are legal requirements under the AI Act, not just good manners.

The 10 rules to put on one page

These ten rules are written to be pinned to a wall or pasted into an onboarding message. Adjust the tool names and data categories to match your own policy.

  • Use only the AI tools on the approved list, on a company-managed account.
  • Never enter personal data, client confidential information, credentials or anything under an NDA into an AI tool unless the policy specifically permits it for that tool.
  • Anonymise before you prompt: remove names, account numbers and identifying details.
  • Treat every AI output as a first draft. Verify facts, figures, citations and code before you rely on them.
  • You own what you send. AI drafted it is never an excuse.
  • Tell colleagues when a document was AI-drafted so they know to review it.
  • Label AI-generated images, audio and video, and make sure chatbots identify themselves as automated.
  • Do not use AI to make or recommend decisions about individuals (hiring, credit, discipline) without documented human review.
  • Do not connect AI tools to company systems, files or email without approval from the policy owner.
  • If something goes wrong, report it the same day. Early reports are treated as learning, not blame.

Training that actually changes behaviour

A policy without training is a document; a policy with training is a practice. The most effective sessions for employees are short, practical and built around real examples from your own business. Show a good prompt and a bad one. Show an output with a fabricated citation and ask the room to find it. Walk through the data classification table with three examples that sit near the line. Thirty to forty-five minutes, once at onboarding and once a year, is enough for most roles.

Record who attended and when. In the EU, the AI Act requires employers to ensure staff have sufficient AI literacy, and attendance records are the simplest evidence. Outside the EU, the same records answer insurers and client auditors.

Frequently asked questions

Can I use AI to write emails to clients?
Usually yes, provided you do not paste confidential client details into a tool that is not approved for confidential data, and you read and correct the draft before sending. You remain the author.
What if I already used a personal account for work?
Tell the policy owner, delete the relevant conversation history from the personal account, and move to a company account. Honest disclosure of past use is exactly what the incident reporting rule is for.
Are AI features inside our existing software covered?
Yes. Assistants built into email, documents, CRM and design tools are AI tools. Check the register to see whether they are approved and what data they may touch.
Do I have to tell a client that I used AI?
Follow the policy and the client contract. If the client has asked about AI use, answer honestly. If content is a deepfake or an AI-generated image of a real subject, label it. For routine drafting, disclosure is generally not required unless your contract or the client says otherwise.
What counts as an AI incident that I should report?
Sensitive data entered into an unapproved tool, an AI-generated error that reached a client or the public, an output that was discriminatory or defamatory, or a tool behaving in an unexpected way with company systems. When in doubt, report.

Generate your own in about four minutes

The free generator writes both the full employee policy and the one-page summary of rules, ready to circulate and sign.

Generate my policy free

Related guides

This guide is general information, not legal advice.