Skip to content

An AI Use Policy for Your Team: What Staff May and May Not Do With AI Tools at Work

  Posted on 31 Aug, 2026
  Artificial Intelligence
An AI Use Policy for Your Team: What Staff May and May Not Do With AI Tools at Work

If your company has not said anything about AI tools, your staff have still made a decision about them. Someone is drafting client emails in a chatbot on a personal account, someone else is summarizing a contract with a browser extension, and nobody knows which of those is fine. An AI use policy replaces that guesswork with a few clear rules.

It does not need to be long or written by a lawyer. For a small or mid-sized company, one page that people actually read does more than a twenty-page document nobody opens. Whether your team uses off-the-shelf chat tools or custom software development with AI built in, the questions are the same: which tools, with what data, and who checks the result.

This guide covers what the policy should say, how consumer and business plans handle your data, and how to roll it out. It is practical guidance, not legal advice.

Why a Small Company Needs a Written AI Policy

Large companies have security teams that block unapproved tools. Smaller ones rely on people using good judgment, and judgment needs something to work from. Without a written rule, each employee decides alone whether a customer list, a salary spreadsheet or a piece of source code is safe to paste into a chatbot. Most will guess reasonably. A few will not.

A written policy also protects staff. People who want to use AI well are often unsure whether they are allowed to, so they either avoid it or use it quietly. A short policy that says "yes, with these tools, within these limits" gets you more of the benefit and less of the hidden use.

Approved Tools and Accounts: Consumer vs Business Plans

The most important line in the policy is the list of approved tools and the type of account staff must use. The same product can treat your data very differently depending on the plan, so "we use tool X" is not specific enough.

How consumer plans typically handle data

On personal plans, the privacy choices belong to the individual user, not to your company. Anthropic states that chats on its consumer Claude plans (Free, Pro and Max) may be used to improve its models if the user chooses to allow it. Google's privacy notice for the consumer Gemini apps says that a subset of chats is reviewed by human reviewers and asks users not to enter confidential information they would not want a reviewer to see. A setting controls this, but each employee would have to change it on their own account, and you cannot check that they did.

How business plans typically handle data

Business plans put those controls in an administrator's hands and usually come with contractual commitments. Anthropic says that by default it does not use inputs or outputs from its commercial products to train its models, unless a customer explicitly submits feedback or opts in. Google says that Workspace customer data is not used to train models without the customer's permission on qualifying business editions. Microsoft says that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models in its Copilot for organizations.

These terms change, and they differ between providers and plans, so read the current page for the exact plan you pay for before you name it in the policy. The practical rule for staff is simple: work goes through company accounts only, never personal ones.

What Data Must Never Be Pasted In

A business plan reduces the risk; it does not remove the need for limits. The UK's National Cyber Security Centre advises organizations not to include sensitive information in queries to public AI models, and not to submit queries that would cause problems if they were made public. That is a good test to give staff. Then name the categories explicitly, because "sensitive" means different things to different people:

  • Passwords, API keys, access tokens and other credentials, in any tool, ever.
  • Personal data about customers, employees or job applicants, unless the tool is approved for it.
  • Anything covered by a client confidentiality agreement or NDA.
  • Unreleased financial results, pricing, legal matters and acquisition plans.
  • Source code and system designs, unless the tool is approved for engineering work.

If you handle health, payment or other regulated data, the rules that already apply to that data apply to AI tools too. US and UK requirements differ by sector and location, so check with whoever advises you on compliance instead of relying on a general policy.

Checking Output Before It Is Used

AI tools produce confident text that is sometimes wrong: an invented reference, a miscalculated figure, a clause that says the opposite of what was intended. The policy should state that the person who uses the output is responsible for it, exactly as if they had written it themselves.

Make the level of checking match the stakes. A rough internal summary needs a quick read. Anything sent to a customer, published, used in a financial or hiring decision, or deployed as code needs a proper review by someone qualified to spot the errors. Tools that take actions on their own, such as the systems described in our guide to what an AI agent is, need approval before they are connected to company systems at all.

Disclosure to Customers and Ownership of Work

Decide when customers are told that AI was involved. Many companies settle on two rules: a customer talking to an automated assistant is told it is not a person, and AI use on client deliverables follows whatever the client contract says. Some contracts restrict AI use or require disclosure, so staff need to know where to look before they start.

On ownership, state that work produced with AI tools during the job is company work product, handled like any other. Be aware that the legal position on AI-generated material is not settled. Microsoft, for example, says it does not claim ownership of Copilot output but also makes no determination on whether that output is protected by copyright. If you sell creative or software deliverables and promise clients full ownership, raise this with a lawyer.

How to Write It on One Page

Write in plain sentences, in the order people will need them. One page can hold all of this:

  • Approved tools, and the instruction to use company accounts only.
  • The never-paste list.
  • The review rule: you are responsible for what you use.
  • When to tell customers and how client contracts apply.
  • Who owns the work.
  • A named person to ask, and how to request a new tool.

That last line matters more than it looks. People work around a policy when asking permission is slow. Name one person, not a committee, and commit to answering new tool requests within a few days.

Common Mistakes to Avoid

The first is a blanket ban. It rarely stops use; it moves it onto personal phones and accounts where you have no visibility and the weakest data terms. The second is the opposite: approving a tool by name without specifying the plan, so staff sign up for the free version with a work email.

Other frequent problems are copying a large enterprise template that nobody reads, writing rules with no named owner, forgetting the AI features built into software you already use, such as email, meeting recorders and design tools, and treating the policy as finished once it is sent out.

What to Do Next: Rollout, Training and Review

Start by asking the team which tools they use today, with no penalty for honest answers. That list tells you what to approve, what to replace and where the real risks are. Then buy business accounts for the tools you approve, write the page, and walk through it in a short session using examples from your own work: this email is fine, this spreadsheet is not, and here is why.

Add the policy to onboarding for new hires, and set a review date. Every six months is a reasonable starting point, plus a review whenever you adopt a new tool or a provider changes its terms. The person named in the policy should own that review.

Conclusion

An AI use policy for your team is one page that answers six questions: which tools, which accounts, what data stays out, who checks the output, what customers are told, and who to ask. A short version written now is more useful than a perfect one next year, because your staff are making these decisions today either way.

If your team has outgrown off-the-shelf chat tools and you are considering an AI feature built around your own data and permissions, you can get in touch with us to talk through the options.

Entrant Technologies
Post written by
Entrant Technologies is one of the leading web, software, iPhone & Android app development company which deliver robust results for great brands worldwide. We deliver software solutions that meet the customers and business expectations.
View all posts by Entrant Technologies →
Latest Blogs
 
A software budget can go wrong before any code is written, at the moment someone prices and schedules a system that nobody has fully described yet. The discovery phase exists to close that gap. It is ...
on 06 Oct, 2026 Read More
 
Most growing businesses end up running four or five separate systems: a CRM for sales, accounting software for invoices, an online store, and something for stock, fulfillment or scheduling. Each works ...
on 05 Oct, 2026 Read More
 
A demo of an AI feature almost always looks good. Someone types five sensible questions, the answers read well, and the room agrees it is ready. Then real customers arrive with misspelled, half-explai ...
on 05 Oct, 2026 Read More