← AI AT WORK GUIDE
AI AT WORK GUIDE

The one-page AI policy your team needs

Your team is already using AI. Surveys keep finding half of employees using it without telling anyone, and the untold half is the risk: client data pasted into free chatbots, confident wrong answers shipped unreviewed. A policy doesn't create AI use; it makes the existing use safe and visible. One page is enough. Longer policies get skimmed once and forgotten. Here's the one-pager, section by section.

Section 1: approved tools

Name them specifically: which assistants, which accounts. The load-bearing distinction is company business accounts versus personal free accounts, because the business tiers carry the no-training-on-your-data terms and admin controls that free tiers don't (see the tool tiers). The sentence that matters: work happens in company AI accounts only. If you don't provide one, this section is where you start providing one, because the alternative isn't abstinence, it's shadow use.

Section 2: what never gets pasted

The data rules, concrete enough to act on:

Teach the redaction habit: strip identifiers, use placeholders, review AI output for a while, then decide. Most tasks work exactly as well on "Client A" as on the client's name.

Section 3: when a human reviews

The tiering that keeps quality incidents from becoming policy funerals: internal drafts and summaries, light review. Anything leaving the building with your name on it, full human review, no exceptions. Numbers, legal language, and commitments, verified against source, because AI states wrong figures with the same confidence as right ones. One clarifying rule: the person who sends it owns it. "The AI wrote it" is not a defense; it's an admission the review step got skipped.

Section 4: disclosure and the gray areas

Decide your stance on disclosure once, so nobody improvises: whether client deliverables mention AI assistance, and what to answer when a customer asks. Then name a person for gray-area questions. New tool someone wants to try, weird edge case, vendor pitching an "AI feature" that wants data access: route to that person instead of to guesswork. This is also the enforcement valve: the policy stays one page precisely because the edge cases have a human instead of a paragraph.

Rolling it out

Introduce it as permission, not prohibition: here are the tools, here's the paid account, here's the one meeting where we walk through it. Pair the policy with training on what AI is actually good at, because people follow rules they see the sense in. Revisit every six months; this field moves. And read the security risks alongside, because sections 1 and 2 are the direct countermeasures to the two most common incidents.

Want this handled instead of homeworked? That's the job.

Email us →
RELATED READING
AI security risks, in plain English AI at Work →
Picking AI tools: built-in, off-the-shelf, or custom AI at Work →
The whole AI at Work guide Pillar →

From the blog

ALL POSTS →
NO FORMS. JUST EMAIL.
mason@hurbs.io
or (832) 457-4317, LA and Houston