GuidesAI governance

An AI policy for employees: what to allow, what to forbid and how to say it

A short, usable policy for staff use of AI tools: what data may go in, which tools are approved, who checks the output and what to do when unsure.

AI audit · 3 min read · 10 October 2026

Your staff are already using AI tools. Some asked; most did not. A ban will not stop it. It will only make people stop mentioning it. What works is a short policy that says what is allowed, why, and where to ask.

A good one fits on a page and can be read in three minutes.

01What the policy must answer

  1. Which tools may be used for work.
  2. What information may never be entered into them.
  3. Who is responsible for what the tool produces.
  4. When the use of AI must be disclosed.
  5. Where to ask when unsure.

02Sort your information into three kinds

  • Public: already on your website. Any approved tool.
  • Internal: plans, drafts, routine correspondence. Approved tools only, with an account the company controls.
  • Restricted: customer data, personal data, prices, contracts, source code, anything under a confidentiality agreement. Only in systems the company runs or has specifically approved.

People follow a rule they can remember. Three kinds of data is a rule. A list of forty is not.

03Who is responsible for the output

The person who sends it. A tool does not sign anything. Whoever uses AI to draft an email, a report or a piece of code is responsible for its accuracy exactly as if they had written every word. Say this plainly; it settles most arguments before they start.

04What to forbid outright

  • Entering restricted data into an unapproved tool
  • Publishing AI output that has not been read by a person
  • Using AI to make a decision about a person without a human review
  • Passing off generated work as a customer's or a colleague's
  • Installing tools that record meetings or read mail without approval

05Make it easy to do the right thing

  • Provide an approved tool. People use unapproved ones when there is no approved one.
  • Name a person to ask, and answer within a day.
  • Run one short session showing good and bad uses with your own examples.
  • Review the policy twice a year. The tools change faster than that.

In short

  • A ban hides AI use; a one-page policy directs it.
  • Sort data into public, internal and restricted, and say which tools may see which.
  • The person who sends the output is responsible for it.
  • Provide an approved tool and a named person to ask.

Questions

Should we block AI tools on the company network?

Blocking without an alternative pushes the use onto personal phones, where you can see none of it. Offer an approved tool first.

Do we need a lawyer to write this?

A plain policy can be written by management. Have it reviewed if you handle regulated or personal data, because legal duties differ by country and sector.

How do we know if staff follow it?

Mostly by making it easy to follow and safe to ask. Technical controls help for restricted data; trust and clarity do the rest.

Can Quantum Beetle help write one?

Yes. The AI Audit looks at how AI is already being used in the business and what rules it needs.

Sounds like your problem?

Tell us about it. We'll say honestly whether the swarm can help, and what it would take.

Read next