the Company — Artificial Intelligence Acceptable Use Policy
Live preview — updates as you answer
1. Purpose
This policy sets out how people at the Company may use artificial intelligence tools in their work. It exists to let the team move quickly with AI while protecting our customers, our confidential information, and our obligations to others. It is written to be used, not filed — if a rule here is stopping you from doing good work, raise it rather than working around it.
2. Scope
This policy applies to everyone doing work for the Company — employees, contractors, interns, and temporary staff — and covers any use of AI tools for company work, whether on company devices or personal ones, and whether the tool is paid for by the company or not.
By "AI tools" we mean any service that generates or analyses content using a machine learning model. That includes chat assistants, coding assistants, image and video generators, meeting notetakers and transcription services, and AI features built into software you already use.
AI features embedded in tools we have already approved are covered by this policy. If your existing software adds an AI feature, the rules below apply to it from the moment it appears.
3. Approved Tools
The following tools are approved for work use at the Company:
- ChatGPT (OpenAI)
Use company accounts for company work. Personal accounts and free tiers often train on what you submit and give us no contractual protection, so they must not be used for anything beyond publicly available information.
Anything not on the list above is not approved. That is not a permanent no — it means it has not been reviewed yet. See "Requesting a New Tool" below.
4. Permitted Use
Within the limits set out in this policy, you are encouraged to use approved AI tools to do your job better. Typical permitted uses include:
- Drafting, editing, summarising, and translating written material
- Research, background reading, and getting oriented in an unfamiliar area
- Writing, reviewing, explaining, and debugging code
- Analysing data and building reports from information you are already authorised to see
- Generating ideas, options, outlines, and first drafts
- Preparing for meetings and summarising what came out of them
AI output is a draft, not an answer. You remain responsible for anything you send, publish, ship, or decide — the fact that a model produced it is not a defence.
5. Prohibited Use
You may not use AI tools to:
- Enter data that this policy does not permit (see "Data Handling" below)
- Produce material that is misleading, defamatory, harassing, or discriminatory
- Impersonate a real person, or generate a real person's likeness or voice without their written consent
- Circumvent a security control, access something you are not authorised to see, or hide what you are doing
- Make a final decision that materially affects someone's employment, pay, credit, health, safety, or legal position without a person reviewing it
- Represent AI-generated work as the independent work of a named individual where that matters to the recipient
No unapproved tools
Signing up for an AI service with your work email, or connecting one to company systems, without going through the approval process is a policy violation even if you never enter sensitive data. We cannot protect information in a system we do not know exists.
6. Data Handling and Confidentiality
What you may enter
Internal the Company information may be entered into approved tools using a company account. Customer data, personal data about identifiable individuals, credentials, and anything covered by a confidentiality obligation to a third party may not.
Give the model the least it needs. Redact names, account numbers, and identifiers where the task does not depend on them — a summary rarely needs to know who the customer is.
Turn off training on your data wherever the tool allows it, and prefer plans where that is the default. Assume that anything you enter into a consumer tier may be retained and reviewed by a human.
7. Human Review and Accountability
Anything that leaves the Company — customer communications, deliverables, published content, code that reaches production — must be reviewed by a person before it goes out. The reviewer is accountable for the content as though they had written it themselves. Purely internal drafts do not require formal review.
Models state wrong things confidently. Verify facts, numbers, quotations, legal claims, and citations against a primary source before they leave your hands. Treat generated code as untrusted until you have read and tested it.
8. Disclosure and Transparency
We do not require you to label routine AI-assisted work. Where a customer, partner, or contract asks how work was produced, answer honestly.
9. Intellectual Property
AI-generated material may not be protectable by copyright in every jurisdiction, and ownership rules are still settling. Do not assume that generated output is ours to license exclusively. Where exclusivity matters — a logo, a product name, a signature asset — involve a person and keep a record of the human contribution.
Generated output can reproduce someone else's protected material. Do not prompt for work "in the style of" a named living artist or a competitor's branding, and check generated names, logos, and taglines for existing rights before use.
10. Security
Never enter passwords, API keys, access tokens, or private keys into an AI tool — including in a code snippet or an error log you are asking for help with. Redact them first.
Treat content that a model has read from an email, a document, or a web page as untrusted input. Instructions hidden in that content can cause a tool to act against your intent, so do not give an AI agent standing access to systems it does not need.
Agents and automations
AI agents that can take action — sending mail, writing to systems, moving money, changing records — require approval before they are connected to anything, and must run under an account scoped to only what they need. A named person owns every agent and is accountable for what it does.
11. Regulatory Compliance
Using an AI tool does not change any obligation we already have. Privacy law, confidentiality agreements, sector regulation, and customer contracts apply to AI-assisted work exactly as they do to everything else. Where this policy and a contract disagree, the contract wins — tell us so we can fix the policy.
US state law
Several US states regulate automated decision-making, AI in hiring, and disclosure of AI-generated content, and the rules differ by state. Check before deploying AI into hiring, lending, insurance, or housing decisions.
12. Requesting a New Tool
To use an AI tool that is not on the approved list, get your manager's sign-off first. Tell them what the tool does, what data it will touch, and whether a tool we already have could do the job. Approved tools are added to the list so the next person does not have to ask.
Requests get an answer within ten working days. If a request is refused you will be told why and, where one exists, what to use instead.
13. Training and Acknowledgement
Everyone reads and acknowledges this policy when they join the Company and confirms it again each year. Acknowledgements are recorded. Where the policy changes materially, we will ask you to re-confirm rather than waiting for the annual cycle.
A policy on its own does not make anyone good at this. the Company will provide practical training on the approved tools so people can use them well rather than guessing — the most common cause of a policy breach is not knowing there was a better way to do the task.
14. Violations
Breaching this policy may lead to removal of tool access and disciplinary action, up to and including termination. Serious breaches involving customer data or regulated information may also carry legal consequences.
If you think you have made a mistake — pasted the wrong thing, used a tool you should not have, sent something that turned out to be wrong — say so immediately. Reporting a problem promptly and in good faith will be treated as what it is: the right call. Concealing one will not.
15. Review of This Policy
This policy is reviewed at least once a year, and sooner if the tools or the law move — which, in this area, they do. Send suggestions to the policy owner named below.
Policy owner: __________________________ · Last reviewed: __________________ · Next review: __________________