Many teams are already experimenting with AI tools. A sensible response is not to pretend that is not happening. It is to give people clear boundaries, safe tasks to practise on and a simple route for questions or concerns.

Start small
Give people jobs that are useful but low consequence
Early use is often most helpful for preparing a first draft: turning rough notes into a clearer outline, proposing questions for a meeting, summarising a public document, suggesting a structure for a presentation or improving the tone of a non-sensitive message. The person using the tool remains responsible for checking facts, tone and suitability.
Do not start by asking a tool to send messages, approve spending, make hiring decisions or handle a complaint without a clear human review stage. The more a result affects a customer, employee or financial outcome, the more important it is to keep a person actively responsible.
Information
Be specific about what should not be pasted into a public tool
A simple policy should name the categories that need care: customer or employee personal information, passwords and access details, bank and payment data, confidential contracts, commercially sensitive plans and material protected by another party’s terms. Staff should not have to guess whether a real customer email or spreadsheet is safe to use.
Use approved business accounts and approved tools where the organisation has decided they are appropriate. The exact data-protection obligations depend on the business and its circumstances, so seek specialist advice where needed. The immediate operational rule is simpler: do not put information into an AI service unless you understand and have approved that use.
- Use approved accounts Avoid sharing work through a personal account or unapproved browser extension.
- Remove identifying detail Use a fictional example when practising a task that would otherwise include personal or confidential information.
- Check the answer Treat summaries, drafts and recommendations as material to review, not a finished decision.
- Ask when unsure Give staff a named person or route for questions instead of rewarding quiet workarounds.
A usable policy
Keep the first policy short enough to be used
A long policy that nobody reads will not make day-to-day work safer. Begin with a page covering approved tools, allowed tasks, restricted information, review responsibilities and where to raise a concern. Explain it with real examples from the team’s work rather than legalistic language.
Then make training practical. Ask staff to improve a routine internal update using made-up content, compare the result with their own version and point out what they would still need to check. That builds judgement rather than encouraging people to copy and paste blindly.
Keep learning
Review use as the team becomes more capable
The right boundary for an early drafting exercise is not necessarily the right boundary for a connected workflow months later. Revisit the policy when tools, access or business processes change. Look at the questions people keep asking; they are often a sign that the guidance needs an example or the process needs improvement.
Good governance should support useful work, not become a reason to stop learning. The aim is a team that can use AI where it helps and can explain when it is not appropriate.