A workplace AI policy should tell people which tools and uses are approved, what data and actions are prohibited, when human review is mandatory, how output must be checked, and where to report incidents. Build it from actual tasks and risks, assign owners, train users, and review it as tools and obligations change.
Who this is for: Managers, operations leaders, security teams, and policy owners creating practical rules for employee use of generative AI.
- Write rules around concrete work situations so employees can recognize when they apply.
- Pair restrictions with approved alternatives, review paths, and a clear way to ask for exceptions.
- Treat policy as an operating system with owners, training, monitoring, and scheduled updates.
Map uses, people, and consequences
Inventory how staff already use AI and what they want to do next. Group uses such as brainstorming, drafting, summarization, code assistance, customer communication, analysis, and automated action. Identify affected people, data classes, decision authority, and possible harm for each use rather than writing from abstract fear or enthusiasm.
Involve security, privacy, legal, HR, IT, records, accessibility, and domain owners as appropriate. Consult workers who perform the tasks because they know where unofficial workarounds appear. NIST AI RMF functions can organize governance and risk discussions, but the final policy must fit the organization's real responsibilities.
Define tools, data, and use boundaries
Name the approved tool categories, account types, and access process. Define prohibited services and personal accounts for work data. Use a data classification table to show what may be entered, what requires special approval, and what is never allowed. Verify current provider terms for each approved environment.
Describe permitted and prohibited actions. Drafting an internal outline may be allowed while making an employment decision, issuing professional advice, impersonating a person, or executing an unapproved transaction may be prohibited. Avoid a vague sentence telling users to be responsible without examples or decision guidance.
Set review and disclosure duties
Assign human responsibility for factual checks, sources, confidential information, bias, intellectual property, accessibility, and final approval. Review intensity should match consequence. State that the user remains accountable even when an approved tool produced the draft. Define records that must be retained for important workflows.
Explain when AI assistance should be disclosed internally or externally based on policy, contract, professional norms, and audience expectations. Do not invent a universal disclosure rule. Provide a route for legal or communications review where the appropriate treatment depends on context.
Operate and improve the policy
Provide short role-specific training, an approved-tool directory, data examples, review checklists, and a contact for questions. Create a non-punitive incident channel for accidental data entry, harmful output, suspected prompt injection, or unauthorized action. Rapid reporting should trigger containment and investigation, not concealment.
Assign a policy owner, exception approver, review cadence, and change log. Monitor usage and incidents proportionately while respecting employee privacy. Update rules after tool, contract, law, business, or risk changes. Quarterly review is sensible for volatile AI services, with immediate review after a material incident.
Draft a policy for a 60-person agency
Employees use personal chat accounts for proposals, meeting notes, image concepts, and client research without shared rules.
- Interview teams and inventory tasks, data types, client obligations, tools, and current workarounds.
- Approve a managed environment for low-risk drafting and prohibit client secrets, credentials, and unapproved automated actions.
- Create task examples showing required source checks, client-review duties, image rights review, and manager escalation.
- Establish an exception form and incident channel with security, privacy, and account-management owners.
- Train staff using realistic scenarios, measure questions and incidents, and schedule a quarterly policy review.
Workplace AI policy outline
Use these sections as a policy drafting and review checklist.
- Scope and ownership: covered people, systems, work, policy owner, and exception authority.
- Approved environment: tools, accounts, access, data classes, retention, records, and prohibited services.
- Use rules: permitted tasks, forbidden actions, high-impact decisions, automation boundaries, and examples.
- Human duties: verification, specialist review, disclosure, approval, source records, and output handling.
- Operations: training, questions, incident reporting, monitoring, enforcement, change log, and review cadence.
Common mistakes
- Publishing a total ban without approved alternatives, then ignoring predictable shadow use.
- Naming one tool as safe for all data instead of defining account and data-class conditions.
- Copying a generic policy without assigning review, exception, incident, and update owners.
Try one
An employee wants to paste a confidential client contract into a personal AI account for summarization. Apply a practical policy decision.
The policy should prohibit the personal account and confidential upload, explain the data and account rules, and point to an approved contract-review path or authorized environment if one exists. It should require source checking and appropriate legal or account-owner review. Evaluation should include incident reporting if data was already entered, not merely tell the employee to delete the chat.
Sources
- NIST AI Risk Management FrameworkNIST framework for governing, mapping, measuring, and managing AI risk.
- NIST AI RMF PlaybookNIST suggested actions for applying the AI Risk Management Framework.