Draft an AI usage policy for employees. This is a working draft for internal review, not final legal language.
Context:
- Company: {{size, industry, and anything regulated about the business — e.g. 80-person healthtech, handles patient data}}
- Tools in use today, sanctioned or not: {{e.g. ChatGPT, Claude, Copilot, an internal chatbot, browser extensions people installed themselves}}
- Most sensitive data categories we handle: {{e.g. customer PII, source code, financials, client contracts}}
- Existing rules this must not contradict: {{security policy, client NDAs, regulatory obligations — or "none written down"}}
- Stance leadership wants: {{encourage-with-guardrails, or restrictive}}
Structure the draft as:
## What you can use AI for here
Start with the allowed uses, concretely. A policy that opens with prohibitions gets read as a ban and then ignored.
## Data rules by category
For each data category above: can it go into an external AI tool, only into approved tools, or never. Give a recognizable example of each category. This is the section people will consult mid-task, so it has to be scannable.
## Approved tools and how to request one
The current list, and the request path for a new tool. Name the owner.
## Where a human stays accountable
The outputs that need human review before they ship or get sent: {{e.g. anything customer-facing, code merged to production, legal or HR text}}. State plainly that "the AI wrote it" transfers no responsibility.
## Disclosure
When employees must say AI was involved, internally or to clients.
## What happens if this goes wrong
Reporting path for accidental data exposure, framed to encourage fast self-reporting rather than concealment.
Flag every clause where I need a real decision from legal or leadership with [DECISION NEEDED: ...] rather than inventing a position. Keep the whole draft under two pages; a policy nobody finishes protects nobody.policyai-governanceinternal-comms