The short version
- A prohibition produces shadow AI, not compliance. IBM's 2025 breach research found shadow AI involved in 20% of breaches and adding around $670,000 to the average cost.
- The rule that matters most is about input, not output: customer data, personal data, source code, unreleased financials and anything under an NDA do not go into a third-party tool.
- Vendor terms differ by plan, not by product. The same assistant may exclude business-tier data from training while retaining consumer-tier conversations for years.
- A confidentiality obligation owed to a client is not the employee's to waive. No individual can consent, on the company's behalf, to disclosing somebody else's information to a vendor.
The purpose of this document is not to make AI safe. It is to make the decision the same every time an employee faces it, so that the answer does not depend on who is asked and how busy they are. Everything below follows from that.
A ban does not stop the usage. It stops the visibility
This is the finding that should shape the whole document. IBM's 2025 Cost of a Data Breach research reported shadow AI — unsanctioned tool use by staff — as a factor in around 20% of breaches, adding roughly $670,000 to the average cost, and found that 97% of organisations reporting an AI-related breach had no proper access controls over AI. A majority of breached organisations either had no AI governance policy or were still writing one.
What each posture actually buys you
Prohibit it outright
- Usage moves to personal accounts
- Consumer terms apply, not yours
- No log of what was shared
- Nobody reports a mistake
Approve a small set
- Business-tier terms you have read
- Admin visibility and retention control
- A named route to add a tool
- Incidents surface early enough to fix
The choice is not between AI and no AI. It is between AI you can see and AI you cannot.
Say this out loud in the policy. Staff who understand that the rule exists to keep usage visible will report a bad paste. Staff who believe it is a trap will not, and the first you hear of it will be from the counterparty.
Name the tools, and name the route to add one
An approved list with no way to extend it is a ban with extra steps, and it goes stale within a quarter. The policy needs both halves: the tools that are cleared today, at which plan tier, for which categories of work — and a named person or inbox that requests go to, with a stated turnaround.
- The tool and the tier. "ChatGPT" is not an approval. The company workspace on a business plan is a different product, contractually, from the same assistant on a personal login.
- What it is cleared for. Drafting and summarising internal material is a different risk from processing customer records or generating code that ships.
- Who to ask. One route, a stated response time, and a public list of what has been approved and refused so the same request is not made twice.
- What triggers a re-review. A change in the vendor's terms, a new data type, or a move from pilot to production.
The rule that matters most is about what goes in
Output problems are visible and recoverable. Input problems are neither: once information has been sent to a third party, it has been disclosed, and no amount of deleting the chat afterwards undoes that. This is the part of the policy to make absolute rather than principled.
Never paste into a third-party tool
- Customer or client data of any kind, including anything that identifies them by inference.
- Personal data about employees, candidates or members of the public.
- Source code, configuration, credentials, keys or infrastructure detail.
- Unreleased financials, forecasts, board papers or anything price-sensitive.
- Anything received under an NDA or a confidentiality clause in a client contract.
- Legal advice, dispute correspondence, or material covered by privilege.
- Anything you would not put in an email to a supplier you have not vetted.
The test to apply before pasting
Does this text belong to someone other than us, or identify someone?
No — it is ours and it is generic
Approved tool, approved use. Review the output before it leaves your hands, and say where it came from if a client asked.
Yes — or you are not certain
Redact it until the answer is no, or use a tool the company has contracted for that specific data. Uncertainty is a request to the approval route, not a judgement call.
Handbook acknowledgment template
Full text, free. A policy nobody has signed for is hard to enforce and harder to rely on in a dismissal. This is the record that the version in force was issued, read and accepted.
Vendor terms differ by plan, and that is the whole question
Whether a conversation is used to train a model, and how long it is retained, is a contractual question decided by which plan the employee is logged into. It is not a property of the brand on the tab. Anthropic's consumer terms changed in August 2025 so that Free, Pro and Max users must choose whether their chats are used for training, with retention extending to five years where they allow it — and the change expressly did not apply to Team, Enterprise, API, government or education customers, who sit under commercial terms. Other vendors draw the line in the same place, at the same kind of boundary.
The second contractual question is who the vendor is to you. If personal data goes in, the vendor is likely acting as your processor, which brings a written contract, restrictions on sub-processors and a firm answer on where the data is held. A free consumer account has none of that, and no privacy policy you publish can honestly describe processing you never contracted for.
Nobody can waive somebody else's confidentiality
This is the obligation employees most often do not know they have. When a client shares information under an NDA or a confidentiality clause, the promise is the company's, and it usually limits disclosure to named categories of people for a defined purpose. A generative AI vendor is not in those categories. An employee pasting the material in has not exercised a judgement they were entitled to exercise — they have breached a contract the company signed.
Two fixes, both cheap. Say plainly in the policy that no individual may consent to disclosure on the company's behalf, and check what your own non-disclosure agreement and client contracts actually permit — many predate this question entirely and permit disclosure only to employees and professional advisers. Where you want headroom, negotiate it into new contracts rather than assuming it; the shape of that clause is covered in AI clauses in client contracts.
The person who sends it owns it
Accountability cannot be delegated to a tool, and the policy should say so in one sentence: output is the work of the employee who uses it, and is subject to the same review as anything they wrote themselves. Anything factual — a figure, a citation, a name, a date, a legal proposition — is unverified until a person has checked the source. The failure modes of confident, fluent, wrong output are set out in where AI legal advice fails, and they generalise well beyond legal work.
Disclosure to clients is a separate question, and a contractual one. Some agreements now require notice of AI use in deliverables; some prohibit it outright; most say nothing, in which case the safe default is that the client is entitled to a straight answer if they ask. Decide the house position once rather than leaving each account manager to improvise.
The seven sections a workable policy has
Workplace AI use policy
Who owns AI-assisted work, and what may not be protectable
Two different questions get merged here. Ownership as between employer and employee is a contract matter, and a well-drafted employment contract already assigns work created in the course of employment. Whether the output is protectable at all is a question of copyright law, and the answer is not automatically yes.
The US Copyright Office's January 2025 report on copyrightability concluded that entering a prompt is not authorship, however detailed the prompt, and that material generated wholly by a machine is outside copyright. Using AI as a tool does not undermine protection: where a person exercises creative control, selects, arranges or substantially modifies, the human contribution is protectable — but the AI-generated elements standing alone are not. The practical consequence is a record-keeping one, and the fuller treatment is in who owns AI-generated content.
Making it stick
Three mechanics do more than the drafting. Issue the policy through the handbook and take an acknowledgment, so there is a record of the version in force. Train against it: in the EU, Article 4 of the AI Act has required providers and deployers to ensure a sufficient level of AI literacy among their staff since 2 February 2025, and the Commission has confirmed it reaches organisations simply using generative tools for writing or translation. And review it on a date, not on an incident.
The test of the document is not whether it covers every case. It is whether an employee at 4pm on a Friday, holding a client email they would like summarised, can read one page and know the answer. If the policy cannot do that, it will be ignored in exactly the situation it was written for — and the usage will carry on somewhere you cannot see it.
Sources
- IBM Cost of a Data Breach Report 2025 — shadow AI findings
- Anthropic — updates to consumer terms and privacy policy (August 2025)
- US Copyright Office, Copyright and Artificial Intelligence Part 2 — analysis of the human authorship requirement
- European Commission — AI literacy questions and answers (Article 4, EU AI Act)
- EU AI Act obligations: mandatory training and prohibited practices
General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.
Frequently asked
Should we simply ban AI tools at work?
Rarely, and only where a sector rule forces it. A ban does not remove the usage; it moves it to personal accounts governed by consumer terms, with no admin visibility, no retention control and no incident reporting. IBM's 2025 breach research found unsanctioned AI use involved in about a fifth of breaches, at materially higher cost. A short approved list with a working request route is more enforceable than a prohibition nobody believes.
What should never be pasted into an AI tool?
Customer and client data, personal data about anyone, source code and credentials, unreleased financials, and anything received under an NDA or a confidentiality clause. The common thread is that the information is not yours to disclose. The practical habit is redaction: strip names, identifiers and figures until the prompt describes the problem rather than the party, which usually leaves the answer just as useful.
Does using AI mean our client work is no longer confidential?
It can, and that is the risk. Confidentiality clauses typically permit disclosure only to defined people for a defined purpose, and a third-party AI vendor is not usually among them. An employee cannot waive that obligation on the company's behalf. Check what your client contracts and NDAs permit before approving a tool, and negotiate express permission into new agreements rather than assuming it exists.
Do we own the output our staff generate with AI?
As between you and the employee, ownership normally follows the employment contract's assignment clause. Whether the output is protected by copyright is separate. The US Copyright Office concluded in January 2025 that prompts alone are not authorship and wholly machine-generated material is not copyrightable, though human selection, arrangement and substantial modification are. Keep a record of the human contribution for anything you may need to enforce.
Do we have to tell clients we used AI?
Only if a contract, a professional rule or a specific representation requires it. Many client agreements are silent, in which case the reasonable default is that the client is buying your judgement and is entitled to a straight answer if they ask. Decide a single house position, write it into the policy, and check whether any of your larger accounts have already imposed a stricter term.