Two things keep AI safe at work: a simple shared policy everyone understands, and a quick gut-check before anyone hits send. Both are below — adapt the policy to your org, and teach the four questions to your team.
Answer honestly. Anything in orange is worth a second look before you use the output.
Answer the four questions
Your verdict appears here as you go.
Use approved AI tools to draft, summarize, brainstorm, research, and speed up routine work. AI is a starting point, not the final word — you review and own what you ship.
Never paste customer data, personal information, passwords, financials, or anything under NDA into a public AI tool. When in doubt, leave it out or use an approved tool with the right data protections.
Treat every output as a confident first draft. Check facts, figures, names, quotes, and legal or medical claims against a reliable source before relying on them or sending them out.
Disclose AI use where it matters — e.g. client deliverables or published content — per our team norms. Don't present AI output as expert advice it isn't qualified to give.
AI doesn't make decisions; people do. The person who sends, publishes, or acts on an output is responsible for it, the same as any other work.
New use case, gray area, or a tool not on the approved list? Ask [name/role] before proceeding. It's always cheaper to ask first.
This is a plain-language starting point, not legal advice. Adapt it to your organization, fill in [the brackets], and have it reviewed by whoever owns compliance before you publish it.