Here is a safe bet: someone in your business has pasted a customer email, a contract clause or a spreadsheet into a free AI tool this month to "tidy it up". They meant well. They also sent that data to a service you have no agreement with, no control over and no idea what it retains. That is not a reason to ban AI. It is a reason to write down the rules.
What a one-page policy covers
- Approved tools. Which AI tools staff may use for work — typically the business versions inside Microsoft 365, where data stays in your tenant and is not used for training.
- What never goes in. Customer personal data, patient information, financials, credentials, anything under NDA — unless the tool is on the approved list and the data classification allows it.
- Check before you trust. AI output is a draft. Numbers, dates, legal wording and anything sent to a customer gets a human check.
- Say when you used it. Not as confession — as good practice, so colleagues know what to review.
- Who to ask. A name, not a committee.
Making it real, not laminated
Give people an approved tool that is genuinely useful, and they will stop using the unapproved ones. Turn on the technical guardrails — sensitivity labels, data-loss prevention, sign-in policies — so the policy is enforced quietly rather than by memory. We set up both halves for customers on Microsoft 365: the approved tool, and the rails around it. The policy itself is a page; we are happy to send a template to start from.

