Somewhere in your company today, an employee pasted something into an AI tool. Maybe it was a paragraph they wanted rewritten. Maybe it was a customer list they wanted sorted, or a contract they wanted summarized. If your company has no AI-use policy, that decision — what goes into which tool, under what account, with what data — was made by whoever was holding the keyboard.
We wrote separately about why employee NDAs and ChatGPT don’t always mix: confidentiality language drafted before generative AI existed may not clearly address an employee feeding information into a third-party tool. This article is the companion question: if the old language has a gap, what does the document that closes it look like?
This is general information, not legal advice. What any company’s policy should say depends on its data, tools, industry, workforce, and the law that applies to it.
Start With What Is Actually Happening
Before a policy can say “yes,” “no,” or “only like this,” someone has to find out what tools are in use. The practical first questions:
- Which AI tools do employees already use — and under personal accounts or company accounts? A policy written for an imagined workplace fails in the real one.
- What kinds of information have been going in? Marketing copy is one conversation; customer data, source code, financials, or anything covered by an NDA is another.
- Do any customer or vendor contracts you have signed say anything about AI use, confidentiality, or data handling that your own team’s tool use could implicate?
The Questions a Workplace AI-Use Policy Should Answer
A useful policy is a set of clear answers, not a ban and not a shrug. The core questions to work through with counsel:
- Which tools, which tiers? Consumer AI accounts and enterprise AI accounts often handle data differently. Does the policy name approved tools and account types — and a path for employees to request new ones?
- What may never go in? Most policies define categories: information covered by customer NDAs, personal information about employees or customers, source code, credentials, unreleased financials. What belongs on your list is a judgment call the policy should make explicitly.
- Who reviews AI output before it ships? If AI-drafted text reaches customers, contracts, or code, the policy should say who is responsible for checking it and what “checked” means.
- How does it interact with the documents you already have? Confidentiality agreements, handbooks, IT and security policies, and customer contracts all touch the same territory. Do they say consistent things once the AI policy exists?
- What happens when the policy is broken? Consistent enforcement is part of what makes a policy meaningful in practice. What is the escalation path, and who owns it?
- Who keeps it current? Tools change quarterly. Does someone own reviewing the policy on a schedule, or does it decay the way the pre-AI confidentiality language did?
A Policy Is a Document, but Adoption Is a Process
The companies that do this well treat the policy as the middle step, not the whole step: inventory first, policy second, then training and the account and tooling changes that make the approved path the easy path. A policy that says “use the enterprise account” only works if the enterprise account exists and someone turned on the right settings.
How Accord & Shield Legal Can Help
We draft and review workplace policies — including AI-use policies — alongside the employee handbooks, confidentiality agreements, and employment documentation they have to agree with, for companies in Arizona, California, and Texas. This work sits within our employment counsel and AI governance practices. Not sure whether your AI use raises questions worth reviewing? Our AI Governance Readiness Check is a free, plain-language self-assessment. Attorneys at Accord & Shield Legal, PLLC are admitted in Arizona, California, and Texas. Whether the firm may accept a matter depends on the facts, applicable law, jurisdiction, conflicts review, attorney availability, and a written engagement agreement.
Frequently asked questions
Do we need an AI policy if we already have NDAs and a handbook?
That depends on what those documents actually say. Many were drafted before generative AI tools existed, and the practical question is whether an employee reading them would know what they may and may not put into an AI tool. If the answer is not obvious, that is the gap an AI-use policy addresses.
Should we just ban AI tools?
A ban is a policy choice some companies make. The tradeoff to weigh: bans are simple to write and hard to police, and employees who find the tools useful may keep using them invisibly, on personal accounts — the outcome with the least company control.
What is the difference between using consumer and enterprise AI accounts?
Different accounts may be governed by different terms. What a provider may do with what employees submit is a question to answer from the provider’s own current terms for the specific account in use — not from a marketing page — which is why tool selection belongs in the policy conversation.
Who inside the company should own the AI policy?
Someone specific. The pattern that fails is everyone assuming someone else owns it. Whether it sits with legal counsel, HR, IT, or a founder depends on the company’s size — the policy should name the owner either way.