Important: This is a practical policy framework, not a substitute for legal, employment or data-protection advice tailored to your organisation.
The policy nobody read
A small professional-services firm had an AI policy. It was twelve pages long, written before the business adopted Microsoft Copilot and stored in a folder most employees could not find. Staff continued to use personal ChatGPT accounts because the policy never answered the question they actually had: “Can I paste this client email in?”
A policy only works when it changes behaviour. It must reflect the tools people really use and give clear answers at the moment of use.
Start with an approved-tools list
Name the tools and account types that are approved. “Use AI responsibly” is too vague. State whether personal accounts are allowed, whether browser extensions need approval and whether built-in AI features in CRM, HR or meeting software are covered.
Give one person or team responsibility for approving new tools. Otherwise shadow AI grows one free trial at a time.
Explain what must never be entered
Use examples employees recognise. Depending on your work, prohibited inputs may include client files, health information, payroll data, passwords, unpublished financial information, legal advice, children’s data or commercially sensitive source code.
The rule should also cover apparently harmless fragments. A name, email address and complaint pasted into a prompt can still be personal data. Removing a name does not always make information anonymous if the person remains identifiable from context.
Define where human judgement is mandatory
AI can draft, summarise and suggest. It should not silently make important decisions about recruitment, discipline, credit, insurance, access to services or legal rights. The policy should identify decisions that require a named human reviewer and explain what meaningful review involves.
A person clicking “approve” is not enough if they do not understand the recommendation, cannot challenge it or lack authority to choose differently.
Require checking and disclosure
Employees should verify factual claims, calculations, sources and professional advice before use. The policy should explain when customers or colleagues must be told that AI was involved—for example, direct chatbot interactions or relevant AI-generated content.
It should also address copyright, confidential information and impersonation. Never assume that generated text, images or code are automatically safe to publish.
Make incidents easy to report
People hide mistakes when reporting feels punitive. Give staff a simple route to report accidental data sharing, unsafe output, biased recommendations or an unapproved tool. Early reporting gives the business a chance to contain the problem and assess whether its data-breach procedure applies.
Plain-English takeaway
Write the policy for the person holding the prompt box.
Tell them what is approved, what must stay out, what needs checking and who to call when something goes wrong.
A practical policy structure
- Purpose and who the policy applies to.
- Approved tools, accounts and procurement route.
- Information that cannot be entered.
- Permitted and prohibited uses.
- Human-review requirements.
- Accuracy, bias, copyright and transparency checks.
- Security and access-control expectations.
- Incident reporting and escalation.
- Training, ownership and review dates.
Keep a record showing that the policy was issued, explained and reviewed. A signed document without practical training is weak evidence that staff understood it.
Official sources: EU AI Act ↗ · Irish DPC: AI, LLMs and data protection ↗ · European Commission AI Act overview ↗