AI

Five practical rules for using generative AI at work

The AI Policy Playbook: 5 Critical Rules to Govern ChatGPT and Generative AI

Generative AI can help with first drafts, summaries and routine research. It can also expose confidential information, produce convincing errors and create uncertainty about who approved the final work.

A short policy gives staff clear boundaries. It does not need to predict every new AI tool. It needs to explain what is allowed, what is not allowed and who makes the final decision.

Rule 1: approve the tools and the uses

Decide which AI services staff may use for work. Free public tools, personal accounts and business plans can handle information differently, so staff should not choose a service based only on convenience.

The policy should list approved uses. Drafting a generic meeting agenda may be acceptable, while assessing a job applicant or giving a client financial advice may need a different process or may not be suitable at all.

Name the person who can approve a new tool or use. Without an owner, exceptions quickly become the policy.

Rule 2: keep confidential information out

Staff should not paste client records, passwords, private emails, contracts, health information, financial details or unpublished business material into an AI service unless the business has approved that service and that use.

Removing a person's name may not be enough if the remaining details can still identify them. When in doubt, use a made-up example or leave the information out.

Your policy should also cover files, images, meeting transcripts and audio. AI tools can receive sensitive information in more ways than a text prompt.

Rule 3: make a person responsible for the result

AI can state incorrect information with confidence. It can also miss context, copy a bias from its source material or produce wording that does not suit the business.

A person must check the result before it is sent, published or used to make a decision. That reviewer should confirm the facts, remove private information and make sure the work meets the same standard as anything written without AI.

The person using the output remains responsible for it. Saying that AI wrote it does not replace approval.

Rule 4: keep records that serve a clear purpose

Some uses need a record of the tool, reviewer and final decision. This can help with quality checks, complaints or work that affects a customer.

Do not collect every prompt by default. A prompt log can contain the same sensitive information the policy is trying to protect. Decide what records are needed, where they will be stored, who can access them and when they will be deleted.

For low-risk drafting, the final reviewed document may be enough. Higher-risk work may need a clearer record of the source material and approval.

Rule 5: review the policy and train staff

AI services and their terms change. The way staff use them will change too. Review the policy after a problem, when a new tool is introduced and at a regular interval chosen by the business.

Training should use examples from the workplace. Show staff what they can enter, what must stay out and how to check a result. Make it easy to ask before using AI for an unfamiliar task.

A simple policy checklist

A useful policy should answer these questions:

  • Which tools may staff use?
  • Which tasks are approved?
  • What information must never be entered?
  • Who reviews the output?
  • When is a record required?
  • Who approves exceptions and policy changes?
  • How can staff report a mistake or unintended disclosure?

Legal, privacy, employment and industry requirements vary. Ask an appropriate legal or compliance adviser about obligations that apply to your business.

Once the policy names the approved tools and uses, contact JCPIT to check the related business accounts, access and Microsoft 365 settings. The review stays on the technology controls. Legal, privacy and employment advice remains with the appropriate adviser.

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
How to Use a Password Manager and Virtual Cards for Zero-Risk Holiday Shopping
Next Article →
The hidden risk of integrations: a checklist for third-party apps