# Workplace AI Policy Read Card

Use with [Find and Read Your Employer's AI Policy Before You Use AI at Work](/articles/read-workplace-ai-policy-before-using).

## Step 1: Find the actual document

Check in this order and note what you found:

- [ ] Company intranet or employee handbook (search "AI," "artificial intelligence," "generative AI," and specific tool names)
- [ ] IT or security's approved-software list
- [ ] Onboarding materials or a past all-hands recording
- [ ] Direct question to your manager
- [ ] Direct question to IT/security, in writing

Where found: _______________________________________________

Date checked: ______________________________________________

## Step 2: Log what it actually says

| Question | Answer found | Source (link/page) |
| --- | --- | --- |
| Named approved tool(s) | | |
| Prohibited or restricted data categories | | |
| Approval process for a new tool | | |
| Disclosure requirements (to manager, client, etc.) | | |
| Consequences for unapproved use | | |

## Step 3: If any answer is missing or unclear

- [ ] Ask your manager directly and in writing.
- [ ] Ask IT/security directly and in writing, naming the specific question.
- [ ] Until you get an answer, treat customer data, other employees' personal information, and confidential business information as off-limits to any AI tool.

## Step 4: If there is genuinely no policy

- [ ] Confirmed with manager: no written policy exists.
- [ ] Agreed informal expectation (if any): ___________________________
- [ ] Defaulting to conservative rule for sensitive data until a policy exists.
- [ ] Considered raising the gap as a specific, concrete ask rather than a complaint.

## What this card does not do

It does not tell you what the safe general rules are — see [privacy and data hygiene at work](/articles/privacy-and-data-hygiene-at-work) for that — and it is not a substitute for asking a named person at your company when the written policy is silent or unclear.
