Find and Read Your Employer's AI Policy Before You Use AI at Work
New to AI8 min readWorkplace AI for Individuals

Find and Read Your Employer's AI Policy Before You Use AI at Work

Most people never actually locate their employer's AI use policy — they guess. A short guide to finding the real document (or confirming there isn't one), reading it for the parts that matter, and knowing who to ask when it is silent.

What you should be able to do

Before you use any AI tool for work, find your employer's actual policy document rather than guessing from what a colleague does or what industry norms suggest. If none exists, that silence is not permission — it is a question you still need to ask, in writing, before you paste in anything work-related.

AI Expert TeamPublished: Jul 31, 2026
Saved only in this browser.
In this article

A new hire’s laptop arrives with ChatGPT already bookmarked by a teammate, a Slack channel full of people pasting meeting notes into a summarizer, and no one has ever mentioned a policy. Six months later, the same employee gets a terse email from IT security asking why a spreadsheet with customer names was uploaded to a personal AI account. Nobody told them not to. Nobody told them they could, either.

That gap — between “nobody said no” and “this is actually approved” — is where most everyday AI-at-work mistakes start. This article is not about what the safe rules generally are; privacy and data hygiene at work already covers that. This one is about the narrower, more mechanical step that most people skip entirely: actually finding your own employer’s policy document, reading the parts that matter, and knowing what to do when it turns out there isn’t one.

What a workplace AI policy actually is

A real policy is a specific, findable document or intranet page, usually produced by IT, security, legal, or HR, that answers four questions: which AI tools are approved for work use, what kinds of data may or may not go into them, what the approval process is for a new tool, and what happens if someone uses an unapproved tool anyway. It is not a Slack message someone sent once, not “what everyone on the team already does,” and not an assumption based on what your last employer allowed.

Companies that have gone through a real AI rollout usually publish this somewhere specific: an IT security wiki page, a section added to the employee handbook, or a named list of “approved AI tools” from procurement. If your company has one, it has a name, a location, and usually an owner you could email with a question.

Asking for that document is a reasonable request, not a nuisance one. Organizations in scope of the EU AI Act have to take measures to support the development of AI literacy among staff and others who operate or use AI systems on their behalf, though that obligation does not require them to guarantee any specific level of AI literacy in any individual (AI Act, Article 4, as replaced by Regulation (EU) 2026/1744). That is your employer’s obligation rather than yours, and it does not tell you what your own company’s rules are — but it does mean that “nobody has explained this to us” is a gap worth naming rather than working around.

Where to actually look

Before assuming there is no policy, check these places, in order:

  1. Your company’s intranet or employee handbook. Search for “AI,” “artificial intelligence,” “generative AI,” or the specific tool names (ChatGPT, Copilot, Gemini) — policies are sometimes filed under IT security or acceptable-use policy rather than a standalone AI section.
  2. IT or security’s approved-software list. Many companies maintain a list of sanctioned tools for any category, and AI tools increasingly appear there with a specific tier or configuration named.
  3. Your onboarding materials or most recent all-hands recording. AI policy announcements are often made once, in a meeting, and then never repeated — check if you missed one.
  4. Your manager. A direct, specific question — “is there an approved AI tool for our team, and is there anything I should not paste into it?” — gets a real answer faster than searching alone.
  5. IT or security directly. If the first four turn up nothing, ask the team responsible for tool approval by name, in writing, so the answer is on record.

Keep the answer somewhere you can find again — a bookmarked page, a saved email, a note in your own files. Policies get updated, links move, and “I read it once” is not the same as being able to point to what it said when a question comes up later.

The misconception that causes the most trouble

Far and away the most damaging assumption is that silence equals permission: “nobody has told me not to use ChatGPT for this, so it must be fine.” The opposite assumption is usually closer to correct. If a company has not published a clear AI policy, the safer working assumption is that nothing sensitive has been cleared for any AI tool yet, and you should ask before using AI on anything involving customer data, unreleased plans, financials, or another employee’s personal information. Silence usually means the organization has not caught up to the question, not that it has quietly decided everything is fine.

The second common mistake runs the other way: assuming a policy that exists for one context covers every context. A company that has approved an enterprise AI tool for drafting internal memos has not necessarily approved it for customer-facing communication, for HR decisions, or for anything involving another employee’s data — read for scope, not just for the existence of a “yes.”

A concrete example

Two employees at the same mid-size company both want to use AI to help draft a client proposal. One searches the intranet, finds a page describing an enterprise-configured tool with a specific login, and uses that. The other assumes “AI is AI” and pastes the client’s contract details into their personal ChatGPT account, because a colleague on a different team does the same thing without apparent issue. Only one of these two has actually checked what their employer approved; the other is relying on an assumption that happens, for now, to not have caused a visible problem. The difference is invisible until it isn’t — the moment an audit, a client complaint, or a data incident asks the question directly.

If you cannot find a clear answer about whether a specific AI tool is approved for a specific kind of data, treat customer data, other employees’ personal information, and anything marked confidential as off-limits to any AI tool until you get a direct answer in writing. In the EU this is not only an internal-policy question: sending customer or colleague personal data to an unapproved third-party tool is normally your employer’s processing to account for, under rules your employer is responsible for satisfying — though an employee who steps outside their employer’s instructions and uses the data for their own purposes can carry responsibility of their own (GDPR). That is a reason to ask before pasting, not a reason to panic after. This is the same discipline covered in more depth in do not paste work secrets into consumer AI — this article covers finding the rule, that one covers the specific line you should not cross while you wait for an answer.

What a real policy usually specifies

When you find the actual document, read it for these five things specifically, rather than skimming for a general “AI is allowed” headline:

What to look forWhy it matters
Named approved tool(s)“AI is allowed” without a named tool tells you nothing usable
Data categories that are prohibited or restrictedCustomer data, financials, source code, and HR data often have different rules from general drafting
The approval process for a new toolTells you what to do if the tool you want is not on the list yet
Disclosure requirementsWhether you need to tell your manager or a client when AI was used — see workplace AI disclosure, when it is required for the decision framework once you know your policy’s specific rule
Consequences for unapproved useA concrete sense of what is actually at stake, not just abstract risk

If the document you found answers none of these five questions specifically, it is likely a general statement of intent rather than an operational policy — a reasonable next step is asking your manager or IT directly for the specific answers it is missing.

If there genuinely is no policy

Some companies, especially smaller ones, have not written anything down yet. That is common and not, by itself, a red flag — but it does put more responsibility on you to ask rather than assume. In that situation:

  • Ask your manager directly whether there is an informal expectation, even if nothing is written.
  • Default to the most conservative reading for anything involving customer data, other people’s personal information, or confidential business information, regardless of how convenient a shortcut looks.
  • Put your question in writing (an email or a Slack message to a named person) so there is a record that you asked, rather than relying on a verbal answer you cannot point back to later.
  • If your role involves genuinely sensitive data on a regular basis, consider raising the absence of a policy as a specific, practical gap worth fixing — not as a complaint, but as a concrete ask: “can we get a one-page answer on which AI tool is approved for X kind of work?”

Find your policy this week

Use the workplace AI policy read card to actually locate your employer’s policy, log what it says about tools, data, and approval process, and note who to ask if any part is unclear. If it turns out there is no policy at all, the card also walks through the conservative-default questions to ask your manager directly. Either outcome is more useful than continuing to guess.

Read next

Continue through the same learning path with the next practical articles.