Find and read your employer's AI policy before you use AI at work
New to AI8 min readWorkplace AI for Individuals

Find and read your employer's AI policy before you use AI at work

Most people never actually locate their employer's AI use policy — they guess. A short guide to finding the real document (or confirming there isn't one), reading it for the parts that matter, and knowing who to ask when it is silent.

What you should be able to do

Before you use any AI tool for work, find your employer's actual policy document rather than guessing from what a colleague does or what industry norms suggest. If none exists, that silence is not permission — it is a question you still need to ask, in writing, before you paste in anything work-related.

Saved only in this browser.
In this article

Imagine a new hire whose teammates use AI tools but who has never been shown an approved-tool policy. Later, IT asks why customer data entered a personal account. The scenario is illustrative, but the control gap is real: peer behavior is not authorization.

That gap — between “nobody said no” and “this is actually approved” — is where most everyday AI-at-work mistakes start. The general safe rules are not the topic here; privacy and data hygiene at work already covers that. The topic is the narrower, more mechanical step that most people skip entirely: actually finding your own employer’s policy document, reading the parts that matter, and knowing what to do when it turns out there isn’t one.

What a workplace AI policy actually is

A usable policy is a specific, versioned document or intranet page with an accountable owner. It should identify approved tools and account configurations, permitted data, human-review and disclosure requirements, new-tool approval, incident reporting, and consequences. A colleague’s message or habit is not a substitute.

Organizations may publish this in an IT-security wiki, acceptable-use policy, employee handbook, procurement catalogue, or named approved-tool list. Record the title, owner, version or date, and link so you can tell whether the rule later changed.

Asking for that document is reasonable. EU AI Act Article 4 requires covered providers and deployers to take measures supporting sufficient AI literacy for staff and others operating AI systems on their behalf, taking context and risk into account (AI Act, Article 4). Whether and how that provision applies to an organization is a legal question; it does not itself authorize an employee to use a tool or data category.

Where to actually look

Before assuming there is no policy, check these places, in order:

  1. Your company’s intranet or employee handbook. Search for “AI,” “artificial intelligence,” “generative AI,” or the specific tool names (ChatGPT, Copilot, Gemini) — policies are sometimes filed under IT security or acceptable-use policy rather than a standalone AI section.
  2. IT or security’s approved-software list. Many companies maintain a list of sanctioned tools for any category, and AI tools increasingly appear there with a specific tier or configuration named.
  3. Your onboarding materials or most recent all-hands recording. AI policy announcements are often made once, in a meeting, and then never repeated — check if you missed one.
  4. Your manager. A direct, specific question — “is there an approved AI tool for our team, and is there anything I should not paste into it?” — gets a real answer faster than searching alone.
  5. IT or security directly. If the first four turn up nothing, ask the team responsible for tool approval by name, in writing, so the answer is on record.

Keep the answer in an approved work location with its title, owner, version or effective date, and link. Do not copy confidential policy material into a personal notes account. Re-check before a new data category, tool, account, or external deliverable.

The misconception that causes the most trouble

A damaging assumption is that silence equals permission: “nobody has told me not to use ChatGPT for this, so it must be fine.” If you cannot find authorization, treat sensitive data as not approved for the tool and ask the responsible owner before using AI on customer data, unreleased plans, financials, or another employee’s personal information. Silence does not establish either approval or prohibition; it leaves an unresolved control question.

The second common mistake runs the other way: assuming a policy that exists for one context covers every context. A company that has approved an enterprise AI tool for drafting internal memos has not necessarily approved it for customer-facing communication, for HR decisions, or for anything involving another employee’s data — read for scope, not just for the existence of a “yes.”

A concrete example

Two employees at the same mid-size company both want to use AI to help draft a client proposal. One searches the intranet, finds a page describing an enterprise-configured tool with a specific login, and uses that. The other assumes “AI is AI” and pastes the client’s contract details into their personal ChatGPT account, because a colleague on a different team does the same thing without apparent issue. Only one of these two has actually checked what their employer approved; the other is relying on an assumption that has not, for now, caused a visible problem. The difference is invisible until it isn’t — the moment an audit, a client complaint, or a data incident asks the question directly.

If you cannot find a clear answer for the exact tool and data class, keep customer data, other employees’ personal information, and confidential material out until an authorized owner answers in writing. In the EU, personal-data use must also fit the organization’s documented GDPR roles, purpose, legal basis, security, and processor arrangements; this article cannot determine those for a specific employer (GDPR). If an accidental paste already occurred, use the incident route rather than hiding or improvising a fix. See do not paste work secrets into consumer AI.

What a real policy usually specifies

When you find the document, read it for these controls rather than skimming for a general “AI is allowed” headline:

What to look forWhy it matters
Named approved tool(s)“AI is allowed” without a named tool tells you nothing usable
Required account, tenant, or configurationA brand name does not show whether a personal login or enterprise tenant is approved
Data categories that are prohibited or restrictedCustomer data, financials, source code, and HR data often have different rules from general drafting
The approval process for a new toolTells you what to do if the tool you want is not on the list yet
Required human review and prohibited decisionsIdentifies where output must be checked and where AI cannot be used at all
Disclosure requirementsWhether you need to tell your manager or a client when AI was used — see workplace AI disclosure, when it is required for the decision framework once you know your policy’s specific rule
Retention, records, and incident reportingTells you what must be logged and what to do after an accidental paste or unsafe output
Consequences for unapproved useA concrete sense of what is actually at stake, not just abstract risk

If the document omits material controls in this table, treat it as incomplete for the proposed use and ask the authorized policy owner for the missing answers.

If there genuinely is no policy

Some organizations have not written an AI-specific policy. That absence does not override existing security, confidentiality, privacy, acceptable-use, procurement, or client rules. In that situation:

  • Ask the authorized policy owner—often IT, security, privacy, legal, procurement, or a delegated manager—for a written decision on the exact tool, account, task, and data class.
  • Default to the most conservative reading for anything involving customer data, other people’s personal information, or confidential business information, regardless of how convenient a shortcut looks.
  • Put your question in writing (an email or a Slack message to a named person) so there is a record that you asked, rather than relying on a verbal answer you cannot point back to later.
  • If your role involves genuinely sensitive data on a regular basis, consider raising the absence of a policy as a specific, practical gap worth fixing — not as a complaint, but as a concrete ask: “can we get a one-page answer on which AI tool is approved for X kind of work?”

Find your policy this week

Use the workplace AI policy read card to actually locate your employer’s policy, log what it says about tools, data, and approval process, and note who to ask if any part is unclear. If it turns out there is no policy at all, the card also walks through the conservative-default questions to ask your manager directly. Either outcome is more useful than continuing to guess.

Sources and review boundary

This article locates policy controls; it does not interpret employment rights, contracts, GDPR roles, or the EU AI Act for a specific organization. Qualified employment, privacy, and legal review remains pending.

Read next

Continue through the same learning path with the next practical articles.