Imagine a new hire whose teammates use AI tools but who has never been shown an approved-tool policy. Later, IT asks why customer data entered a personal account. The scenario is illustrative, but the control gap is real: peer behavior is not authorization.
That gap — between “nobody said no” and “this is actually approved” — is where most everyday AI-at-work mistakes start. The general safe rules are not the topic here; privacy and data hygiene at work already covers that. The topic is the narrower, more mechanical step that most people skip entirely: actually finding your own employer’s policy document, reading the parts that matter, and knowing what to do when it turns out there isn’t one.
What a workplace AI policy actually is
A usable policy is a specific, versioned document or intranet page with an accountable owner. It should identify approved tools and account configurations, permitted data, human-review and disclosure requirements, new-tool approval, incident reporting, and consequences. A colleague’s message or habit is not a substitute.
Organizations may publish this in an IT-security wiki, acceptable-use policy, employee handbook, procurement catalogue, or named approved-tool list. Record the title, owner, version or date, and link so you can tell whether the rule later changed.
Asking for that document is reasonable. EU AI Act Article 4 requires covered providers and deployers to take measures supporting sufficient AI literacy for staff and others operating AI systems on their behalf, taking context and risk into account (AI Act, Article 4). Whether and how that provision applies to an organization is a legal question; it does not itself authorize an employee to use a tool or data category.
Where to actually look
Before assuming there is no policy, check these places, in order:
- Your company’s intranet or employee handbook. Search for “AI,” “artificial intelligence,” “generative AI,” or the specific tool names (ChatGPT, Copilot, Gemini) — policies are sometimes filed under IT security or acceptable-use policy rather than a standalone AI section.
- IT or security’s approved-software list. Many companies maintain a list of sanctioned tools for any category, and AI tools increasingly appear there with a specific tier or configuration named.
- Your onboarding materials or most recent all-hands recording. AI policy announcements are often made once, in a meeting, and then never repeated — check if you missed one.
- Your manager. A direct, specific question — “is there an approved AI tool for our team, and is there anything I should not paste into it?” — gets a real answer faster than searching alone.
- IT or security directly. If the first four turn up nothing, ask the team responsible for tool approval by name, in writing, so the answer is on record.
Keep the answer in an approved work location with its title, owner, version or effective date, and link. Do not copy confidential policy material into a personal notes account. Re-check before a new data category, tool, account, or external deliverable.
The misconception that causes the most trouble
A damaging assumption is that silence equals permission: “nobody has told me not to use ChatGPT for this, so it must be fine.” If you cannot find authorization, treat sensitive data as not approved for the tool and ask the responsible owner before using AI on customer data, unreleased plans, financials, or another employee’s personal information. Silence does not establish either approval or prohibition; it leaves an unresolved control question.
The second common mistake runs the other way: assuming a policy that exists for one context covers every context. A company that has approved an enterprise AI tool for drafting internal memos has not necessarily approved it for customer-facing communication, for HR decisions, or for anything involving another employee’s data — read for scope, not just for the existence of a “yes.”
A concrete example
Two employees at the same mid-size company both want to use AI to help draft a client proposal. One searches the intranet, finds a page describing an enterprise-configured tool with a specific login, and uses that. The other assumes “AI is AI” and pastes the client’s contract details into their personal ChatGPT account, because a colleague on a different team does the same thing without apparent issue. Only one of these two has actually checked what their employer approved; the other is relying on an assumption that has not, for now, caused a visible problem. The difference is invisible until it isn’t — the moment an audit, a client complaint, or a data incident asks the question directly.
If you cannot find a clear answer for the exact tool and data class, keep customer data, other employees’ personal information, and confidential material out until an authorized owner answers in writing. In the EU, personal-data use must also fit the organization’s documented GDPR roles, purpose, legal basis, security, and processor arrangements; this article cannot determine those for a specific employer (GDPR). If an accidental paste already occurred, use the incident route rather than hiding or improvising a fix. See do not paste work secrets into consumer AI.
What a real policy usually specifies
When you find the document, read it for these controls rather than skimming for a general “AI is allowed” headline:
| What to look for | Why it matters |
|---|---|
| Named approved tool(s) | “AI is allowed” without a named tool tells you nothing usable |
| Required account, tenant, or configuration | A brand name does not show whether a personal login or enterprise tenant is approved |
| Data categories that are prohibited or restricted | Customer data, financials, source code, and HR data often have different rules from general drafting |
| The approval process for a new tool | Tells you what to do if the tool you want is not on the list yet |
| Required human review and prohibited decisions | Identifies where output must be checked and where AI cannot be used at all |
| Disclosure requirements | Whether you need to tell your manager or a client when AI was used — see workplace AI disclosure, when it is required for the decision framework once you know your policy’s specific rule |
| Retention, records, and incident reporting | Tells you what must be logged and what to do after an accidental paste or unsafe output |
| Consequences for unapproved use | A concrete sense of what is actually at stake, not just abstract risk |
If the document omits material controls in this table, treat it as incomplete for the proposed use and ask the authorized policy owner for the missing answers.
If there genuinely is no policy
Some organizations have not written an AI-specific policy. That absence does not override existing security, confidentiality, privacy, acceptable-use, procurement, or client rules. In that situation:
- Ask the authorized policy owner—often IT, security, privacy, legal, procurement, or a delegated manager—for a written decision on the exact tool, account, task, and data class.
- Default to the most conservative reading for anything involving customer data, other people’s personal information, or confidential business information, regardless of how convenient a shortcut looks.
- Put your question in writing (an email or a Slack message to a named person) so there is a record that you asked, rather than relying on a verbal answer you cannot point back to later.
- If your role involves genuinely sensitive data on a regular basis, consider raising the absence of a policy as a specific, practical gap worth fixing — not as a complaint, but as a concrete ask: “can we get a one-page answer on which AI tool is approved for X kind of work?”
Find your policy this week
Use the workplace AI policy read card to actually locate your employer’s policy, log what it says about tools, data, and approval process, and note who to ask if any part is unclear. If it turns out there is no policy at all, the card also walks through the conservative-default questions to ask your manager directly. Either outcome is more useful than continuing to guess.
Sources and review boundary
- The ICO’s internal AI use policy is an official, real-world example covering approved use, personal data, output checking, and incident handling; it is not a template that overrides another employer’s rules.
- Ireland’s National Cyber Security Centre guidance on generative AI for public-sector bodies illustrates approved-tool and business-data restrictions in a high-governance setting.
This article locates policy controls; it does not interpret employment rights, contracts, GDPR roles, or the EU AI Act for a specific organization. Qualified employment, privacy, and legal review remains pending.



