Skip to main content

Workplace AI-use policy · Acceptable use policy · BYOAI

Workplace AI-Use Policies — What Belongs in One

A reference on governing employee AI use — what a durable policy contains, the questions its owners should be able to answer, and where it meets employment and privacy law.

8 min read

Summary

A workplace AI-use policy is the document that tells employees which AI tools they may use for work, on what data, with what disclosure, and under whose review. As staff adopt general-purpose AI faster than most employers can govern it — often bringing their own tools to work — the policy is what turns an unmanaged practice into a defensible one.

Most asked

Should we ban AI at work instead of writing a policy?

In most organizations a ban is self-defeating. Employees who find that an AI tool saves them an hour will use it whether or not a policy permits it; a ban simply moves that use onto personal accounts and unmanaged devices, where the organization can neither see the data leaving nor prove what happened when a decision is later questioned. Prohibition trades a governance problem for an evidence problem, and the evidence problem is worse. A workable policy starts from the premise that the tools will be used and channels that use into places the organization can observe, document, and defend.

What belongs in a workplace AI-use policy?

A policy that holds up under scrutiny tends to specify six things: the permitted tools and tiers (which systems are approved for which classes of work); data handling and confidentiality (what may and may not be entered into an AI system); disclosure and human review (where a person stays accountable for AI-assisted work that affects others); vendor and model provenance (which providers are approved and who owns the diligence); record-keeping (what gets logged and for how long); and enforcement and escalation (what happens when the policy is broken and where an employee goes with a hard case).

Who should own the AI-use policy?

Whoever owns it should sit close to legal and compliance, because the policy is where several bodies of law converge and those specifics change often. Just as important as the owner is the date: “last reviewed” is a field that matters, because a policy written against last year’s legal landscape is a liability dressed as a safeguard.

More questions ↓

This reference covers what a durable workplace AI-use policy contains, the questions its owners should be able to answer, and where it meets employment and privacy law.

Why a policy, rather than a ban

The instinct to prohibit is understandable and, in most organizations, self-defeating. Employees who find that an AI tool saves them an hour will use it whether or not a policy permits it; a ban simply moves that use off the record, onto personal accounts and unmanaged devices, where the organization can neither see the data leaving nor prove what happened when a decision is later questioned. Prohibition trades a governance problem for an evidence problem, and the evidence problem is worse. A workable policy starts from the opposite premise: that the tools will be used, and that the organization’s task is to channel the use into places it can observe, document, and defend.

The cost of getting this wrong is concrete. An employee pastes a customer list into a consumer chatbot and the confidentiality obligation is breached before anyone reviews it. A hiring manager runs candidates through an unvetted screening tool and creates a discrimination record no one designed and no one can explain. In each case the failure is not the technology; it is the absence of a rule that would have made the safer path the obvious one.

The elements a durable policy contains

A policy that holds up under scrutiny — an audit committee’s, a regulator’s, or an adversary’s in discovery — tends to specify six things.

Permitted tools and tiers. Which AI systems are approved, for which classes of work, and how an employee gets a new one reviewed. The strongest policies define tiers rather than a single yes/no: an approved enterprise tool for sensitive data, a broader set for low-risk drafting, and a clear line no tool may cross without review — employment decisions, legal or medical judgments, anything touching regulated data.

Data handling and confidentiality. What may and may not be entered into an AI system, stated in terms an employee can apply without a lawyer: no customer or employee personal data, no confidential or privileged material, no trade secrets, into any tool not on the approved list. This is the provision that prevents the most common and most damaging failures.

Disclosure and human review. Where AI is used in work that affects other people — a hiring screen, a performance input, a customer communication — the policy should require that a person remains accountable for the outcome and that the use is disclosed where law or context calls for it. Human review is worth specifying as an event that leaves a record, not as a general expectation.

Vendor and model provenance. Which providers are approved, what the organization knows about how they train and retain data, and who owns the diligence. A policy that names approved vendors and a review path is far easier to defend than one that leaves each employee to choose.

Record-keeping. What gets logged — approvals, exceptions, the basis for AI-assisted decisions that affect people — and for how long. The record is what converts a policy from a statement of intent into something an organization can stand behind later.

Enforcement and escalation. What happens when the policy is broken, who owns exceptions, and how an employee raises a question without guessing. A rule with no path for the hard case is a rule people route around.

The oversight questions to be able to answer

A board member or general counsel does not need to read the policy to test whether it is real. Five questions do that work:

  • Do we know which AI tools our people actually use, including the ones they brought themselves?
  • Is there a line no AI system crosses without human review, and is it written down?
  • Can we show, for any AI-assisted decision that affected a person, what the system did and who was accountable?
  • Who owns this policy, and when was it last reviewed against current law?
  • When an employee has a question the policy doesn’t answer, where do they go?

An organization that can answer these has governance. One that cannot has a document.

Where it meets the law

A use policy is not only internal hygiene; it is where several bodies of law converge, and the specifics vary by jurisdiction and change often. Four areas recur.

Employment decisions. When AI touches hiring, evaluation, or separation, anti-discrimination and emerging AI-employment duties apply. Illinois, for example, amended its Human Rights Act to reach AI in employment decisions; its implementing rules were temporarily withdrawn June 2, 2026, and the statute applies regardless. Several other states and jurisdictions have their own requirements, with names, effective dates, and thresholds that vary and change often.

Biometric and general privacy. Tools that process images, voice, or personal data can trigger biometric-privacy and consumer-privacy obligations that a use policy should keep employees clear of.

Confidentiality and trade secret. Entering protected material into a third-party model can waive confidentiality or privilege and put trade-secret status at risk — which is why the data provision above is the policy’s load-bearing clause.

Sector duties. Financial, health, and other regulated employers carry model-risk, clinical, or supervisory obligations that a general policy must defer to rather than override.

The point of naming these is not to convert a use policy into a legal instrument. It is to show why the policy’s owner should sit close to legal and compliance, and why “last reviewed” is a date that matters.


Khullani M. Abdullahi holds a Juris Doctor and is the founder of Techné AI. Techné AI provides advisory services and does not provide legal advice or assurance services within the meaning of the AICPA Statements on Standards for Attestation Engagements.

Frequently asked questions

Should we ban AI at work instead of writing a policy?
In most organizations a ban is self-defeating. Employees who find that an AI tool saves them an hour will use it whether or not a policy permits it; a ban simply moves that use onto personal accounts and unmanaged devices, where the organization can neither see the data leaving nor prove what happened when a decision is later questioned. Prohibition trades a governance problem for an evidence problem, and the evidence problem is worse. A workable policy starts from the premise that the tools will be used and channels that use into places the organization can observe, document, and defend.
What belongs in a workplace AI-use policy?
A policy that holds up under scrutiny tends to specify six things: the permitted tools and tiers (which systems are approved for which classes of work); data handling and confidentiality (what may and may not be entered into an AI system); disclosure and human review (where a person stays accountable for AI-assisted work that affects others); vendor and model provenance (which providers are approved and who owns the diligence); record-keeping (what gets logged and for how long); and enforcement and escalation (what happens when the policy is broken and where an employee goes with a hard case).
Who should own the AI-use policy?
Whoever owns it should sit close to legal and compliance, because the policy is where several bodies of law converge and those specifics change often. Just as important as the owner is the date: “last reviewed” is a field that matters, because a policy written against last year’s legal landscape is a liability dressed as a safeguard.
Does an AI-use policy need to address hiring and other employment decisions?
Yes. When AI touches hiring, evaluation, or separation, anti-discrimination and emerging AI-employment duties apply. Illinois, for example, amended its Human Rights Act to reach AI in employment decisions; its implementing rules were temporarily withdrawn June 2, 2026, and the statute applies regardless. Several other states and jurisdictions have their own requirements, so the policy should require a person to remain accountable for any AI-assisted decision that affects someone, with the use disclosed where law or context calls for it.
How does bring-your-own-AI (BYOAI) change the risk?
BYOAI is the core reason a policy beats a ban. When employees bring their own tools, unmanaged use moves off the record — onto consumer accounts the organization cannot monitor. The failure modes are concrete: a customer list pasted into a consumer chatbot breaches a confidentiality obligation before anyone reviews it; an unvetted screening tool creates a discrimination record no one designed and no one can explain. The policy’s job is to make the safer path the obvious one and to keep the use where it can be seen.

How to cite this article

APA

Abdullahi, K. M. (2026, July 21). Workplace AI-Use Policies — What Belongs in One. Techné AI. https://techne.ai/insights/workplace-ai-use-policies

MLA

Abdullahi, Khullani M. "Workplace AI-Use Policies — What Belongs in One." Techné AI, July 21, 2026, https://techne.ai/insights/workplace-ai-use-policies.

Plain text

Abdullahi, Khullani M. "Workplace AI-Use Policies — What Belongs in One." Techné AI, July 21, 2026. Available at: https://techne.ai/insights/workplace-ai-use-policies

Get the next piece

The Techné Institute is the firm’s periodical on AI, work, and the law — Adverse Impact weekly and Duty of Care monthly, written for boards, GCs, and the advisors who serve them.

About the author

Khullani M. Abdullahi, JD, is an AI governance and compliance consultant and the founder of Techné AI, an independent advisory firm based in Chicago. She submitted written testimony to the Illinois Senate Executive Subcommittee on AI and Social Media; the substance of one of her recommendations was incorporated into an AI-risk impact study bill. She authored the AI Governance & D&O Liability briefing now in active circulation among practitioners and underwriters, maintains the Illinois AI Legislative Ecosystem tracker, and hosts the AI in Chicago podcast. Techné AI is an advisory firm, not a law firm.