Three things a manager can set in an afternoon: a specific list of what never goes into a chat, a norm of disclosing AI use, and five agreed terms so meetings stop talking past each other.
If you manage people, your job is not to use AI well yourself. It is to make sure the people who report to you do. Most of that comes down to three small pieces of groundwork: what stays out of the chat window, what people feel safe saying about their own use, and a shared set of words.
None of this needs a long policy document. It needs to be specific, said once, and easy to follow by default.
Most AI tools are safe for most work. The exception is not a type of task but a type of content. Once something is pasted, it has left your control, and that is the only question that matters.
Never paste:
Fine to use: public information, your own writing, hypothetical scenarios and de-identified examples. Drafting, summarising, brainstorming and editing mostly fall here and need no second thought.
If you wouldn't paste it into a public Slack channel at your company, don't paste it into a chat window either.
The thirty-second habit: before pasting, ask who else could plausibly see this if it left the room right now. If the honest answer includes people who should not see it, redact, generalise or leave it out.
A policy nobody remembers is the same as no policy.
The real risk is not people using AI too much. It is people submitting AI output unchecked because they are afraid to admit they used it. Make it ordinary to say "I used AI for the first draft", and the checking happens in the open instead of in secret.
In one-to-ones, replace "are you using AI?" with two questions: what did AI save you time on this week, and what did you have to fix afterwards? The second half tells you whether the team is using it well or just using it fast. Managing AI use well is managing trust, not managing a tool.
Half of an AI conversation at work gets derailed by people using the same words to mean different things. You do not need to understand the technology, only to agree on a handful of terms.
| Term | Working definition |
|---|---|
| Hallucination | The model states something false with full confidence. Not a bug you can switch off but a property you check for. |
| Prompt | The instruction you give. A better prompt is more specific, not longer. |
| Context window | How much the model can hold in one conversation. When it "forgets" something earlier, it has usually fallen out of this window. |
| Fine-tuning | Training a model further on specific data. Most teams do not need it; they need a better prompt or process. |
| Model | The AI system doing the work. Different models suit different tasks, which is why "just use AI" is not a real instruction. |
Add one distinction early: AI that assists a person's judgment versus AI that replaces a decision. Most useful workplace AI is the first, and treating it as the second is where trust breaks down.
Skip the architecture, the training process and the maths. Vocabulary that does not change a decision is not worth a meeting slot.
A short checklist of decisions an AI policy should never delegate, such as ending employment, safeguarding judgements and legal signatures, and why keeping the list short protects the rest of the policy.
AI Use Policy · 4 minGuide · 24 September 2026A template for the permitted-use table in an AI policy: one row per role and task, with four columns for role, task, safeguard and data boundary, so staff can find answers in seconds.
AI Use Policy · 3 minExplainer · 27 September 2026Personal data is wider than names and numbers, and a prompt's fate depends on account tier, retention and sub-processors; a technical explainer for DPOs and IT leads, with four questions to ask any tool.
AI Use Policy · 5 minIf this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.