← Back to AI Legal Lab
Insight

Internal AI Use Basic Rules

Hello, this is Legal Agent.

Many companies hesitate when they first start using generative AI internally. It is hard to say "use it freely" and just as hard to say "no use at all." The business side asks to use it for a first draft of a contract, while management worries about confidential information leaking out. Both concerns are reasonable, and a company often ends up caught between them.

A common scenario: an employee pastes the full text of a service agreement, complete with a counterparty's name and a deal amount, straight into a free generative AI tool and asks it for a summary. There is no bad intent; it is simply convenient. But once that information has gone to an external server, and possibly been reused from there, it is not something to overlook. Incidents like this happen because there is no rule in place.

A perfect rulebook is not needed from day one. Setting just a few minimum ground rules already prevents most of this kind of trouble. Three lines matter most at the start.

The three things to settle first

Before building out detailed rules, settling just these three brings real peace of mind, since they map directly onto generative AI's two main risks: information leaks and inaccurate output.

  • What information may and may not go in: the line for entering confidential or personal information
  • Which services may be used: whether use is limited to services and plans the company has approved
  • The duty of final review: a person checks AI's output before it is used

On the first point, simply deciding "do not enter a counterparty's name, a person's name, an unpublished amount, or the full text of a contract" already cuts down the kind of incident described above. Entering information covered by an NDA into an external service can itself risk breaching that confidentiality obligation, which makes this point worth particular care. These three are worth settling first.

Why these three, specifically

A closer look at why each of these three matters helps make the judgment calls easier on the ground.

The first, what information may go in, is the line that prevents leaks. Some generative AI services use submitted content for training or store it on their servers. Entering confidential or personal information risks sending it outside the company's control.

The second, which services may be used, is about controlling the entry point. Even for the same underlying model, an enterprise plan that does not use input for training and a free consumer service handle information very differently. Limiting use to services and plans the company has approved keeps the risk consistent and manageable.

The third, the duty of final review, guards against inaccurate output. AI can get a statutory citation or a number wrong, so the rule should be that a person checks the output before it is used, rather than using it as-is.

Set the terms of use, do not just ban it

The instinct, when thinking through rules, is often to reach for an outright ban. But an outright ban tends to push use underground onto personal phones and other devices the company cannot see, which is worse: this is called shadow IT, and it makes the risk harder to spot, not easier.

Setting conditions for safe use, rather than banning it outright, tends to work better in practice. A rule like "use is fine as long as you do not enter confidential information, use an approved service, and check the output" is easier for people to actually follow, and, as a result, easier to manage.

Start small, then build it out

There is no need to write a thick rulebook from the start. A one-page set of rules that people can actually read tends to work better than a long manual nobody opens.

Start with a basic rule that fits on a single page, then add specific cases as they come up in practice, and the rules end up fitting how the company actually works. Begin with just the three basics, for instance, and add specific guidance later, such as "summarizing meeting minutes is fine, but drafting performance-review text needs a check first."

Sample: drafting a first cut of the basic rules (basic form)

Having AI produce a first draft is a good way to get a rules project moving. Here is a basic-form prompt for that first draft.

Draft a one-page set of basic rules for our company's business use of generative AI. Cover the following points:

- Information that may and may not be entered
- The scope of services that may be used
- The duty to check output before use
- Who to contact with questions

Flag anything that needs legal review with a "needs legal review" note. Do not leave ambiguous points blank; list them as open questions instead.

Treat what comes out as a starting point only. Adapt it to your company's actual situation, and have legal review and finalize it.

Sample: working out concrete examples of what may be entered (applied form)

An applied-form prompt for making the line more concrete: turning the abstract rule of "no confidential information" into specific examples people can apply on the spot.

Based on our company's business, list five concrete examples each of information that may be entered into generative AI and information that may not, with one example that sits on the boundary.

- Include an example where the line is hard to judge (for example, information that has already been made public versus information that has not)
- Classify anything that could be personal information or a counterparty's confidential information clearly as "may not be entered"
- Assume legal will review the final classification

[Describe your company's business and the kind of information it handles here]

Turn this list of examples into a Q&A or reference sheet attached to the basic rules, and it becomes something people can turn to when unsure. Keep what goes into this prompt itself at a general level, and avoid entering anything too sensitive about the company.

Common mistakes

A few mistakes come up often when building out these rules, mostly at the point where the rules meet day-to-day practice rather than in the initial design.

The first is writing the rules and stopping there, without ever telling anyone. A rule nobody knows about is the same as no rule at all. Distribution and explanation need to be part of the plan from the start.

The second is building overly detailed rules all at once, which nobody ends up reading. Starting with one page and building it out through actual use tends to work better.

The third, and a common one, is writing the rules once and never revisiting them. Generative AI services and the law around them keep changing, so a regular review needs to be built in from the start.

Things to watch for

  • Rules are not finished once written. They need to be communicated internally and reviewed regularly
  • The line on entering confidential and personal information deserves particular clarity
  • AI's output should always get a final human check before use
  • What a company needs varies by industry and the information it handles, so adjust the rules to fit your own situation

Related articles

Articles connected to this topic.

Insight / 2026.07.23 Game Payments and Gacha: Reviewing Japan's Payment Services Act and Premiums Rules Together Insight / 2026.07.22 Entertainment and Creator Contracts Should Define Ownership and Secondary Uses First Insight / 2026.07.21 Esports Tournament Operations Require Separate Analysis of Prizes, Sponsors, and Minors
View AI Legal Lab articles