Minimum Rules for Using Generative AI in the Workplace: A Beginner's Guide
Hello, I'm Noriaki Asato, Representative Attorney at LegalAgent.
When considering the use of generative AI within the company, many businesses are unable to decide between "allowing it across the board" and "banning it entirely," and find themselves stuck. Front-line staff ask to be able to "produce first drafts of contracts quickly," while management raises the concern that "confidential information might leak outside the company." Both the wish to take advantage of the convenience and anxiety about information management exist side by side, making this a theme in which people easily get caught in the middle.
A typical example of the concern is a situation in which a staff member enters a draft contract showing the counterparty's name and the contract amount, as is, into an external AI service the company has not approved, and has it summarized. Even if the action was well meant and intended to improve efficiency, if the service is configured so that data sent to external servers is reused for training or service improvement, the data may move beyond the company's control. In an environment where the standards for what information may be entered are not shared, situations like this become more likely.
That said, it is difficult to prepare rules covering every risk from the outset. By first deciding on some basic ground rules, the company can create a foothold for preventing careless input of information.
Three Elements: Input Information, Services Used and Checking Output
In putting internal usage rules in order, it is practical to start by sharing clear standards on the following three points. They are the starting point for keeping down the risks most often encountered in daily work.
- Drawing the line on input information: standards that keep input within the scope necessary for the work and restrict the entry of confidential and personal information
- Scope of services used: limiting use to internally approved tools whose handling of input information, retention period, use for training and admin functions have been checked
- Human review of output: a procedure in which a person checks output before external use or decision-making, in view of the risk of errors and rights infringement
For the first, input information, one approach is to decide that, until the legal or information management department has completed its review, information that could identify a business partner and undisclosed contract terms will not be entered. The scope of use permitted after the review is set to match confidentiality obligations and the terms of the approved service. Entering confidential information subject to a confidentiality obligation into an external service may constitute a breach of contract, depending on the contract terms and the scope of permitted disclosure. Even if company names and the like are masked, if the counterparty can be inferred from the context or the content of the transaction, this can still become an issue under the confidentiality obligation, so careful handling based on the contract terms with the counterparty is required.
Personal information, too, must be handled within the scope of the business purpose of use. If the provider's business handles personal data for purposes other than generating responses, the legal requirements on purpose of use and provision to third parties may not be met, resulting in a violation. It is therefore important to confirm that the service is configured not to use data for training, but choosing a no-training setting does not by itself satisfy all legal obligations, nor does every input always require prior consent. Restricting the entry of personal information under internal rules is positioned as a conservative operating policy pending legal review, and should be distinguished from a blanket legal prohibition on input. Also, even for information that has already been made public, check the extent to which it can be used from the standpoint of privacy and intellectual property.
For the second, services used, it is important to note that free consumer services and business plans differ in data retention periods and whether data is used for retraining. That said, the handling of input information cannot be determined from the price or plan name alone. It is desirable to have employees use an environment the company has approved after checking the actual contract terms, workspace settings and whether opt-outs are effective.
The third, checking output, is to prepare for the possibility that article numbers, legal interpretations and calculation results presented by AI contain errors. These three standards are the minimum foothold for starting limited, low-risk use, and individual tasks require further checks. For uses that affect other people's rights, such as assisting in writing personnel evaluations or automatically sending messages externally, a separate legal review needs to be put in place.
The Scope of Permitted Use and Where to Seek Advice
When considering introducing internal rules, there will be times when the size of the concerns makes a "complete ban" tempting. However, where the business need is high, a complete ban may instead invite shadow IT, with unauthorized use on personal devices and the like. When use spreads in places the company cannot see, it becomes harder, not easier, to confirm safety.
For that reason, I think that restricting high-risk use while setting realistic conditions of use, such as "don't enter confidential information," "use tools with company-approved settings" and "the person in charge checks the output," makes it easier to explain the scope of permitted use.
Also, even if detailed rules running to dozens of pages are prepared from the outset, they will not translate into practice if staff cannot find the parts they need. One approach is to start with basic rules summarizing the key points on roughly one sheet of A4 paper and update them based on day-to-day inquiries. For example, start with the three basic items, and once operation is under way, add specific examples such as "Summarizing meeting minutes that contain only information approved for input is permitted in the approved environment. Consult legal in advance before drafting text relating to personnel evaluations." Supplementing appropriate concrete examples to match the industry and the nature of the information handled, and specifying the person responsible for management, the consultation desk and the timing of periodic reviews, increase effectiveness.
Asking AI to Draft the Basic Rules
When considering the outline of internal rules, having the generative AI itself output a first draft is also efficient. The following is a basic prompt for creating basic rules of about one sheet of A4 paper.
Please create a first draft of basic rules, about one sheet of A4, for using generative AI for work at our company. Include the following points.
- Information that may / may not be entered
- The scope of services that may be used
- The obligation to check output before using it
- Whom to consult when in doubt
Mark points that require supervision by a law firm with "Legal review required." Do not leave ambiguous points blank; keep them as items to be confirmed.
After the output, the legal team revises the draft to fit the company's operations. The names of the people to consult and the approvers are also filled in according to the actual internal structure.
In addition, a prompt that clarifies the boundary between "information that may be entered" and "information that must not be entered" is useful for helping front-line judgment. The following example assumes an internal policy at the time of introduction under which personal information and business partners' confidential information are not to be entered. It does not represent a blanket legal prohibition, and the legal team checks the resulting classification.
Based on our company's operations, please organize "information that may be entered" and "information that must not be entered" into generative AI, giving five concrete examples of each. Also add one example where the boundary is unclear.
- Also show examples on borderlines where judgment is easily confused (e.g., published vs. unpublished)
- Clearly classify anything that could be personal information or a business partner's confidential information as "may not be entered"
- Prepare this on the assumption that the legal team will check the final classification
[Enter an outline of our industry and the information we handle here]
Attaching the concrete examples obtained from this prompt to the rules as an internal Q&A makes the standards for front-line judgment clear. Note that, so as not to give the AI too much of the company's undisclosed information or sensitive data at the stage of entering the prompt, care should be taken to keep the input to a general outline of the business.
The People Responsible for Communicating and Revising the Rules
Even after the rules are distributed, check whether staff know their content and can seek advice when needed. If parts are found that do not fit actual use, review both the operation and the standards.
One common failure is to create the rules and then neglect to communicate them, so that awareness does not spread on the front line. If staff do not know the rules, they cannot use them in daily decisions. It is important to convey, through internal notices and brief explanatory sessions, why the standards are needed as well.
The second failure is to include overly strict exception provisions or complex approval procedures from the start, causing the front line to shy away from using the tools. Starting with focused standards and updating them gradually in line with actual usage and consultation cases makes them easier to take root.
The third is to set the rules once and then leave them without revision. The functions and terms of use of generative AI services and the guidelines of the relevant ministries keep changing. It is necessary to make the responsible department and the consultation desk clear and to put in place a system for periodic review.
Support for Creating Usage Rules
If you would like individual advice suited to your company's business on creating internal rules for the use of generative AI or reviewing how they operate, please make use of the following services.