How to create an internal generative AI use policy
Hello, this is Legal Agent.
A request to write a generative AI use policy usually turns out to mean something narrower once we ask who the document is really for. A policy built entirely out of prohibitions rarely gets followed, because a list of banned actions does not tell an employee what they can actually do, what they must never type in, when a human needs to check the output, how to bring in a new external AI tool, or what to do if something goes wrong.
A policy that only warns does not work
Telling staff not to input "confidential information" leaves the real judgment call to each employee, because nobody can act on that instruction without knowing whether a masked customer name is fine, whether part of a contract is fine, whether internal meeting notes are fine, whether source code is fine. Concrete examples at this level of detail are what make a policy usable rather than decorative.
Why a company-wide rule is needed at all
Generative AI is something any employee can start using alone, by creating an account, which is exactly the risk: customer information, unpublished results and trade secrets can end up in an external service without the company ever knowing, and because AI output reads naturally, errors are easy to miss when the text goes straight into legal work, HR decisions or customer communication. Without a shared policy, each department reaches its own answer: sales uses AI in customer proposals, marketing in ad copy, HR in job postings and evaluation comments, engineering in code. Each choice is locally reasonable, but nobody is able to say what risk the company as a whole is actually carrying.
Building the policy around what people actually do
The definition of covered tools should be written to extend to services that do not exist yet, rather than naming today's products one by one. A two-tier risk classification lets most everyday use proceed without friction: everyday tasks such as paraphrasing, translation or summarising public material on one side, and personal data, legal judgment or anything headed for external publication on the other. Prohibited inputs should be named specifically, with an approval route for the exceptional case, and any use of a personal account for work should be addressed explicitly, since a company-approved account may restrict training use in ways an employee's own free or paid plan does not.