Writing an AI usage policy for your staff: what to include

A plain-language structure for a workplace AI policy that staff will actually read, covering approved tools, data rules, review of outputs and who to ask.

By TENONTECH Advisory Team · · 3 min read

If your company has not published rules on AI, your staff are almost certainly using it anyway. Surveys in Singapore and elsewhere consistently show high use of generative AI at work, much of it on personal accounts that managers do not know about. Banning AI tends to push usage out of sight. A clear, short policy brings it into the open and makes it safer.

Keep it short

The policies that work are two to four pages long and written in plain English. Long documents written by lawyers for lawyers get acknowledged and ignored. Aim for something a new employee can read in ten minutes and remember the main points of.

A structure that works

1. Purpose

Two or three sentences explaining why the policy exists: the company wants staff to use AI to work better, and wants to protect customers, employees and the business while doing so.

2. Approved tools

List the tools staff may use for work, and the account type required. For example:

  • Microsoft 365 Copilot through company accounts
  • ChatGPT Team or Enterprise through the company workspace
  • The internal knowledge assistant

State plainly that personal or free accounts must not be used for company information. Explain how staff can request a new tool to be reviewed.

3. Information rules

This is the most important section. Use three categories, with examples:

CategoryExamplesRule
PublicPublished marketing material, public website contentMay be used with any approved tool
InternalInternal procedures, draft documents without personal dataApproved tools only
RestrictedCustomer personal data, NRIC numbers, salaries, medical information, client confidential documents, passwordsNever entered into AI tools unless a specific, approved system has been set up for it

4. Checking outputs

AI tools make mistakes, including invented facts, wrong calculations and made-up references. The person using the tool is responsible for the result. Require staff to:

  • Check facts, figures and references before using AI-generated content
  • Never send AI-drafted content to customers without reading it fully
  • Be especially careful with legal, financial, medical and technical statements

5. Transparency

Set expectations on when to disclose AI use. Many companies require disclosure when content is substantially AI-generated and published externally, or when a customer is interacting with an automated system.

6. Prohibited uses

Be specific. Common examples:

  • Making decisions about hiring, firing, pay or discipline based solely on AI output
  • Generating content that impersonates a real person
  • Using AI to get around security controls or monitoring
  • Uploading third-party copyrighted material where your licence does not allow it

7. Intellectual property

Clarify that work produced with AI tools in the course of employment belongs to the company, as with any other work. Remind staff that AI outputs may resemble existing material and should be checked before publication, particularly images and marketing copy.

8. Reporting problems

Tell staff what to do if something goes wrong: restricted data entered by mistake, a harmful output, or a customer complaint about an AI system. Make reporting quick and blame-free, so problems surface early. Link this to your existing data breach procedure.

9. Ownership and review

Name the person or role responsible for the policy, and commit to reviewing it at least every six months. AI tools change fast, and a policy written a year ago may already be out of date.

Roll it out properly

Publishing the policy is the easy part. To make it stick:

  • Brief each team in 20 minutes, using examples from their own work
  • Give people the approved tools at the same time, so the rules come with something useful
  • Put the information rules on a single page that staff can keep at hand
  • Ask for feedback after a month and adjust anything that is not working

Aligning with Singapore guidance

A policy along these lines supports your obligations under the PDPA and reflects the accountability and human-oversight principles in IMDA's Model AI Governance Framework. For the detail behind the information rules, see our PDPA checklist for generative AI, and for the wider governance picture, our explainer on the framework.

Frequently asked questions

Should we ban AI tools until we have a policy?

A short-term restriction on restricted data is sensible, but a blanket ban is usually ineffective. A simple interim rule ("no customer or employee personal data in any AI tool, and use only company accounts") can cover you while the full policy is written.

Do employees need to sign the policy?

Many companies ask for acknowledgement, often through their HR system or onboarding process. More important than the signature is a short briefing so people understand it.

Need help applying this in your business? TENONTECH works with Singapore SMEs on AI strategy, implementation and governance. Book a consultation.

Related reading