Staff are already using AI tools at work - whether or not there's a policy telling them how. The realistic goal isn't banning ChatGPT and Copilot outright; it's giving staff clear, sensible rules so the genuine productivity benefit doesn't come with a client data leak attached.
Why "Just Ban It" Doesn't Work
Blocking AI tools on the work network rarely stops usage - it just pushes it onto personal phones and unmanaged devices, where there's no visibility and no control at all. A written policy paired with sanctioned, properly configured tools almost always produces a better outcome than prohibition.
What an AI Usage Policy Should Actually Cover
What can and can't be entered into a public AI tool
The core rule: nothing goes into a public, free-tier AI chatbot that you wouldn't be comfortable posting publicly. That means no client names tied to sensitive matters, no financial data, no health information, no passwords or system details, and no unreleased business information. Many free AI tools use submitted content to further train their models - once it's in, it's not coming back out.
Which tools are sanctioned
Enterprise versions of these tools - Microsoft 365 Copilot, ChatGPT Enterprise/Team, and similar paid tiers - typically come with contractual commitments that your data isn't used for model training and stays within your tenant's data boundary. Naming the specific sanctioned tools in the policy (rather than a vague "use AI responsibly") gives staff a clear, safe option rather than forcing them toward whatever free tool is easiest to reach.
Checking AI-generated output before it goes out
AI tools confidently produce incorrect information - in legal, financial, or technical contexts, this can create real liability if it's sent to a client unchecked. The policy should be explicit that AI output is a draft, not a deliverable, until a human has verified it.
Disclosure expectations
Decide, and write down, whether clients need to be told when AI tools were used in producing their work - particularly relevant for professional services where clients may have their own expectations about who (or what) is doing the work they're paying for.
Account and access controls
Where possible, AI tool access should sit behind the same MFA and access controls as the rest of your business systems - an AI account logged into with a weak, reused password is just another account for an attacker to compromise.
A Practical Starting Template
- Approved tools - name the specific AI tools staff are permitted to use for work, and under what business or personal accounts.
- Data classification - a simple list of what can never be entered into a public AI tool (client identifiable data, financial details, anything covered by an NDA).
- Verification requirement - all AI-assisted output reviewed by a human before being sent externally or relied upon for a decision.
- Reporting - a clear point of contact if someone realises they've entered something they shouldn't have.
Where This Fits With Your Other Policies
An AI usage policy works best alongside your existing BYOD policy and data handling rules, rather than as a standalone document nobody reads. The goal is one consistent set of expectations about where company and client data is allowed to go.
Not sure where your business actually stands? Try our free 2-minute AI readiness self-assessment to see where the gaps are.
Frequently Asked Questions
Should we just ban ChatGPT and Copilot at work?
Blocking these tools on the work network rarely stops staff using them, it usually just pushes usage onto personal phones where you have no visibility at all. A written policy paired with sanctioned, properly configured tools tends to work much better than an outright ban.
What's the difference between the free version of ChatGPT and an enterprise version?
Enterprise or paid business tiers, such as Microsoft 365 Copilot or ChatGPT Enterprise/Team, typically come with contractual commitments that your data isn't used to train the underlying model and stays within your organisation's data boundary. Free, public tools generally don't offer the same protection, so anything entered there should be treated as potentially public.
Do we need to tell clients if we used AI to help produce their work?
That's a decision worth making deliberately and writing down rather than leaving informal. Some clients, particularly in professional services, may have their own expectations about disclosure, so it's worth deciding your position in advance rather than being asked mid-project.
What's the single most important rule for an AI usage policy?
Nothing goes into a public, free AI tool that you wouldn't be comfortable posting publicly - no client names on sensitive matters, no financial data, no passwords. Everything else in a good policy supports that one rule.
We help Perth businesses roll out AI tools properly - sanctioned accounts, sensible policy, and staff who actually understand the boundaries.
IT Consulting Services →Staff already using AI tools with no policy in place?
Call 0433 087 091 for a free, no-obligation conversation about getting ahead of it.
Book a Free Consultation