An AI use policy gives a contracting company practical rules for which tools employees may use, what data is prohibited, who approves customer-facing automation and how errors are reported. It should be short enough for daily work and supported by approved alternatives, training and technical controls.
- Quick answer
- Start with a real inventory
- State the purpose and scope
- Define approved and prohibited tools
- Classify information
- Write clear prohibited-input rules
- Define human approval
- Set customer-facing rules
- Address accuracy and fact-checking
- Address copyright and brand
- Secure accounts and integrations
- Review vendors
- Create an exception process
- Create incident reporting
- Define incident response
- Train by role
- Monitor compliance without hidden surveillance
- Review and update the policy
- A one-page employee rule set
- Organize the policy into layers
- Define risk tiers
- Set rules for AI-generated code and automation
- Set rules for procurement
- Set rules for records
- Include agency and franchise controls
- Roll out the policy
- Policy implementation checklist
- Write a customer-communication standard
- Write a generated-image standard
- Write a workforce-use standard
- Define record ownership
- Make managers accountable
- Measure policy effectiveness
- Frequently asked questions
- How long should an AI use policy be?
- Should all AI be banned?
- Who owns the policy?
- Do vendors need to follow it?
- Can employees use personal AI accounts?
- What is the first step?
- Related Oivic guides
- Authoritative resources
- Write rules people can use during real work
Quick answer
Inventory current AI use, classify data and risk, publish approved tools and prohibited inputs, require human approval for safety, pricing, diagnosis, contracts and high-impact decisions, define customer transparency, secure accounts, review vendors, and create incident and exception procedures. Assign owners and update the policy as tools and workflows change.
Start with a real inventory
Ask employees and vendors what they already use for writing, images, calls, email, scheduling, proposals, analysis and coding. Include personal accounts, extensions and built-in AI features. A policy built without this discovery will miss the highest-risk use.
State the purpose and scope
Explain that the policy supports useful AI while protecting customers, employees, confidential information and service quality. Cover employees, contractors, agencies, branches, devices and business accounts.
Define approved and prohibited tools
Maintain an approved list with owner, use case, data class, permissions and review date. Prohibit unreviewed tools from processing confidential or restricted data. Give employees a request path for new products.
Classify information
- Public approved content
- Internal operating information
- Confidential customer and business data
- Restricted credentials, payment, identity, access and sensitive employment data
Map each class to permitted environments.
Write clear prohibited-input rules
List passwords, API keys, payment data, government IDs, access codes, private customer records, unapproved recordings, sensitive employee files, confidential contracts and property-security details. Include examples employees recognize.
Define human approval
| AI output | Required approval |
|---|---|
| Routine internal outline | Task owner |
| Customer email draft | Authorized sender until narrow automation is approved |
| Price, discount or proposal | Estimator or manager |
| Safety or diagnosis | Qualified professional; AI does not approve |
| Contract, legal or employment content | Appropriate authorized and qualified review |
| Public image or claim | Marketing plus technical review where needed |
Set customer-facing rules
Use appropriate disclosure, avoid impersonation, offer human access, verify claims and distinguish messages, requests and confirmed actions. Generated images cannot be presented as real projects or people.
Address accuracy and fact-checking
Employees remain responsible for outputs they use. Require current sources for technical, legal, safety, product, price and local claims. Prohibit fabricated citations, reviews, customer stories and qualifications.
Address copyright and brand
Only upload material the company is permitted to use. Follow licenses and manufacturer brand guidance. Do not request exact imitation of a competitor’s work or publish uncertain generated logos and trademarks.
Secure accounts and integrations
Use business accounts, individual access, multifactor authentication, least privilege, approved integrations, offboarding and audit logs. Shared passwords and personal admin accounts should be prohibited.
Review vendors
Assess data use, retention, training, subprocessors, security, permissions, audit, export, deletion, incident notification and contract termination. Apply deeper review to tools with sensitive data or action authority.
Create an exception process
Employees submit purpose, tool, data, users, action and duration. Low-risk experiments can use synthetic data and limited accounts. High-risk workflows require security, privacy, operational and legal review.
Create incident reporting
Employees should report wrong customer promises, unsafe content, private-data exposure, unauthorized tools, generated misinformation and suspicious access immediately. Protect good-faith reporting.
Define incident response
- Pause the affected tool or action.
- Preserve prompts, outputs, logs and system state.
- Assess data, customers, employees and commitments affected.
- Engage appropriate leadership and specialists.
- Correct records and communicate where required.
- Fix controls, retest and document learning.
Train by role
Office staff need email, call and customer-data examples. Marketing needs claim, image and review rules. Technicians need property photo and job-note guidance. Managers need approval, monitoring and incident duties.
Monitor compliance without hidden surveillance
Review accounts, integrations, incidents and sample workflows transparently. Do not use AI monitoring for undisclosed employment decisions. Obtain qualified guidance for workforce use.
Review and update the policy
Review at least annually and after material vendor, law, model, integration or business changes. Track versions and require acknowledgment for important updates.
A one-page employee rule set
- Use approved business accounts only.
- Never enter restricted data.
- Use the minimum customer information.
- Verify facts and links.
- Do not invent reviews, projects, prices or credentials.
- Get required approval before sending or publishing.
- Offer human help in customer-facing workflows.
- Report mistakes and exposure immediately.
Organize the policy into layers
Use a short core policy for company-wide principles, a tool register for approved products, data standards for sensitive information and workflow procedures for calls, marketing, proposals and employee use. This avoids rewriting the entire policy whenever one tool changes.
Link each layer from one employee page and show the current version.
Define risk tiers
- Low: public information, no system action and easy human review.
- Moderate: internal information, customer communication draft or limited integration.
- High: confidential data, customer-facing autonomy, workforce evaluation or financial action.
- Prohibited: restricted data in public tools, impersonation, fabricated evidence or unauthorized high-impact decisions.
Use the tier to determine review, testing, contract and monitoring.
Set rules for AI-generated code and automation
Generated scripts, integrations and website changes require code review, testing, security checks, backups and controlled deployment. Never paste production credentials into a coding assistant. Document who owns and maintains the output after launch.
Set rules for procurement
No department should sign up for a high-risk tool without data, security, contract and integration review. Require a business owner, full price, acceptance test and exit plan. Free trials must use synthetic or redacted data unless approved.
Set rules for records
Identify which AI outputs become official records and where they are stored. A generated summary should not replace the source. Retention, correction, access and legal hold procedures must apply across connected systems.
Include agency and franchise controls
Marketing agencies, answering providers, subcontractors and branches may introduce their own AI. Require disclosure of tools and data, approval for customer-facing assets and prompt incident notification. Define who owns generated files, accounts and history.
Roll out the policy
- Discover current use without punishment.
- Approve essential low-risk tools and alternatives.
- Publish core rules and role examples.
- Train managers and frontline teams.
- Remove unsafe access and integrations.
- Audit, collect feedback and revise.
Policy implementation checklist
- Leadership sponsor and policy owner are named.
- Current tools and shadow use are inventoried.
- Approved products have scoped use cases.
- Data classes map to allowed environments.
- Human approval and prohibited decisions are clear.
- Customer disclosure and handoff rules exist.
- Procurement and vendor review are connected.
- Incidents and exceptions have forms and owners.
- Training is role-specific and documented.
- Version and review dates are visible.
Write a customer-communication standard
Specify which messages AI may draft, which may send automatically and which always require review. Lock price, warranty, cancellation and required disclosure language. Require current-state checks before sends and a monitored reply channel.
Write a generated-image standard
Real projects and people require authentic, permissioned images. Concepts and illustrations must be labeled when realism could mislead. Prohibit fabricated portfolios, reviews, credentials and unsafe technical scenes. Keep provenance and original assets.
Write a workforce-use standard
Disclose approved monitoring and coaching uses, limit access, validate accuracy, allow correction and avoid automated high-stakes decisions. Employment, location and call analysis require appropriate specialist review.
Define record ownership
Generated summaries, drafts and recommendations should identify the official system and human approver. Keep source material accessible. Corrections must propagate to tasks and customer records so employees do not act on old output.
Make managers accountable
Managers approve use cases, ensure review capacity, monitor incidents and prevent productivity pressure from encouraging prohibited shortcuts. Policy failure is not only an employee training issue.
Measure policy effectiveness
- Approved versus unapproved tools discovered
- Training and acknowledgment completion
- Data or misinformation incidents by severity
- Time to contain and correct
- Overdue vendor and tool reviews
- Employee questions and exception turnaround
- Useful workflows adopted safely
Report results to leadership with severity and root cause, not only incident count. More reports can indicate better awareness rather than worsening behavior. Track whether controls prevent recurrence and whether approved alternatives meet employee needs.
Revise training from that evidence.
Publish the updated examples promptly.
Frequently asked questions
How long should an AI use policy be?
Keep the core rules concise, with linked standards and procedures for detail.
Should all AI be banned?
No. Risk-based approved use with safe alternatives is more practical than an unenforceable blanket ban.
Who owns the policy?
Leadership should assign a coordinator across operations, security, privacy, marketing and people management.
Do vendors need to follow it?
Yes where they use AI, data or accounts on the company’s behalf. Contract terms may be needed.
Can employees use personal AI accounts?
Not for company confidential or restricted data. Define whether any low-risk public-content use is allowed.
What is the first step?
Discover current tools and data flows before writing rules.
Related Oivic guides
- AI Privacy Risks
- Data to Keep Out of Public AI
- Use AI Without Misleading Customers
- AI Readiness Checklist
Authoritative resources
Write rules people can use during real work
Oivic helps contractors connect AI policy with approved tools, training, permissions and accountable operations.




