# [Team or organisation name]: how we use AI tools at work

**Template. Not legal advice.** This is a starter template from AI Tools Academy for a team's working rules. It does not replace your organisation's policies. Check it against your data protection obligations, contracts and any sector rules, and ask your data protection officer or legal adviser to review it before you adopt it. If these rules and your organisation's policy disagree, the policy wins.

**Status:** [Draft / Interim / Agreed on date]
**Owner:** [name and role]
**Next review:** [date, for example six months from agreement]
**Related policies:** [link to your organisation's AI, acceptable use or data protection policy, if any]

---

## 1. Approved tools

Use only these AI tools for [team or organisation name] work:

- [Tool name], signed in with your [work / business] account, for [what it is approved for]
- [Tool name], signed in with your [work / business] account, for [what it is approved for]

Don't use personal AI accounts for work unless this list says so. To suggest another tool, ask [name or role]. They will reply within [time period].

## 2. Information: what can go in

**Never put into any AI tool:**

- passwords, access codes or security details
- bank or card details
- [sensitive personal data your team handles, for example health, sickness, disability, ethnicity, religion, trade union membership, criminal records, safeguarding]
- [anything about a disciplinary, grievance or complaint about a person]
- [documents marked confidential or restricted]
- [anything else your team must keep out]

**Only in an approved tool, and only the minimum needed:**

- [for example customer names and order details]
- [for example internal plans, procedures or figures]

**Fine in any approved tool:**

- [for example published information, general wording help]

Removing a name doesn't always make information anonymous. If you're not sure which group something is in, treat it as "never" and ask [name or role].

## 3. Checking

Check everything AI produces before you use or send it. Check every name, date, figure, price and quote against the source.

For [anything going to a customer / anything informing a decision / other higher-risk work], also [check every line against the source / have it checked by name or role].

## 4. Responsibility

If you send it, submit it or act on it, you're responsible for it, exactly as if you'd written it yourself.

[Add any work that needs sign-off from name or role.]

## 5. Saying when AI was used

Tell the person checking your work when AI drafted a substantial part of it.

[For example: for reports that inform a decision, add a line saying which tool was used and for what.] [Add any record keeping your organisation requires.]

## 6. Decisions AI doesn't make

Don't use AI to make or recommend decisions about people, including [hiring, shortlisting, discipline, pay, performance ratings, references]. A named person makes these decisions and must be able to explain them in their own words.

Talk to [HR / name or role] before using AI for any task that involves these decisions.

[Add any other decisions your team keeps fully human.]

## 7. Customers, suppliers and the public

Anything sent outside [team or organisation name] is checked by the sender before it goes.

[For example: quotes and prices are checked against the current price list. Complaint replies are read by name or role before sending.]

If someone asks whether AI was used, answer honestly.

## 8. Questions and mistakes

**Not sure?** Ask [name or role] before you paste. Backup: [name or role].

**Think something went into an AI tool that shouldn't have?** Tell [name or role] straight away, even if you're not certain. Don't delete anything until you've spoken to them. They will involve [data protection officer or contact].

Reporting quickly matters more than blame. Nobody will be in trouble for telling us.

---

*Template. Not legal advice. Adapted from the AI Tools Academy team AI rules starter.*
