# AI usage policy — starting draft

## 1. Approved tools
Our approved AI tool is: ____________ (one official tool, on a business tier).
Personal or free AI accounts are not approved for any work involving business or customer information. If it's about work, it happens in the approved account.

## 2. What we use AI for
(List the tasks your team actually uses AI for, and the review rule for each.)

- ____________ — reviewed by ____________ before it goes out.
- ____________ — reviewed by ____________ before it goes out.

## 3. The standing rule: AI drafts, a human approves
AI output is a draft, always. Anything a customer will see — a reply, a quote, a post, a translation — is read and approved by a person before it goes out. The person who approves it is responsible for it.

## 4. What never goes into an AI tool
- Passwords, access codes, or anything security-related
- Payment or bank details
- Full customer records — use only the minimum needed for the task
- ____________ (add anything specific to your business)

## 5. When to hand it to a person
Stop and involve a person directly when a situation involves:
- a complaint that questions what actually happened
- a refund, discount, exception, or anything that commits the business
- a legal question, a safety issue, or an upset customer
The AI was not there and has no authority. People handle judgment calls.

## 6. Ownership and review
This policy is owned by: ____________ (name a person, not a committee)
Review it every 3 months, or whenever we change tools, plans, or the kind of customer information we handle.

---
This is a practical starting point, not legal advice and not a complete
compliance policy. Review it against your actual legal, regulatory,
contractual, and security obligations — especially the PDPA if you handle
personal data in Singapore.
