Free tool
AI Usage Policy Starter
If your team is pasting customer messages into personal AI accounts, you already have a data policy — you just didn't write it. Answer a few questions and watch a practical first draft assemble as you go: approved tools, review rules, and what never goes in.
Everything runs in your browser. Nothing you enter is stored or sent anywhere. The draft is a starting point, not legal advice.
From the article: How to stop AI from making things up in your business →
Your policy draft
Updates as you fill in the form. Blanks stay in the document until you answer them — or fill them in after copying.
# AI usage policy — starting draft Team size: ____ · Drafted with the Nestoz policy starter ## 1. Approved tools We will pick ONE official tool on a business tier (ChatGPT Business, Claude Team, or Gemini) and name it here: ____________. Personal or free AI accounts are not approved for any work involving business or customer information. If it's about work, it happens in the approved account. ## 2. What we use AI for - (Tick the tasks your team actually uses AI for, and the review rule for each will appear here.) ## 3. The standing rule: AI drafts, a human approves AI output is a draft, always. Anything a customer will see — a reply, a quote, a post, a translation — is read and approved by a person before it goes out. The person who approves it is responsible for it. ## 4. What never goes into an AI tool - Passwords, access codes, or anything security-related - Full customer records — use only the minimum needed for the task ## 5. When to hand it to a person Stop and involve a person directly when a situation involves: - a complaint that questions what actually happened - a refund, discount, exception, or anything that commits the business - a legal question, a safety issue, or an upset customer The AI was not there and has no authority. People handle judgment calls. ## 6. Ownership and review This policy is owned by: ____________ (name a person, not a committee) Review it every 3 months, or whenever we change tools, plans, or the kind of customer information we handle. --- This is a practical starting point, not legal advice and not a complete compliance policy. Review it against your actual legal, regulatory, contractual, and security obligations — especially the PDPA if you handle personal data in Singapore.
This is a practical starting point, not legal advice. Review it against your actual legal, regulatory, contractual, and security obligations before adopting it.
Not sure which of your workflows AI should — and shouldn't — touch? Get a free First Take →