AI policy and shadow AI

Safe AI Rules for the Workplace

A clear AI policy helps people understand what is allowed, what is prohibited, what requires approval and when human review is required.

What is shadow AI?

Shadow AI is unapproved AI use at work.

It often happens because AI tools are easy to access, useful and fast. However, unapproved AI use can expose confidentiality, privacy, cyber security, intellectual property, accuracy and compliance risks.

Abstract connected data lines representing hidden AI tool use across a workplace.
Policy sections

What an AI policy should include.

Purpose and scope

Who the policy applies to and what AI tools it covers.

Approved tools

Which AI systems may be used for work and for what purposes.

Prohibited uses

When AI must not be used, including unlawful or high-risk purposes.

Data rules

What information must never be entered into AI tools unless controls are approved.

Human review

When outputs must be checked before publication, decisions or customer communication.

Accuracy and bias checks

How staff verify output and consider fairness.

Record keeping

How AI use is documented for important decisions or high-risk processes.

Incident reporting

How staff report errors, privacy concerns, security issues or harmful outputs.

Training and review

Minimum awareness training and policy review cycles.

Simple employee rule

If a tool is not approved, do not use it with work information. If the output affects a person, decision, customer, safety issue or legal obligation, a human must review it.