Policy · Hero

AI use policy for employees: what to include, with a one-page template

The useful detailsA workable AI policy fits on one page and answers six questions. Which tools and accounts are allowed? What information never goes in? What must a person check? Who decides anything about people? When do we tell clients or applicants? What do you do after a mistake? The template below covers all six. Fill in the brackets, have whoever owns privacy for your business read it, then walk the team through it.

Make three decisions before you write anything

A policy is a record of decisions. If the decisions haven't been made, the document will be vague, and people will ignore it.

  1. Which tool, on which account. Name the product and the plan, for example "Microsoft Copilot Chat, signed in with your work account" or "ChatGPT Business workspace". The plan matters more than the brand. A free personal account and a business workspace from the same company can have very different terms. One is usually enough to start.
  2. Which information is off limits. Decide in categories (see the template), not file by file. If you handle health information, payment data or anything under a client contract, decide those first.
  3. Who owns it. One named person approves new tools, answers "can I paste this?" questions and updates the policy. Without an owner, the policy is out of date by the time the next tool update ships.

Free downloadWant this as a file you can edit? Get the one-page template as a Word document. Free, no call needed.

What each part is for

SectionWhy it's thereWhat weak policies get wrong
ScopeCovers employees, contractors and anyone using your accountsForgetting contractors and temps, who often bring their own tools
Approved tools and accountsMoves work out of personal accounts and into accounts you controlListing brands but not plans ("ChatGPT is allowed")
Never-enter informationGives people a clear red lineSaying "don't share sensitive data" without examples
Allowed and not-allowed usesShows what "yes" looks like, not only "no"Banning everything, which pushes use underground
Human reviewMakes one person accountable for every output"Check your work" with no list of what to check
Decisions about peopleKeeps hiring, discipline, pay and credit decisions with a personLeaving it out entirely
DisclosureSays when you tell clients, applicants or the publicSaying nothing, then being asked by a client
Connected apps and note-takersCovers AI that reads email, files or meetings, not only chat windowsTreating AI as a chat box only
MistakesTells people what to do the same day, without fearNo path, so mistakes get hidden
Review dateKeeps the policy current as tools and terms changeNo owner, no date

The one-page template

Copy this into a document. Replace everything in square brackets. Delete any line that doesn't apply.

[ORGANIZATION NAME] · Using AI at work · Owner: [NAME, ROLE] · Last reviewed: [DATE]

1. Who this covers. Everyone who does work for us, including employees, contractors and temporary staff, on any device.

2. Approved tools. You may use: [TOOL + PLAN, e.g. "Microsoft Copilot Chat signed in with your work account (look for the green shield)"]. Any other AI tool, browser extension, plug-in or meeting note-taker needs approval from [ROLE] first. Ask by [HOW, e.g. a message in #ai-questions].

3. Accounts. Use only accounts we provide. Do not use personal AI accounts for work content, and do not sign up for AI tools with your work email without approval.

4. Never enter, in any AI tool: passwords, access codes or API keys; Social Insurance Numbers, health card, driver's licence or passport numbers; bank or card numbers; health information about any person; [OTHER, e.g. "full client files", "anything under a confidentiality agreement or legal privilege"].

5. Only in approved tools, for approved tasks: client or employee names with details, internal financials, draft contracts, [OTHER]. If you are not sure which list something is on, stop and ask [ROLE].

6. Good uses. First drafts, rewording, summaries of material you are allowed to use, outlines, checklists, formulas, brainstorming. [ADD TWO EXAMPLES FROM YOUR OWN WORK.]

7. Human review. Before anything AI-assisted leaves your hands, check facts, figures, names, dates, quotes and sources against the original. The person who sends it owns it.

8. Decisions about people. AI does not decide hiring, discipline, performance, pay or credit. A person decides and can explain why. [If we use AI to screen, assess or select job applicants, our public job postings say so.]

9. Disclosure. [OUR RULE, e.g. "We tell a client when AI materially helped produce a deliverable, when they ask, or when their contract requires it."]

10. Connected apps and meetings. Do not connect AI tools to work email, calendars, files or the CRM without approval. Do not add an AI note-taker to a meeting unless everyone in the meeting has been told.

11. Mistakes. If something on the never-enter list goes into an AI tool, tell [ROLE] the same day: what, which tool, which account, when. Reporting is never punished. Hiding it is a problem.

12. Review. [ROLE] reviews this policy and the approved-tool settings every [6 MONTHS] and whenever we add a tool.

I have read this policy. Name: ______ Date: ______

Your next chapter starts here.

Enter your email to get the file. Updates are optional.

Canadian rules worth checking before you finalize

This is general information, not legal advice. It shows which questions to ask whoever handles privacy or legal for you.

  • Federal private-sector privacy law (PIPEDA). It applies to most businesses outside Quebec, Alberta and BC when they handle personal information in commercial activity. You stay accountable for personal information you hand to a service provider, including an AI vendor. If a breach of security safeguards creates a real risk of significant harm, you must report it to the Privacy Commissioner of Canada and notify the people affected. You must keep a record of every breach for 24 months. Your mistakes clause (line 11) is what lets you meet that duty.
  • Quebec (Law 25). Before personal information is communicated outside Quebec, including to a cloud or AI provider, Quebec's private-sector law requires a privacy impact assessment. If you make a decision about a person based exclusively on automated processing, you must tell them. If you have Quebec clients or staff, raise both points with your adviser.
  • Alberta and BC have their own private-sector privacy laws (both called PIPA). The principles are similar. Check which law applies to which information.
  • Ontario health information (PHIPA). Clinics and other health information custodians have their own rules. Ontario's Information and Privacy Commissioner has said that entering personal health information into an AI scribe the custodian hasn't authorized is a privacy breach. That can mean notifying patients and reporting to the IPC.
  • Ontario job postings. Since January 1, 2026, Ontario employers with 25 or more employees must say in a publicly advertised job posting if they use AI to screen, assess or select applicants. A one-line statement is enough. Using AI only to help write the posting does not trigger it. Line 8 covers this.
  • Professional rules. Lawyers, accountants, engineers, insurance brokers and health professionals have confidentiality and competence duties of their own. Your policy can't be looser than those duties.
  • What's coming. A new federal privacy bill (Bill C-36) was introduced in June 2026. It is not law as of October 2026, so PIPEDA still applies. Plan to review your policy if it passes.

A next stepNot sure what your team already puts into AI tools? An AI security assessment finds out. Start with a free 30-minute call.

Roll it out in 30 minutes, not by email

A policy that arrives as an attachment gets skimmed once. Run a short session instead:

  1. Five minutes: explain why. People are allowed to use AI. This is how to do it safely.
  2. Fifteen minutes: go through three scenarios as a group and decide which policy line answers each one (see the table below).
  3. Ten minutes: questions. Write down anything the policy didn't answer and fix it in the next version.
Scenario to discussLines that answer it
"Can I paste this client email into Copilot to draft a reply?"2, 5 and 7
"A vendor's AI note-taker joined our call. Is that OK?"10
"I pasted a spreadsheet with employee SINs into the wrong tool."4 and 11

Post the never-enter list (line 4) where people work, and put the policy where people can find it in under a minute.

Common mistakes

  • A ban. People who already save time with AI will keep using it, just in personal accounts you can't see.
  • A policy with no approved tool. If the only answer is "no", the policy becomes a reason not to ask.
  • Copying a big company's 12-page policy. Nobody reads it, and it describes controls you don't have.
  • No owner and no date. AI tools change their features and terms often. A policy nobody reviews goes stale fast.

Where Hero fits

You can write this yourself with the template above. If you want help, Hero's AI security assessment finds out which tools and accounts are really in use and what goes into them. The AI use policy & secure setup then turns these headings into a policy in your words, with account settings to match. Hero writes in plain language. It doesn't give legal advice, so your lawyer or privacy lead should review anything that touches legal duties. Prices are on the pricing page.

Related: What not to put into AI tools · How to train employees to use AI · AI readiness checklist

Sources checked (October 7, 2026): Ontario, Your guide to the Employment Standards Act: publicly advertised job postings (ontario.ca) and O. Reg. 476/24 · PIPEDA s.10.1 and the Breach of Security Safeguards Regulations (laws-lois.justice.gc.ca) · Quebec, Act respecting the protection of personal information in the private sector, ss. 12.1 and 17 (legisquebec.gouv.qc.ca) · IPC Ontario, Artificial intelligence gone wrong (April 27, 2026) · Microsoft Learn, Copilot Chat privacy and protections · LEGISinfo, Bill C-36 (45-1).

A CLEAR NEXT STEP STARTS HERE

Want the policy written for your team?

An AI security assessment finds which tools and accounts are really in use. Then we turn the template into a policy in your words. Start with a free call.

Free 30-minute call with our founder · Video call, camera optional