AI use policy for employees: what to include, with a one-page template
✳By Hero Published Sept 12, 2026 · Updated Oct 7, 2026
The useful detailsA workable AI policy fits on one page and answers six questions. Which tools and accounts are allowed? What information never goes in? What must a person check? Who decides anything about people? When do we tell clients or applicants? What do you do after a mistake? The template below covers all six. Fill in the brackets, have whoever owns privacy for your business read it, then walk the team through it.
Make three decisions before you write anything
A policy is a record of decisions. If the decisions haven't been made, the document will be vague, and people will ignore it.
Which tool, on which account. Name the product and the plan, for example "Microsoft Copilot Chat, signed in with your work account" or "ChatGPT Business workspace". The plan matters more than the brand. A free personal account and a business workspace from the same company can have very different terms. One is usually enough to start.
Which information is off limits. Decide in categories (see the template), not file by file. If you handle health information, payment data or anything under a client contract, decide those first.
Who owns it. One named person approves new tools, answers "can I paste this?" questions and updates the policy. Without an owner, the policy is out of date by the time the next tool update ships.
Covers employees, contractors and anyone using your accounts
Forgetting contractors and temps, who often bring their own tools
Approved tools and accounts
Moves work out of personal accounts and into accounts you control
Listing brands but not plans ("ChatGPT is allowed")
Never-enter information
Gives people a clear red line
Saying "don't share sensitive data" without examples
Allowed and not-allowed uses
Shows what "yes" looks like, not only "no"
Banning everything, which pushes use underground
Human review
Makes one person accountable for every output
"Check your work" with no list of what to check
Decisions about people
Keeps hiring, discipline, pay and credit decisions with a person
Leaving it out entirely
Disclosure
Says when you tell clients, applicants or the public
Saying nothing, then being asked by a client
Connected apps and note-takers
Covers AI that reads email, files or meetings, not only chat windows
Treating AI as a chat box only
Mistakes
Tells people what to do the same day, without fear
No path, so mistakes get hidden
Review date
Keeps the policy current as tools and terms change
No owner, no date
The one-page template
Copy this into a document. Replace everything in square brackets. Delete any line that doesn't apply.
[ORGANIZATION NAME] · Using AI at work · Owner: [NAME, ROLE] · Last reviewed: [DATE]
1. Who this covers. Everyone who does work for us, including employees, contractors and temporary staff, on any device.
2. Approved tools. You may use: [TOOL + PLAN, e.g. "Microsoft Copilot Chat signed in with your work account (look for the green shield)"]. Any other AI tool, browser extension, plug-in or meeting note-taker needs approval from [ROLE] first. Ask by [HOW, e.g. a message in #ai-questions].
3. Accounts. Use only accounts we provide. Do not use personal AI accounts for work content, and do not sign up for AI tools with your work email without approval.
4. Never enter, in any AI tool: passwords, access codes or API keys; Social Insurance Numbers, health card, driver's licence or passport numbers; bank or card numbers; health information about any person; [OTHER, e.g. "full client files", "anything under a confidentiality agreement or legal privilege"].
5. Only in approved tools, for approved tasks: client or employee names with details, internal financials, draft contracts, [OTHER]. If you are not sure which list something is on, stop and ask [ROLE].
6. Good uses. First drafts, rewording, summaries of material you are allowed to use, outlines, checklists, formulas, brainstorming. [ADD TWO EXAMPLES FROM YOUR OWN WORK.]
7. Human review. Before anything AI-assisted leaves your hands, check facts, figures, names, dates, quotes and sources against the original. The person who sends it owns it.
8. Decisions about people. AI does not decide hiring, discipline, performance, pay or credit. A person decides and can explain why. [If we use AI to screen, assess or select job applicants, our public job postings say so.]
9. Disclosure. [OUR RULE, e.g. "We tell a client when AI materially helped produce a deliverable, when they ask, or when their contract requires it."]
10. Connected apps and meetings. Do not connect AI tools to work email, calendars, files or the CRM without approval. Do not add an AI note-taker to a meeting unless everyone in the meeting has been told.
11. Mistakes. If something on the never-enter list goes into an AI tool, tell [ROLE] the same day: what, which tool, which account, when. Reporting is never punished. Hiding it is a problem.
12. Review. [ROLE] reviews this policy and the approved-tool settings every [6 MONTHS] and whenever we add a tool.
I have read this policy. Name: ______ Date: ______
Canadian rules worth checking before you finalize
This is general information, not legal advice. It shows which questions to ask whoever handles privacy or legal for you.
Federal private-sector privacy law (PIPEDA). It applies to most businesses outside Quebec, Alberta and BC when they handle personal information in commercial activity. You stay accountable for personal information you hand to a service provider, including an AI vendor. If a breach of security safeguards creates a real risk of significant harm, you must report it to the Privacy Commissioner of Canada and notify the people affected. You must keep a record of every breach for 24 months. Your mistakes clause (line 11) is what lets you meet that duty.
Quebec (Law 25). Before personal information is communicated outside Quebec, including to a cloud or AI provider, Quebec's private-sector law requires a privacy impact assessment. If you make a decision about a person based exclusively on automated processing, you must tell them. If you have Quebec clients or staff, raise both points with your adviser.
Alberta and BC have their own private-sector privacy laws (both called PIPA). The principles are similar. Check which law applies to which information.
Ontario health information (PHIPA). Clinics and other health information custodians have their own rules. Ontario's Information and Privacy Commissioner has said that entering personal health information into an AI scribe the custodian hasn't authorized is a privacy breach. That can mean notifying patients and reporting to the IPC.
Ontario job postings. Since January 1, 2026, Ontario employers with 25 or more employees must say in a publicly advertised job posting if they use AI to screen, assess or select applicants. A one-line statement is enough. Using AI only to help write the posting does not trigger it. Line 8 covers this.
Professional rules. Lawyers, accountants, engineers, insurance brokers and health professionals have confidentiality and competence duties of their own. Your policy can't be looser than those duties.
What's coming. A new federal privacy bill (Bill C-36) was introduced in June 2026. It is not law as of October 2026, so PIPEDA still applies. Plan to review your policy if it passes.
A policy that arrives as an attachment gets skimmed once. Run a short session instead:
Five minutes: explain why. People are allowed to use AI. This is how to do it safely.
Fifteen minutes: go through three scenarios as a group and decide which policy line answers each one (see the table below).
Ten minutes: questions. Write down anything the policy didn't answer and fix it in the next version.
Scenario to discuss
Lines that answer it
"Can I paste this client email into Copilot to draft a reply?"
2, 5 and 7
"A vendor's AI note-taker joined our call. Is that OK?"
10
"I pasted a spreadsheet with employee SINs into the wrong tool."
4 and 11
Post the never-enter list (line 4) where people work, and put the policy where people can find it in under a minute.
Common mistakes
A ban. People who already save time with AI will keep using it, just in personal accounts you can't see.
A policy with no approved tool. If the only answer is "no", the policy becomes a reason not to ask.
Copying a big company's 12-page policy. Nobody reads it, and it describes controls you don't have.
No owner and no date. AI tools change their features and terms often. A policy nobody reviews goes stale fast.
Where Hero fits
You can write this yourself with the template above. If you want help, Hero's AI security assessment finds out which tools and accounts are really in use and what goes into them. The AI use policy & secure setup then turns these headings into a policy in your words, with account settings to match. Hero writes in plain language. It doesn't give legal advice, so your lawyer or privacy lead should review anything that touches legal duties. Prices are on the pricing page.
Sources checked (October 7, 2026): Ontario, Your guide to the Employment Standards Act: publicly advertised job postings (ontario.ca) and O. Reg. 476/24 · PIPEDA s.10.1 and the Breach of Security Safeguards Regulations (laws-lois.justice.gc.ca) · Quebec, Act respecting the protection of personal information in the private sector, ss. 12.1 and 17 (legisquebec.gouv.qc.ca) · IPC Ontario, Artificial intelligence gone wrong (April 27, 2026) · Microsoft Learn, Copilot Chat privacy and protections · LEGISinfo, Bill C-36 (45-1).
A CLEAR NEXT STEP STARTS HERE
Want the policy written for your team?
An AI security assessment finds which tools and accounts are really in use. Then we turn the template into a policy in your words. Start with a free call.