Your staff are already using ChatGPT. The question is whether they are using it with a work account and clear rules, or with a personal login and their best guess. A short handbook section fixes that faster than a long policy nobody reads.
Below is a sample you can adapt. It fits on one page, which is the point. Replace the brackets, then have legal and IT check it before it goes out.
Sample handbook section
USING CHATGPT AND OTHER AI TOOLS AT WORK
Why this exists
AI tools can save you real time. This section explains how to use
them without putting customers, colleagues or the company at risk.
Which tools
Use [ChatGPT Enterprise / Team] and [other approved tool] with
your work account only. Personal accounts and free versions are
not approved for work content, even for the same product.
You can
- draft and edit emails, documents and presentations
- summarise documents that contain no restricted data
- brainstorm, outline, and check your reasoning
- analyse data that has been anonymised
You must not
- enter customer personal data, passwords or access keys
- enter confidential client material or unannounced financials
- use AI output in hiring, pay or disciplinary decisions without
[HR] approval
- present AI output as checked fact without checking it
Before anything goes out
Read it yourself. You are responsible for anything you send,
whatever tool helped write it.
If something goes wrong
If restricted data goes into an AI tool, tell [IT security] the
same day. Reporting quickly will not count against you.
Questions
[Channel or inbox], answered within one working day.
Owner: [role]. Reviewed every six months.
Three choices to make before you publish
- Disclosure. Do staff need to tell clients when AI helped? Decide, then add a line.
- Other tools. Is it only ChatGPT, or Claude, Gemini and Copilot too? Name every approved tool.
- Personal devices. If people work from phones, say whether the app is allowed there.
Why this short version works
Staff ask three questions: can I use it, what can I put in, and who do I ask. Each has a line. Everything else, vendor assessment and risk registers, belongs in a governance document for the people who run it.
Questions people ask
Should we ban ChatGPT instead?
Bans tend to push use onto personal phones, where you have no visibility. Approving a work version with clear rules is usually safer.
Does this cover Copilot and Gemini?
Rename the heading to "AI tools" and list every approved product. The rules are the same.
Do contractors need to follow it?
They should. Add a line to contractor agreements pointing to this section.
Where to take this next
For the full policy structure, see the free AI policy template and our guide to rolling it out. The House Rules builds these rules into every AI assistant your team uses.
Leave a comment: