Effective date: [DATE]
Owner: Chief AI Officer / Head of AI / Steering Committee Chair
Version: 1.0
Purpose
This policy defines what AI tools employees of [COMPANY] may use, what data they may input, and what obligations they carry.
Read this before using any AI tool for company work. Sign the acknowledgment at the end.
Scope
Applies to:
- All employees, contractors, and interns
- All AI tools — consumer, enterprise, API, open-source, embedded features
- All company data — whether accessed at work, at home, or on personal devices
The four rules
Rule 1 — Only approved tools for work
The approved tool list is at company/02-accounts-procurement/platform-account-order.md. Anything else requires Steering Committee approval before use with company data.
Rule 2 — Data classification, then tool
Every piece of company data has a classification: Public, Internal, Confidential, Restricted. Match the classification to the tool tier per data-classification-matrix.md. When in doubt, treat as more sensitive, not less.
Rule 3 — You are responsible for AI output
AI is a tool; you are the author.
Review every AI-generated output before it is sent, published, or committed.
You are accountable for accuracy, tone, and legal compliance of anything you approve.
Rule 4 — Report incidents immediately
If you paste sensitive data into an unapproved tool, receive suspicious output, or suspect a prompt injection, notify [SECURITY EMAIL] within 24 hours. No blame for reporting; blame for not reporting.
Explicit permissions
Employees may:
- Use approved AI tools for drafting, summarization, research, code assistance, and analysis
- Save prompt libraries locally or in company drives
- Build automations with approved tools within their team's remit
- Share AI-generated drafts internally for review
Explicit prohibitions
Employees may not:
- Paste customer PII into a consumer AI tool (free ChatGPT, personal Claude, personal Gemini)
- Paste source code with credentials or unreleased IP into any unapproved tool
- Send AI-generated communications externally without human review
- Represent AI-generated content as fully human-authored when accuracy matters (client deliverables, legal docs, medical/financial advice)
- Use AI tools to circumvent company policy (fabricating evidence, drafting deceptive communications, evading review processes)
- Build AI automations that send external communications without a human-in-the-loop approval step
- Share their AI account credentials
- Use personal AI subscriptions for confidential company work
Consequences
Violations follow standard disciplinary policy. Egregious cases (deliberate data exfiltration, deceptive use) may result in termination and legal action.
Amendments
This policy is reviewed by the AI Steering Committee quarterly and updated as the tool landscape evolves. Changes are communicated via all-hands and require re-acknowledgment.
Acknowledgment
I have read and understood this policy. I understand what I may and may not do, and I understand my obligation to report incidents.
Name: ___
Date: ___
Signature: ___
Plain-language summary (for orientation decks)
Only use tools on our approved list for work.
Confidential data goes only in Enterprise-tier tools with DPAs.
Never paste passwords, keys, SSNs, or client PII into consumer AI.
Steering Committee → CEO / GC (within 48 hours if A1–A3 with material impact)
Company → Affected parties (per legal guidance)
Company → Regulators (per statutory deadlines)
Tabletop exercise
Run a tabletop at least annually:
Choose an incident class
Announce the scenario to Security, Legal, IT, an AI Champion, and an executive
Time the response
Document gaps
Post-incident
Every material incident produces:
- Incident report — timeline, root cause, blast radius, remediation
- AUP update if a policy gap contributed
- Eval set update — the incident scenario added as a regression test
- Training update — the case incorporated into next quarterly refresh
Reporter protection
Reporters are protected from retaliation. First-time honest reports do not trigger discipline. Cover-ups do.
Anyone in the company can submit a request:
- New tool approval
- New use-case sanction
- New data type classification
- Policy question
Submit via [FORM URL]. Committee triages within 5 business days.
Public commitments
The Committee publishes internally:
- Approved tool list (up to date)
- Data classification matrix
- Policy changelog
- Quarterly summary (wins, incidents, spend)
Committee lifecycle
Formed at kickoff of AI program
Full charter (this doc) reviewed annually
Committee itself is reviewed by Executive Sponsor annually — dissolved if AI becomes fully embedded across departments (steady-state governance moves to existing functions)
Escalation from Committee
To Executive Sponsor — anything requiring exec approval, budget beyond charter cap
To Board — material regulatory risk, or AI use with strategic implications
A Data Processing Agreement (DPA) must be signed with every AI vendor that processes company data. Do this before rollout, not after.
What to require in every AI DPA
[ ] Zero-retention clause — vendor will not retain inputs beyond the request lifetime, or will retain only for a defined short period (e.g., 30 days for abuse prevention) and only in encrypted form
[ ] No-training clause — vendor will not train models on our inputs or outputs
[ ] Sub-processor list — vendor identifies all sub-processors and notifies of changes
[ ] Data location — where processing occurs; EU customers require EU residency options
[ ] Breach notification — vendor notifies within 72 hours of a security incident
[ ] Audit rights — right to request evidence of controls (SOC 2 Type II report at minimum)
[ ] Deletion on termination — vendor deletes all data within defined period after contract ends
[ ] Data portability — right to export data before termination
[ ] Liability caps — appropriate to volume and sensitivity of data
[ ] BAA addendum — if PHI is involved (HIPAA)
[ ] DPA appendix compliant with GDPR — if EU personal data
[ ] Standard Contractual Clauses (SCCs) — for cross-border EU-US transfers
Provider-specific notes
OpenAI (Enterprise / Team)
API zero-retention available (x-openai-organization header + request); Enterprise ChatGPT no-training default
Sign OpenAI DPA + BAA (if applicable)
Verify: SOC 2 Type II, CSA STAR
Anthropic (Claude for Enterprise)
No training on API traffic by default; verify in contract
Zero-retention for API available under Enterprise contract
Sign Anthropic DPA
Verify: SOC 2 Type II
Google (Gemini for Workspace / Vertex AI)
Existing Google Workspace DPA typically covers Gemini
Vertex AI has separate terms
Verify: SOC 2, ISO 27001
Microsoft (Copilot for M365 / Azure OpenAI)
Existing M365 DPA covers Copilot for Microsoft 365
Azure OpenAI has its own commitments (no data used for training)
Verify: HITRUST, SOC 2, ISO 27001
Perplexity (Enterprise Pro)
Zero-retention available under Enterprise agreement
Sign Perplexity DPA
Verify enterprise controls
xAI / Grok
Read current terms carefully — training defaults have changed multiple times
Confirm no-training in writing
Groq / OpenRouter / Together / Fireworks
Read their terms; they route to underlying open-weight models
Fewer certifications typically; use only for public/internal data unless verified
DPA request template
Send to vendor:
Subject: DPA request for [COMPANY] AI deployment
Hello [VENDOR],
We are preparing to deploy [PRODUCT] across [COMPANY]. Before rollout, we need:
1. Your current Data Processing Agreement (executable form)
2. Confirmation of zero-retention on [SERVICE TIER]
3. SOC 2 Type II report (under NDA)
4. BAA if we process PHI [yes/no]
5. Sub-processor list
6. Data residency options
Please share these and route to our legal team at [EMAIL].
Thank you.
Tracking
Maintain a register:
Vendor
Product / tier
DPA signed date
Zero-retention?
Sub-processors reviewed?
Renewal date
Owner
OpenAI
Enterprise
Anthropic
Claude Enterprise
Google
Gemini Workspace
Microsoft
Copilot 365
Perplexity
Enterprise Pro
Owned by: Legal or Vendor Management. Reviewed quarterly by Steering Committee.
Contract: Azure Enterprise Agreement + AI Services Product Terms
Perplexity
Perplexity Enterprise Pro
Default: no training on Enterprise Pro conversations
Verify: Admin settings → Data & Privacy
Contract: Perplexity Enterprise Agreement + DPA
Perplexity API
Configure per contract — request zero-retention explicitly
xAI Grok
Read current terms — default has changed multiple times
If used: only for Public data unless zero-retention is contractually confirmed
Verify quarterly
Groq / Together / Fireworks / OpenRouter
These providers route to open-weight models
Read each provider's data policy — most claim no training, but certifications vary
Suitable for Public / Internal data by default; Confidential only with contract review
Local / self-hosted (Ollama, vLLM, TensorRT-LLM)
Zero data leaves your infrastructure by definition
Suitable for all classes, subject to local security controls
Verification checklist per provider
After configuring, save these to the audit file governance/audits/YYYY-MM/:
[ ] Screenshot of the "no training" toggle set to off
[ ] Screenshot of the retention setting
[ ] Copy of signed DPA
[ ] Date of last verification
[ ] Owner (person responsible for re-verifying quarterly)
Quarterly re-verification
The Steering Committee's quarterly agenda includes:
- Walk through this document
- Confirm every provider still configured correctly
- Note any changes to vendor defaults (which happen)
If a vendor changes defaults in a way that increases retention or training, they must renotify per DPA; escalate immediately.