Adapt the bracketed sections to your organisation, have leadership approve it, and share it with every staff member. Plain English on purpose.
1. Why we have this policy
AI tools (like ChatGPT, Claude, Copilot and Gemini) help us work faster. They also create risks: leaking confidential information, producing wrong answers that look right, and generating content that misleads. This policy keeps the benefits and manages the risks.
2. What you can use AI for
- Drafting and improving documents, emails and lesson plans
- Summarising publicly available information
- Brainstorming, planning and research starting points
- Writing or reviewing code (with human review before use)
3. What must NEVER go into an AI tool
- Personal information about staff, students, clients or donors (names, contact details, health, grades, records)
- Passwords, keys or system details
- Confidential business information: contracts, financials, unreleased plans
- Anything covered by a confidentiality agreement
Rule of thumb: if you wouldn't post it on a public noticeboard, don't put it in a prompt.
4. Check before you trust
AI tools make things up ("hallucinations") and state them confidently. Before acting on AI output:
- Verify facts, figures, quotes and references independently
- Have a human review anything sent outside the organisation
- Never rely on AI alone for legal, financial, medical or safety decisions
5. Approved tools
We use only tools approved by [role/team]: [list approved tools]. Want a new one? Ask [contact] — don't just sign up with your work email.
6. Disclosure
Be transparent when AI meaningfully contributed to work shared externally, per [organisation]'s standards.
7. If something goes wrong
Pasted something you shouldn't have? Spotted AI-generated misinformation about us? Tell [contact] straight away. No blame — fast reporting shrinks problems.