When other people are using it too
Most people read a page like this because something already happened. Somebody saw a customer list pasted into a chat window, or found out a proposal had been drafted by a tool nobody had approved, and the question stopped being should we use this and became what is already going on here.
If that’s you: the first move is not a rule. It’s finding out.
Start by looking, not announcing
Section titled “Start by looking, not announcing”You cannot write a useful policy for a situation you can’t see. Before anything else, ask the team what they’re using and what they’re using it for — and make it genuinely safe to answer.
That last part is the whole thing. If the first move looks like an investigation, you will get “nothing, really,” and you’ll write your rules against a fiction. Say plainly that nobody’s in trouble and that you’re trying to work out what to support.
What comes back is usually more mundane and more useful than expected: someone drafting the awkward emails, someone summarising long documents, someone who built a little process that quietly saves an afternoon a week. That list is worth more than any policy template — it tells you what your business actually needs, and who your first champion is.
They used a personal account because nothing else was on offer
Section titled “They used a personal account because nothing else was on offer”When you find people using their own accounts, treat it as a supply problem rather than a discipline problem. They were trying to get work done and nothing sanctioned existed.
Worth knowing, plainly: free and personal tiers generally treat what you paste differently from business and enterprise ones — retention, and whether your material can be used to improve the vendor’s models. Read the terms of whatever you’re on, once.
Then fix the supply. Providing one decent, paid, business-tier tool does more for your actual exposure than any amount of policy, because it removes the reason people went around you. A rule that competes with someone’s deadline loses.
Write one page, not forty
Section titled “Write one page, not forty”A policy nobody reads is not a control, it’s a document. Aim for something a new hire reads once and remembers.
The version that works looks less like a legal document and more like a short list of worked examples:
- What’s fine, by example — drafting, summarising, rewriting, brainstorming, checking your own work
- What needs a pause — anything with a customer’s personal details in it, anything under an NDA, anything you’d have to ask permission to email outside the company
- What isn’t allowed, and why in one clause — not a category list, an actual reason
- Which tool you’re paying for, and where to ask for access
- Who to tell if something goes wrong, with an explicit promise that telling them early is not punished
That last line matters more than the rest combined. The expensive version of every AI incident is the one somebody sat on for three weeks.
The one area where the rules are not yours to set
Section titled “The one area where the rules are not yours to set”Everything above is your judgement call. This part isn’t.
Decisions about people — hiring, promotion, discipline, pay, credit, who gets served and who doesn’t — carry specific legal obligations in a growing number of places. Notice to the person, sometimes an audit of the tool, sometimes a right to a human review. And the thresholds often don’t work how people assume: several of these rules apply regardless of how many staff you have.
We’re not lawyers and this varies by where you operate, so the useful advice is narrow: if you’re about to use one of these tools anywhere in a decision about a person, check your own jurisdiction before, not after. It’s a short conversation with someone qualified and a much longer one if you skip it.
The safe pattern in the meantime is the same one that works everywhere else: use it to prepare information for a human decision, not to make the decision.
They won’t believe it works until they watch it work
Section titled “They won’t believe it works until they watch it work”This is the part most people get wrong, and it costs more than any policy failure.
You will roll something out, tell people it’s working, and they will carry on doing it the old way and report back that it didn’t work. It’s tempting to read that as resistance. It isn’t. They’ve been told things work before.
Telling people does nothing. Put one real case through the system while they watch, then point at two more they can go and check themselves. That’s the entire trick, and it works where memos don’t, because it replaces your assurance with their own eyes.
Two things that follow from it:
Name a champion, and don’t let it be you. You won’t be the daily user and you shouldn’t be the one training everyone. Pick someone who does the work, who other people already ask for help, and give them the time — actual time, in their week — to become the person others go to.
Find out who your process really depends on. It’s frequently not the person on the org chart. If the only person who understands the new way of working leaves, you’ll discover it the week they do.
Where a rule does more harm than good
Section titled “Where a rule does more harm than good”Not everything needs governing.
If someone is using it to rewrite their own emails or make sense of their own notes, that is between them and their job. Policing that costs you goodwill and buys nothing, and it teaches people that the honest answer to “what are you using?” is silence — which is the one outcome that actually hurts you.
Govern where it touches other people’s information, money, or a decision about someone’s life. Leave the rest alone.
Before you automate anything
Section titled “Before you automate anything”There’s a difference between a team using these tools to work faster and a system acting on your behalf without a person in the loop. The second one deserves its own thinking, and the failure modes aren’t obvious.
→ What breaks, and how far it reaches
Running into something this doesn’t cover? Tell us.