GullyHR
Training

Half your team is already using AI. There is no policy.

Ganesh HS ·

In brief

  • A ban you cannot enforce produces the same usage, with less visibility and no guardrails.
  • The two real risks are what goes in — confidential data — and what comes out unchecked.
  • Classify by data sensitivity rather than by tool, because the tool list changes monthly.
  • Say who is accountable for the output: always the person, never the tool.

A services firm discovered, more or less by accident, that an analyst had been pasting sections of a client contract into a public chatbot to summarise them. She was not being careless in her own mind — she was under deadline pressure, the tool was obviously useful, and nobody had ever told her not to. There was no policy. There was not even an informal norm.

The reaction was a hurriedly circulated ban. Three months later the usage was identical and the visibility was worse, because people had simply stopped mentioning it.

Why the ban does not work

The tools are free, they are on personal phones, and they make a genuinely difficult task easier. A policy that says no, with no enforcement mechanism and no alternative, asks people to be slower for a reason nobody has explained to them.

What a ban reliably produces is the worst configuration: the same usage, now invisible, by people who will not ask a question when they are unsure because asking would admit the behaviour. The organisation loses its ability to see the risk without reducing it.

The alternative is not permissiveness. It is a small number of clear rules that people can actually follow, plus the training to follow them.

Classify the data, not the tool

Policies written around named products — this tool approved, that one not — are out of date within a quarter and become a list nobody reads. Writing the rules around what is being put in survives the churn.

Three tiers
RED    NEVER into any external tool
         Client data, contracts, personal data of
         employees or candidates, salary information,
         anything under an NDA, source code where the
         contract forbids it, medical or ID documents.

AMBER  Only into approved tools with a business account
         Internal documents, draft strategy, unpublished
         financials, meeting notes naming individuals.

GREEN  Anything goes
         Public information, generic drafting, learning,
         code snippets with nothing identifying in them,
         rewriting your own text for clarity.

Most day-to-day use is green, which is worth saying explicitly — a policy that reads as a list of prohibitions gets ignored wholesale, including the parts that matter. Naming the large permitted space is what makes the red line credible.

One test people can apply without consulting anybody: would you be comfortable if this text appeared on a public website tomorrow with your employer's name attached? It is imprecise and it resolves the majority of cases correctly in about two seconds.

The second risk: output nobody checked

Data going in is the risk that gets attention. Output coming out unchecked causes at least as much damage and is harder to spot.

These tools produce fluent, confident text regardless of whether the content is correct. A summary that quietly inverts a contractual obligation, a figure that was never in the source, a citation that does not exist — all of it arrives looking exactly like competent work. The reviewer's usual signals for sloppiness, which are mostly stylistic, are absent.

  • The person who sends it owns it. Every time, without exception. "The tool produced that" is not available as an explanation, and saying so once in the policy prevents a great deal of ambiguity later.
  • Anything factual gets checked against the source. Numbers, dates, names, obligations, quotations. If checking it would take as long as writing it, the tool was not the right choice for that task.
  • Nothing goes outside the business unread. Client-facing text, in particular, should be read start to finish by a human who is willing to be accountable for every sentence.
  • Say when it was used, where it matters. Analysis presented to a board or a client carries different weight depending on how it was produced, and the disclosure norm should be set deliberately rather than left to individuals.

What the policy should actually say

Short enough to be read. One page is achievable and two is the limit. It needs five things and nothing else.

  1. 1

    The three tiers, with examples from your business

    Generic examples do not transfer. "Client contracts" means something concrete in a services firm and something different in manufacturing, and the examples are what people remember.

  2. 2

    Which tools are approved for amber

    A short named list with business accounts where data is not used for training, and the name of the person who adds to it. A route to request a new tool matters more than the list, because the list will be wrong within months.

  3. 3

    The accountability line

    One sentence: the person who uses the output is responsible for it. This is the sentence that does the most work in the whole document.

  4. 4

    What to do after a mistake

    Somebody will paste something they should not have. A stated, non-punitive route to report it within 24 hours is the difference between finding out and not. Businesses that skip this line find out months later, from someone else.

  5. 5

    Who to ask

    A named person, not a mailbox. Most questions are five-second questions and they go unasked when there is nowhere obvious to put them.

Training is the part that changes behaviour

A circulated policy changes very little on its own. What changes behaviour is a short, practical session using the tools people already use, on the work they actually do.

The useful version covers three things: where these tools are genuinely good and where they are quietly unreliable, how to check output without spending more time than you saved, and a walk through the three tiers using real examples from the business. Ninety minutes is usually enough, and it is more effective than the policy document by a wide margin — which is the case for treating this as digital and AI workplace productivity capability-building rather than as a compliance exercise.

It is also worth training managers separately, because they face a question their teams do not: how to evaluate work when they cannot tell how it was produced. The honest answer is that they should assess the output on its merits and hold the person accountable for it — which is what they were always meant to do, and which most performance conversations have never been explicit about. Where a business has competency frameworks, this is worth writing into them rather than leaving as a verbal norm, and competency and talent management is where that definition belongs.

A note on what this article is not

Data protection obligations, contractual restrictions in client agreements, and sector-specific rules vary considerably and change. Nothing here is a legal position, and a policy that needs to stand up to a client audit or a regulator should be confirmed with a qualified professional before it is circulated.

What is safely within reach without legal advice is the readiness work: knowing which of your data is red, which tools people are already using, whether anyone has been told anything, and whether there is a route to report a mistake. Most businesses that think they have an AI policy problem in fact have not yet done that inventory.

Practically, that is a short exercise — ask each team what they use and for what, without consequence attached to the answer, and write down what comes back. It usually takes a week and it is the input to everything else, including deciding what digital and AI workplace productivity training should cover. Where it turns out the underlying problem is that nobody knows who owns which policy or how one gets updated, that is a governance gap rather than a technology one, and HR policies and governance work is the place it gets fixed.

Questions we are asked

Only if you can enforce it, which almost no business can while the tools are free and on personal devices. An unenforceable ban converts visible usage into invisible usage and removes your ability to manage the risk at all.

Related service

Digital and AI Workplace Productivity

Workplace behaviour and the management capability a growing business runs on.

Discuss a Custom Training Programme

Read next

Training

Why the Saturday training changed nothing

Good trainer, engaged room, excellent feedback forms — and no observable difference six weeks later. What went wrong, and what a training day needs around it.

Read the article
Exclusive Business Offer

Stop managing HR on spreadsheets and WhatsApp.

As your team grows, manual coordination leads to compliance risks and payroll errors. A free HR audit shows you where yours are.

Prefer the full picture? Request a free 360-degree HR audit.

Talk to an HR consultant

Your details stay private. No spam, ever.