Your employees are already using ChatGPT. They started months ago, without asking permission, on their personal accounts. Some use it to draft emails. Others paste customer data into it. A few might be treating it like a search engine for sensitive internal information.
The question isn't "should you allow it?" — it's already happening. The real question is: how do you set guidelines that protect your business without creating so much friction that people go back to using it in the shadows?
At Empire-HQ, we went through this exact challenge across our portfolio companies. Here's what we learned and the policy framework we use.
The Risk of Doing Nothing
Before we get to the policy, let's be clear about what's at stake when employees use AI without any guardrails:
- Data leakage. ChatGPT (and most AI tools) use the conversations you feed them for training. If an employee pastes customer PII, financial data, or trade secrets, that information becomes part of the model's training data. You can't get it back.
- Hallucinated facts. AI models confidently generate incorrect information. An employee who trusts ChatGPT for technical answers might ship code with security vulnerabilities, file incorrect tax forms, or send inaccurate legal advice to customers.
- Shadow IT. Without official tools and accounts, employees use whatever free tier they find. You have no visibility into what tools are being used, what data is flowing through them, or whether they comply with regulations in your industry.
- Inconsistent quality. Some employees become expert prompters. Others get poor results and conclude AI is useless. Without guidance, the quality gap widens instead of narrowing.
The risks are real, but banning AI outright creates worse problems: employees will use it anyway (often more recklessly), you lose the productivity gains, and you signal that your company is behind the times.
The Simple Policy Framework
Here's the framework we use. It has four parts, each with clear rules and examples. You can implement this in an afternoon.
Part 1: What Data Can Go In
This is the most important part of any AI policy. Employees need a clear, memorable classification of what data is safe to share with AI tools.
The rule: Use the "Red Light, Yellow Light, Green Light" system:
- Green (safe to use): Public information, general industry questions, drafting templates, brainstorming, grammar checking, summarizing public articles. Anything you could post on your company blog is green.
- Yellow (use with caution): Internal processes that are not proprietary, anonymized data, draft versions of public-facing content. Use enterprise accounts (not personal free tiers) and never include identifiers.
- Red (never paste): Customer PII (names, emails, phone numbers, addresses), financial statements, source code for proprietary products, trade secrets, passwords or API keys, legal documents, employee HR data, and any regulated data (HIPAA, GDPR, PCI).
Why this works: Traffic light analogies are intuitive. Employees don't need to memorize a rulebook; they just need to classify the data before they paste it.
Part 2: Which Tools Are Approved
Not all AI tools are created equal. Some offer enterprise data protection; others train on everything you give them. Create a short list of approved tools, each with a clear use case.
Our recommended starter list:
| Tool | Use For | Data Protection |
|---|---|---|
| ChatGPT (GPT-5.6, company plan) | General writing, analysis, research | Not trained on your data on paid/company plans — confirm in the vendor's current terms |
| Claude (Sonnet 5 / Opus 5, Team plan) | Long-form documents, analysis | Not trained on your data on Team/Enterprise — confirm in current terms. Claude 3 Opus is outdated. |
| GitHub Copilot | Code generation | Enterprise IP indemnity |
| Notion AI | Internal notes, wikis, docs | Data stays in Notion |
| Grammarly | Writing assistance | Business tier protections |
The rule: If it's not on the approved list, don't put any business data into it. Employees can experiment with personal accounts for personal use only.
Part 3: Verification Requirement
AI outputs look authoritative even when wrong. Every employee needs to know what to verify before using AI-generated content.
The rule: Verify AI outputs against these criteria:
- Facts: Verify names, dates, statistics, and regulatory claims against primary sources. AI is not a search engine.
- Code: Never use AI-generated code in production without code review. AI can generate code with security vulnerabilities that look correct.
- Numbers: AI is notoriously bad at math. Review any calculations manually.
- Customer-facing content: A human must review any AI-generated content before it reaches a customer.
Example policy language: "AI-generated content is a first draft, not a final product. Employees are responsible for verifying accuracy before using any AI output in their work."
Part 4: Disclosure
Should your team tell customers they used AI? This depends on context, but a simple rule helps:
The rule: If a customer would reasonably expect a human did the work, disclose AI assistance. If AI is used as a productivity tool (spellcheck, grammar, phrasing), no disclosure needed.
Examples:
- No disclosure needed: Using ChatGPT to draft a faster email reply, using Grammarly to fix typos, using AI to brainstorm meeting agendas.
- Disclose: Using AI to write a full consultant report, generating images for a client deliverable, creating code for a customer's product, translating customer-facing documents.
When in doubt, disclose. A simple "We used AI tools in preparing this deliverable, and humans reviewed all content" covers most cases without alarming clients.
Implementing the Policy
A policy is only useful if people actually follow it. Here's the implementation playbook:
- Write a one-page policy document. Not twenty pages. One page with clear rules and examples. Use the traffic light system as the centerpiece.
- Send it in an email. Brief announcement: "We're embracing AI. Here's how to use it safely." Attach the one-pager.
- Hold a 30-minute training. Walk through the traffic light system. Show examples of green, yellow, and red data. Demonstrate how to use your approved enterprise accounts.
- Set up enterprise accounts. Before the training, create accounts on your approved tools. Remove the friction of "I'll just use my personal account."
- Make it easy to ask questions. Designate someone as the AI policy contact. When employees aren't sure if something is green or red, they need a quick way to get an answer.
- Review and update quarterly. AI tools change fast. New tools appear, existing tools update their privacy policies, and your business needs evolve. Review the policy every 90 days.
What About the Ban-It-All Approach?
Some companies respond to AI risks by banning all AI tools outright. This is understandable but counterproductive:
- Enforcement is impossible. Employees access ChatGPT on their phones, on personal laptops, through browser extensions. You can block it on company devices, but you can't un-invent the technology.
- You lose competitive advantage. Companies that use AI effectively will produce more, faster, and cheaper than those that don't. Banning AI is like banning spreadsheets in 1990.
- You train people to hide. When you ban something useful, people use it in the shadows without training or guidelines. That's more dangerous than open use with guardrails.
Instead of banning, invest in education and infrastructure. A confident employee who knows the rules is safer than a scared employee who breaks them in secret.
A Sample One-Page Policy
Here's a template you can adapt:
[Company Name] AI Usage Policy
Our approach: We embrace AI as a productivity tool. These rules keep our data safe and our work quality high.
Data classification: Green = safe. Yellow = use enterprise accounts, no identifiers. Red = never paste into any AI tool. (See traffic light examples in the attached guide.)
Approved tools: [List 3-5 tools with enterprise accounts]. Use these for all business-related AI work.
Verify before using: Facts, numbers, code, and customer-facing content must be reviewed by a human.
Disclose when needed: If a customer would expect human work, disclose AI assistance.
Questions? Email [ai-policy@company.com].
That's it. One page, clear rules, zero ambiguity.
Looking Ahead
AI policies will continue to evolve as the technology matures. The companies that treat AI adoption as a skill to be managed — rather than a threat to be blocked — will be the ones that thrive.
Start with the simple framework above. Train your team. Review the rules regularly. And remember: the goal isn't to control every use of AI. The goal is to give your team the confidence to use AI effectively while understanding where the boundaries are.
Your employees are already using AI. Make sure they're using it the right way.