AI Use Policy for [Business Name]
1. Why we have this policy
[Business Name] uses AI tools to save time and do better work. This policy keeps our clients' information safe, keeps our work accurate, and makes sure the people we serve can trust us.
It applies to everyone who works for or with [Business Name], on any device, whenever the work is ours.
2. The tools we approve
Only the AI tools on this list may be used for work. Each one is a business account, set so it does not train on our data wherever the provider allows it.
[Tool name]: [what we use it for]. Account owner: [name].
To add a tool, ask [Policy Owner] first. They check where it stores data and whether it trains on what we send.
3. What never goes into an AI tool
- Clients' personal information (names with contact details, home addresses, birth dates, health, financial or government identity details), unless the tool is approved for exactly that use
- Passwords, access codes, card numbers or bank details, ever
- Anything a client gave us in confidence, including contracts and pricing, unless the approved tool is set up for it
- Information about staff beyond what the task needs
4. What is fine
- Drafting emails, posts, proposals and documents that a person then checks
- Summarising our own notes and public information
- Brainstorming, outlines and research, with every source checked
- Formulas, templates and code that contain no client information
5. A person checks before it goes out
AI can be confidently wrong. Before anything written with AI reaches a client or the public, the person sending it checks every name, number, date, price and claim, and answers for it as if they wrote it alone.
AI never approves a payment, a contract, a refund or a reply to a complaint.
6. Telling people when AI is involved
Any AI that talks to customers directly, such as a phone or chat assistant, says it is an AI at the start. If a call is recorded, the caller is told at the start.
We never publish AI-made images, audio or video of a real person without that person's permission.
7. Where information goes
Some AI services store or process information outside Canada. Our privacy policy tells clients, in plain words, that their information may be processed in another country and may be accessible to that country's authorities.
Approved tools that process information outside Canada: [list them].
8. Accounts and access
AI accounts belong to [Business Name], never to one person. Two-step sign-in is on for every account that offers it.
When someone leaves, their access to every AI tool is removed the same day.
9. When something goes wrong
If client information goes into the wrong tool, or AI output causes a mistake that reached a client, tell [Policy Owner] the same day.
They decide what to fix, whether clients must be told and whether to report it, with advice where needed. Depending on which privacy law covers the business, telling the people affected and the privacy regulator can be required.
10. Review and sign-off
[Policy Owner] reviews this policy every six months and whenever a new AI tool is added. Last reviewed: [date].
I have read this policy and will follow it.
Name: ____________________ Signature: ____________________ Date: ____________
This template is a starting point, not legal advice. Privacy law depends on your business and your clients; for anything sensitive, have a lawyer read your final version.
