Policy & governance · 7 min read

What Rules Should Employees Follow When Using AI at Work?

A practical employee AI-use policy covering approved tools, prohibited data, human review, verification, transparency, access, and incidents.

Wallai Insights cover graphic: Rules before rollout — What Rules Should Employees Follow When Using AI at Work?
The short answer

Employees should use only approved AI products and accounts, for approved business purposes, with permitted information. They must minimize personal and confidential data, verify important outputs, keep a person accountable for decisions, and report mistakes or incidents.

A small-business policy should answer daily operating questions:

  • Which AI products and accounts are approved?
  • Which tasks are permitted?
  • What information is prohibited?
  • When must personal information be minimized or de-identified?
  • Which outputs require human review?
  • How should facts and sources be checked?
  • When must AI use be disclosed?
  • Who handles exceptions and incidents?

This article is operational guidance, not legal advice. Policies must be adapted to applicable privacy, employment, human-rights, intellectual-property, professional, contractual, sector, and other legal obligations.

The principles behind the rules

Canada's privacy commissioners say organizations using generative AI must comply with applicable privacy laws. Their joint guidance calls for legal authority, appropriate purposes, necessity and proportionality, transparency, accountability, safeguards, accuracy, and privacy by design.[1]

The Office of the Privacy Commissioner of Canada's business guidance also recommends limiting the sharing of personal, sensitive, or confidential information and labelling when generative AI has been used in content or decisions.[2]

NIST's Generative AI Profile identifies risks including confabulation, data privacy, harmful bias, information security, intellectual property, and human over-reliance. It recommends governance, testing, monitoring, documentation, and incident handling appropriate to the use case.[3]

A practical small-business AI-use policy

The wording below is a starting template. It must be reviewed and adapted before adoption.

1. Use approved products and business accounts

Employees may use AI for company work only through products, plans, workspaces, connectors, and accounts approved by the organization.

They must not:

  • use a personal account for a business use case that requires an approved company workspace;
  • connect company systems or folders without authorization;
  • share accounts or authentication credentials;
  • bypass security, retention, access, or administrative controls.

2. Use AI only for approved purposes

The organization should maintain a list of approved use cases. Each use case should identify the purpose, users, information, workflow, reviewer, and output destination.

Employees should not expand an approved use to a different purpose, dataset, department, or decision without review.

3. Do not enter prohibited information

Unless the organization has explicitly approved the use case and controls, employees must not enter:

  • customer or employee personal information;
  • health, financial, identity, credential, or authentication information;
  • confidential business plans, contracts, legal advice, pricing, trade secrets, or non-public financial information;
  • client or partner information restricted by contract;
  • regulated or professionally privileged information;
  • copyrighted or licensed material the organization is not authorized to provide;
  • passwords, API keys, tokens, or payment details.

An approved exception should be documented and limited to the minimum information necessary.

4. Minimize and de-identify information

Use public, non-sensitive, synthetic, or de-identified information when it can accomplish the task. Remove unnecessary personal details and evaluate whether the remaining combination could still identify someone.

The privacy commissioners state that organizations should limit collection and use to what is necessary, proportionate, and appropriate for the stated purpose.[1]

5. Verify important outputs

Employees must not assume an AI answer is correct because it is fluent or confident. NIST uses the term "confabulation" for false or erroneous content presented confidently by a generative AI system.[3]

Before using an output, the reviewer should check:

  • factual claims against authoritative sources;
  • calculations against source records or a trusted calculation method;
  • quotations and citations against the original material;
  • customer, employee, product, policy, and legal details;
  • omissions, bias, and inappropriate assumptions;
  • compliance with company instructions and brand standards.

6. Keep people accountable for decisions

AI may support a decision only where the organization has approved that role and review process. A qualified person remains responsible for the decision and its consequences.

Canada's privacy commissioners state that accountability rests with the organization, not the automated system.[1]

High-impact decisions affecting employment, credit, health, insurance, housing, safety, legal rights, or access to services require specific legal and governance review before AI is used.

7. Protect intellectual property and confidential work

Employees must respect copyright, licence terms, confidentiality duties, client restrictions, and company ownership rules. They should not ask an AI system to reproduce protected material in a way the organization is not authorized to use.

Important external content should be reviewed for originality, source support, permissions, and brand or legal risk before publication.

8. Be transparent where required

The organization should define when AI use must be disclosed internally or externally. Factors include the materiality of the AI contribution, applicable law, contractual requirements, professional duties, platform rules, and the risk of misleading the recipient.

The Office of the Privacy Commissioner of Canada's business guidance recommends labelling when generative AI has been used in creating content or making decisions.[2]

9. Do not let AI act beyond its approval

Employees must not allow an AI system to send external messages, publish content, change records, approve payments, make commitments, alter permissions, or take other business actions unless that action and its controls are specifically authorized.

The approval should define authentication, permissions, review, logs, limits, exceptions, and a stop mechanism.

10. Report errors and incidents promptly

Employees should stop the affected workflow and report:

  • personal or confidential information entered into an unapproved system;
  • incorrect or harmful output used externally;
  • unexpected access to information;
  • suspicious prompts or instructions in connected content;
  • unauthorized system actions;
  • biased or discriminatory output;
  • a suspected security, privacy, or legal incident.

The report should go to the named internal owner. The organization should preserve appropriate records and follow its incident-response obligations.

What each approved use case should contain

Required fieldExample of what to document
Business purposeThe exact problem and intended outcome
Approved usersRoles or named team
Approved productProduct, plan, workspace, and connectors
Permitted informationSpecific data categories
Prohibited informationSpecific exclusions
InstructionsApproved process or prompt
Human reviewReviewer and checklist
Output destinationWhere approved work may go
RetentionHow inputs, outputs, and logs are handled
MeasurementAdoption, quality, and operational result
EscalationContact and stop condition

Rollout checklist for the owner

  • Obtain appropriate privacy, legal, security, and contractual review.
  • Inventory current employee use, including personal accounts.
  • Select approved products and administrators.
  • Define permitted and prohibited data.
  • Approve a small number of role-specific use cases.
  • Train employees using the real workflows.
  • Provide a clear way to ask questions and report incidents.
  • Review adoption, quality, incidents, vendor changes, and policy updates on a schedule.

Frequently asked questions

Can employees use AI for public information?

Public information can reduce some confidentiality concerns, but it still requires source verification, appropriate use, respect for rights and licences, and compliance with company policy. Publicly accessible personal information remains subject to privacy law in many contexts.[1]

Is a "do not paste confidential data" rule enough?

No. Employees need examples, approved products, permitted uses, review steps, escalation, and a decision owner. Ambiguous rules are difficult to apply during real work.

Should every AI-generated draft be disclosed?

Disclosure depends on the context and applicable requirements. The organization should define when disclosure is mandatory and obtain appropriate advice for regulated, contractual, professional, or public-facing situations.

How often should the policy be reviewed?

Use a schedule appropriate to the risk and review it when products, terms, integrations, laws, incidents, or approved use cases change.

Free 15-minute AI strategy call

Turn the policy into daily operating rules

A policy becomes useful when it is attached to real work. Wallai can help define the workflow, approved product, data boundary, human review, and owner for a first use case.[4]

Book the free 15-minute AI Strategy Call

Sources

  1. Office of the Privacy Commissioner of Canada, “Principles for responsible, trustworthy and privacy-protective generative AI technologies,” published December 7, 2023; modified May 6, 2025. priv.gc.ca
  2. Office of the Privacy Commissioner of Canada, “AI, privacy, and your business,” modified May 6, 2025. priv.gc.ca
  3. NIST, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” NIST AI 600-1, July 2024. doi.org/10.6028/NIST.AI.600-1
  4. Wallai, “Free 15-Minute AI Strategy Call,” accessed July 17, 2026. wallai.ca/strategy-call