A good company AI usage policy answers a handful of plain questions: which AI tools may staff use, what data may go into them, who checks the output, who owns the policy, and what to do when something goes wrong. It works best at one to three pages, written in everyday language, with an owner and a review date. This article is general information, not legal advice; confirm the final wording with your legal and compliance team.
Start with purpose and scope
Open with two or three sentences on why the policy exists: to let people use AI productively while protecting customers, staff and the company. Then say who it covers (employees, contractors, interns) and which tools it covers. Include AI features built into software people already use, not only chat assistants, because staff often do not realise those features count.
List the approved tools and how to request new ones
People will use AI whether or not you have a policy, so give them a sanctioned route. Keep an approved-tools list that names each tool, what it may be used for and which account type to use (for example, a company-managed account rather than a personal one). Add a short, quick process for requesting a new tool, with a named person who decides. A policy that only says "no" pushes usage out of sight.
Set clear data rules
This is the most important section. Classify your information into a few simple classes, such as public, internal, confidential and personal data, and state what may be entered into which approved tool. Cover at least:
- Customer, candidate and employee personal data, which also touches your obligations under Malaysia's Personal Data Protection Act. See our guide to AI governance and the PDPA.
- Source code, contracts, financial results and anything under a confidentiality agreement.
- Information belonging to clients or partners, which may be restricted by your agreements with them.
Where you are unsure how a data class should be treated, say so and send the question to your legal or compliance team rather than guessing in the policy.
Require human review of AI output
AI output can be fluent and wrong. State that a person remains accountable for anything they send, publish or decide using AI, and that output must be checked before external use. Match the level of checking to the risk: a brainstormed subject line needs little, a customer-facing figure or a legal clause needs a lot. Our guide on how to check whether AI output is accurate gives a practical method staff can follow.
Decide on disclosure and intellectual property
Say when AI use must be disclosed, for example when content is sent to customers, submitted to regulators or used in regulated advice. Add a line on intellectual property: who owns work produced with AI help, and what to check before reusing generated text, images or code. These are areas where the details depend on your contracts and sector, so mark them for review by legal counsel.
Prohibited and high-risk uses
Name a short list of things staff must not do, such as entering restricted data into unapproved tools, using AI as the sole decision-maker on hiring, credit or disciplinary matters, or presenting AI-generated content as verified fact. Also name higher-risk uses that need sign-off before starting. Keep the list short and concrete so people can remember it.
Explain how to report problems
Include a simple incident path: who to tell, how quickly, and what counts as an incident (for example, pasting confidential data into the wrong tool, or an AI error reaching a customer). Make it clear that honest reporting will be treated as helpful, not punished, otherwise problems stay hidden.
Name an owner and a review cycle
A policy with no owner goes stale. Name a role, not just a person, responsible for it, often shared between IT, legal or compliance and a business sponsor. Set a regular review date and a trigger for earlier updates, such as adopting a new tool or a change in regulation. AI tools change quickly, so a policy that is never revisited will drift away from what people actually do.
Pair the policy with training
A document nobody understands protects no one. Give staff short, practical training on the policy: what the data classes mean, how to review output and how to report an issue. Leaders also need to understand the decisions behind the policy. The governance domain of the Claude Certified Associate exam guide covers responsible-use basics, and Agmo's AI Forward CXO Program is aimed at senior leaders setting direction. For team-level sessions, see in-house training.
A one-page skeleton to adapt
- Purpose and scope
- Approved tools and how to request new ones
- Data classes and what each may be used for
- Human review and accountability
- Disclosure and intellectual property
- Prohibited and high-risk uses
- Incident reporting
- Policy owner and review date
- Training and acknowledgement
Start with this skeleton, fill it in with your own tools and data classes, and have your legal and compliance team review it before you issue it.