Responsible Use of Generative AI at Work · Unit 5 of 5 · about 8 minutes

Unit 5: Your organisation's rules

The one idea this unit exists to teach

Your personal judgement about safe AI use, however good, operates inside your organisation's rules. Knowing where those rules live, and what to do when they do not exist yet, is the final habit of a responsible user.

Finding the rules that apply to you

AI rules rarely live in one tidy document. Check, in order:

  1. A dedicated AI or acceptable-use policy, in the staff handbook or policy library.
  2. Existing policies that cover AI without naming it. Data protection, confidentiality, IT acceptable use, social media and procurement policies all constrain AI use even if the word "AI" never appears.
  3. Your approved tools list: which tool, which account, which data. The practical core of most AI policies.
  4. Role and sector rules. Regulated professions, government-facing work, education and healthcare often carry sector rules above your employer's policy.

If you have never looked, budget ten minutes this week. Knowing the rules is part of the job now.

What the typical policy actually asks

Most workplace AI policies converge on five requirements this course has already taught: use approved tools with your work account; never input the never list; verify output before it leaves your hands; disclose where trust or rules require it; report incidents early, because a leaked prompt or a published fabrication gets more expensive with silence.

When there is no policy

Absence of a policy is not permission for anything, and it is not a ban on everything. It means the risk decisions have not been made for you. Two moves:

  1. Apply the floor rules from this course. The never list, the check-before-use routine and the disclosure test are safe defaults in any organisation.
  2. Ask, in writing, before high-stakes use. A two-line email ("I plan to use [tool] for [task]; the data involved is [description]; any objection?") converts your personal risk into an organisational decision.

If you are the manager receiving that email, that is your signal that your team needs a policy. Our course AI Policy for Organisations exists for exactly that moment.

Scenario: the missing policy

A school administrator wants to use AI to draft parent newsletters. There is no AI policy. She applies the floor rules: no student names or personal details in prompts, every draft reviewed before sending, and a one-line email to the principal describing the plan. The principal approves, then asks her to draft usage guidelines for all staff based on how she works. Six months later she is the school's de facto AI lead. Responsible use, practised visibly, tends to become policy.

Key takeaways

  • Rules live in four places: AI policy, older policies that still apply, the approved tools list, and sector rules.
  • No policy means the decision has not been made, not that it is yours to make alone for high-stakes uses.
  • The floor rules from this course are safe in any organisation.
  • Asking in writing converts personal risk into organisational decision.

Knowledge check

Q1. Your organisation has no AI policy. You want to use a free AI tool to summarise anonymised customer feedback for an internal report. What is the responsible approach?

Q2. Which existing policy most obviously applies to AI use even if it never mentions AI?