AI usage policy for your company

A one-page document your team will actually read. Answer eight questions and get finished rules you can print, pin up or drop into Slack.

Why it pays to write this down

Research by Experience Institute and Praca.pl (July 2026, N = 1636) found that only 27% of employees confirm their company has clearly defined rules for using AI. At the same time, just 16% ever stop to wonder whether the way they use these tools is legal — more than four in five never ask themselves the question at all.

The authors call this a management gap, not a technology gap. In practice it means company data ends up in random free tools — not because someone is breaking the rules, but because there are no rules to break.

An absence of rules does not stop people using AI. It makes them use it quietly, with no sense of the risk and nobody to ask.

Eight questions and you are done

Twenty-page policies tend to end up in a drawer that nobody opens. This is everything a team actually needs to hear. The full text is below — fill in the form and you will see it straight away with your own company name and the person people can turn to with questions.

Adds one line to the never-paste list — the only place where the rules differ between industries.

How you want to keep it

Static — download and done

nothing leaves your browser

Everything happens in your browser. Nothing is sent to a server, nothing is stored, we do not ask for your email. Print it or save it as a PDF and put it wherever you like.

Live — you will get a link

coming soon

Not built yet — we are working on it. Your rules will get their own address to paste into the intranet or pin in Slack; change them and the team sees the current version straight away, with the date of the last edit. This mode will require storing the text on our side, so it stays a deliberate choice: we will say plainly what we keep and let you delete it in one click. Until then the static mode works, and there nothing leaves your browser.

Your answers stay in this browser so a refresh does not wipe them. They are never sent to us — clearing the form removes them for good.

AI usage rules at [company]

In force from 5 September 2026 · Questions: [person], [contact]

You can

Use the approved AI tools for writing and editing, translation, tidying up notes, learning, analysing public data and working with code. This is an ordinary work tool, not something you need to hide.

Approved tools: ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, GLM (z.ai), DeepSeek, Kimi.

Never paste

Personal data about customers or colleagues, confidential documentation, passwords, keys and tokens, code covered by a client agreement, or anything marked confidential. If you are unsure whether something belongs on this list, it belongs on this list.

Ask first

Check with your manager before you use AI for a decision about a person — in recruitment, a performance review or anything to do with pay, prepare material that will go out under the company name, or want to use a tool that is not on the list above.

You own the output

A model can write something wrong in a perfectly confident tone — which is exactly why it is worth checking numbers, quotes, names and legal points before the material goes any further. A person signs off the finished work, not the tool.

Say so when it matters

If AI did a substantial part of the work and the reader would assume otherwise, tell them. This applies to analysis, opinion pieces and anything published under a person's name.

If something goes wrong

Say so straight away — nobody will hold it against you. Everyone clicks too fast sometimes. If something ended up in a tool that should not have, the sooner we know, the more can still be put right. A hidden mistake costs far more than a reported one.

If only one line survives, make it the last one. When people are afraid to admit a mistake they simply stay quiet, and then nobody gets the chance to react in time. Rules that do not frighten anyone work better than rules everybody dreads.

The questions people ask most

Is this legal advice?

No. It is a frame to fill in and a starting point for a conversation — with a lawyer, with your team, with the board. We make no claim that it puts you in compliance with the AI Act, the GDPR or anything else, because compliance depends on what you actually do with data, and eight questions cannot establish that.

Do you store what I type in?

In the static version, nothing at all. The form runs in your browser and the document is generated locally. In the live version we store only the text you typed, so it can be reopened at a permanent address — and you delete it with one click.

We already have a policy. Now what?

Compare it against the six blocks below. In practice the last two are usually missing: who owns the output, and what to do when someone gets it wrong. Without the second one people hide their mistakes, which costs more than the mistake did.

Why only one page?

Because nobody reads longer ones, and a policy nobody reads protects nobody. The problem was never a shortage of templates on the internet — it is that nobody rolls them out.

Does this work outside our country?

The core does. "Do not paste customer data into a free tool" means the same thing everywhere — the legal differences are in the details, not in the principle. That is why industry is a separate question rather than something hard-wired into the rules.

And if AI is going to talk to your customers too

FlashAI is an assistant that answers customers around the clock in 106 languages. Data stays inside your deployment, and before anything reaches the model, phone numbers, email addresses and tax or national ID numbers are swapped for placeholders — in other words, we apply the rule the never-paste block describes.

See how it works
Hi! 👋 I'm FlashAI. How can I help you boost your sales today?

FlashAI Assistant

Online

Powered by SymfoniX