AI adoption is likely already happening inside your company, whether leadership has formally introduced it or not. Employees are experimenting with generative AI tools like ChatGPT, Claude, Copilot, and other AI technologies to research topics, summarize information, draft content, analyze data, and get their work done faster.
There is a name for this: shadow AI. It describes employees using AI tools the company has not vetted, approved, or in many cases even heard about. It is rarely malicious. It is a natural gravitation toward new, genuinely useful tools that are just one browser tab away, even if official guidance hasn’t yet been provided.
Organizations have an opportunity to get ahead of shadow AI. Realistically, employees aren’t going to wait for your company to figure everything out before using the tools. Releasing a coherent AI usage policy can give employees clear guidance, encourage responsible use, and reduce unnecessary risk. As AI usage evolves within your company, you can adjust your policy accordingly.
Start With a Candid Conversation
Before you write a company AI policy, find out what people are actually doing.
Talk to your team about the tools they are using and how they are using them. Understand the habits that have already developed. These conversations will help inform specific guidance to include in your AI policy and the areas of risk to which your company might already be exposed.
The best approach is to acknowledge the reality head-on. Everyone is figuring this out right now. You do not need to have every answer, but you do need enough understanding of current behavior to give people useful direction.
It helps to make clear that this is not an audit. If people believe the goal is to catch them, you will get a sanitized answer and learn nothing. Ask what is working, what saves them time, and where they were unsure whether something was allowed.
Put a Clear AI Usage Policy in Place
Once you understand what is happening, create a policy that is clear, easy to follow, and easy to understand.
The purpose is to guide people toward responsible use in the workplace. Employees should understand your expectations and, if your company has a preferred AI tool or platform, which one they should use for work.
The policy does not need to solve every possible AI question. The technology is changing too quickly for that. It does need to give people a common starting point so they are not each making their own decisions about AI use without any guidance from the company.
The complexity of your AI policy will depend on your industry. Organizations in the financial or healthcare spaces will require strict instructions and guidance to ensure they remain in compliance with HIPPA and other regulator standards. For companies that operate in less regulated industries, more basic guidance about which tools are approved for use along with some guidelines for how to use the tools responsibly might suffice.
A document nobody is responsible for goes stale quietly. Your AI policy should be dated and have an owner who is responsible for updating it as needed. A quarterly review is reasonable given how quickly these tools change.
Make Security Part of the Policy
Data security is one of the most important considerations when people use AI at work.
Vague guidance like, “Be careful with sensitive information”, leaves every employee to determine their own risk tolerance. You might want to specify categorically, for example, client data covered by NDA or contract, personally identifiable information, protected health or financial records, source code, unreleased financials, credentials, and anything else living in a system with access controls around it.
Client confidentiality deserves particular attention. Much of the information your team handles day to day belongs to someone else, which raises the stakes beyond your own risk tolerance. Your obligation to existing client agreements that address third-party tools and data handling does not pause because a new category of tool showed up. Review the settings and terms of the AI models and tools you use to understand what happens to the information you enter and whether you can customize data-sharing settings.
This is where free and paid tiers genuinely differ. Consumer tiers of many AI tools may use what you enter to train future models, while business and enterprise tiers typically commit not to. Business tools typically provide administrative controls, audit visibility, and adjustable data retention settings. Confirm the specifics for whichever tool you choose rather than assuming. For business use, the modest monthly cost of an appropriate paid plan is usually worth the difference in control.
Best practice is to include your technical team in the conversation as well. Ask them to identify any obvious, low-hanging risks you can address up front rather than waiting until a problem appears.
Remember That AI Still Makes Mistakes
These tools are fast, capable, and productive across a remarkable range of work. They also get things wrong, and they tend to do so confidently.
That is why human review is still important. People need to work with the technology, check its output, and apply their own judgment before sending something into the world.
Your policy should reinforce that basic expectation. AI can assist with the work, but the person using it still needs to apply judgment. If the information matters, check it. If the tone matters, review it. If you would normally be accountable for the work, using AI does not change that accountability.
This is especially important because AI-generated content can sound perfectly reasonable even when the underlying information is incorrect. Responsible use means treating the output as something to evaluate, not something to accept automatically. The risk scales with the stakes, so it is worth naming the work where review is non-negotiable: anything going to a client, anything with a number on it, anything with legal or regulatory weight.
Give People Room to Learn
AI is accessible at many different levels. You can be a database engineer doing highly technical work or you can be a functional business user interacting with a chatbot. You do not need a coding background to get value from these tools.
If you want your team to develop AI skills, one of the simplest things you can do is give them an opportunity to try it. As people experiment, they develop a better understanding of AI capabilities, where it is useful, and where human judgment is still needed. Once people begin using AI, they start learning where it falls short, and how the way they ask a question affects the answer they get.
A policy should create boundaries for responsible use, but it should also give people enough room to build confidence with the technology. Boundaries that are too tight tend to produce more shadow AI, not less. If the approved path is slower than the unapproved one, people will quietly take the faster path and stop telling you about it.
Help People Use AI Responsibly
You do not need a finished AI strategy to set basic expectations. Shadow AI is already in your organization, and the practical question is whether it happens with guidance or without it. Start with a conversation, write something short, name what cannot be shared, and revisit it as your team learns.
InfoWorks’ AI strategy consultants can help you think through responsible AI use, identify potential risks, and establish guidance that fits the way your team is beginning to use AI.