Policy · Updated July 2, 2026

A Lightweight AI Use Policy

One page. Two tiers of data and one ethos, that there is no AI work product, only AI-assisted human work product, and a human is accountable for all of it.

The one idea

There is no such thing as an AI work product. There is only AI-assisted human work product. Whoever puts their name on a piece of work owns all of it, every fact, every number, every claim, no matter whether they, a colleague, or a chatbot produced the first draft. That single principle is the whole policy. Everything below is how to live it.

Why this frees you

Once accountability sits squarely with the human author of record, the usual fears lose their grip. Hallucinations, uneven quality, a confident wrong answer, these are not new risks that AI introduced. They are the ordinary risks of any draft from any source, and you already know how to manage them, because you check the work before it leaves your hands. A chatbot is a fast, tireless, sometimes-wrong colleague. You would not forward a junior analyst’s memo to the board without reading it. Treat AI output the same way and you can use it for far more, far faster, because you are the backstop.

The two tiers of data

Most of what people call an AI policy is a data policy in disguise. Keep it simple enough to hold in your head. The sensitivity of the information decides the environment it is allowed to enter.

  • Tier 1, Confidential. Anything business-confidential: unpublished results, program data, sequences, patient information, financials, legal matters, anything under an NDA or partner agreement, anything not yet public. Tier 1 information goes only into contracted, enterprise-secure environments that [Company] has approved for that class of data. Never a personal or consumer account.
  • Tier 2, Open. Public or non-confidential information: published literature, general knowledge, marketing copy, anything already public or that safely could be. Use any approved tool freely, and explore. The risk is low and the upside is high, so the default here is yes.

If a person cannot say cleanly which tier a piece of information belongs to, that is a classification question to resolve first, not a reason to freeze.

On trusting your contracts

The hardest Tier 1 question is whether an enterprise agreement is really enough to protect your data. It is a fair question, and it deserves to be settled once, deliberately, up front, not relitigated on every use.

Responsible innovation means not reopening settled debates out of principle. If [Company] has done the diligence and holds an enterprise agreement that a vendor will not train on or retain your data, then decide, and let people work. But be honest that a contract is one control, not the whole story. The full picture is the control environment around it: access controls, retention and residency, subprocessors, incident response, and monitoring. Frameworks like the NIST AI Risk Management Framework exist to map that terrain, and for regulated records the standards below govern. If you do not trust the arrangement, you do not have a tooling problem, you have a Permission problem, and the work is on the front end, choosing vendors, terms, and controls you can stand behind. Do that once, then get out of your people’s way.

What you still owe the work

Accountability is total, so a few duties come with it.

  • Verify before it leaves you. Facts, figures, citations, and quotes are yours to confirm. AI is a strong first draft, never a source of record.
  • Name the human on consequential work. For anything that becomes part of an official record, a regulatory submission, a clinical judgment, a legal position, a published result, a specific person owns the decision and a human reviews before it ships. Higher stakes, more review.
  • Disclose where it is material, not everywhere. You do not caveat every email. But where the origin of the work matters to the reader, the scientific record, a regulatory filing, be transparent about AI assistance.
  • When in doubt, ask. [Name or role] is the person to ask before, not after. Asking early is always the right call, and it is never held against you.

What this policy is not

It is not a surveillance program and it is not a ban. It is a one-page employee quick guide, the layer people actually read, and it sits inside a fuller governance architecture your quality, security, and legal functions own: provenance, access controls, retention, subprocessors, validation, incident response, and monitoring. This page makes people accountable and fast; it does not replace that control standard. The goal is more capable people doing better work, and accountable for all of it.


Adapt the bracketed items for [Company], approve your environments and your point of contact, and this is ready to use. Keep it to a page. If it grows, it stops getting read.

Sources and further reading