Internal AI use policy and team training
Your teams are already using artificial intelligence, with or without authorisation, and pasting into external tools information that should never leave the company. Banning it does not work and saying nothing does not either. We draft a short, workable policy —approved tools, information that never leaves, mandatory human review, labelling of generated content—, connect it to the internal work rules and train each department on cases from your own business.
The problem the policy solves
Where there are no written rules, every employee sets their own. One pastes a client's contract into a free assistant to get a summary; another generates a commercial reply and sends it unread; a third signs up for a tool on the department card. None of them acts in bad faith and all three expose the company. The policy does not exist to punish. It exists so people know what they may do, with which tools and under what review, and so the company can show it set those rules.
What it contains
A short document that can be read end to end and applied without translation. If it runs to forty pages, nobody will consult it on the day it matters.
- Approved tools. Which are allowed, which are not, and what has to happen for a new one to be approved, with a named owner.
- Information that never leaves. Personal data of clients and employees, information under confidentiality agreements, trade secrets, third party documents and anything the company cannot share without permission.
- Mandatory human review. Which deliverables do not leave the company until a person has checked them, and who that person is in each case.
- Labelling and traceability. When content generated or assisted by AI is identified as such, and what is kept as evidence of the review.
- Use in front of clients. What may be promised, what may not, and what the client is told when a system takes part in the service.
- A channel to propose new uses. Because a policy that only prohibits pushes the use underground.
- Consequences of breach. Written so they are enforceable and not a decorative warning.
Why the internal work rules have to be touched
A policy that is not built into the company's employment instruments will struggle to support any disciplinary consequence. We adjust the internal work rules, the confidentiality clauses and the onboarding documents so the obligation sits where it has effect, and we leave the record of communication that shows the employee knew about it.
Training by department
A single company-wide talk reassures the legal team and changes nothing in the operation. We prefer short sessions, by team, on cases people recognise as their own.
- Sales and customer service. What generated copy may promise, what binds the company towards the consumer and what gets checked before sending.
- Human resources. Candidate and employee data, automated filtering and the point at which a person has to decide.
- Finance and collections. Use of customer information, credit and collection decisions, and traceability of what the system suggested.
- Technology and operations. Tool procurement, access, data retention and incident reporting.
- Management and the board. The duty to supervise, which questions to ask and what to report to the governing body.
The minimum governance we leave installed
Compliance that cannot be demonstrated does not exist. We put in writing who answers for each system, who authorises a new one, on what criteria it is approved, where those decisions are recorded, how policy versions are controlled and what happens the day an incident occurs. If the company already runs SAGRILAFT, PTEE or another risk management system, we connect AI to that structure instead of creating a parallel governance that ends up contradicting it.
What the client receives
- The artificial intelligence use policy, drafted to be applied by people who are not lawyers.
- The amendments to the internal work rules and confidentiality clauses, with wording ready to adopt.
- The training sessions delivered by department, with materials and attendance records.
- The incident protocol and the template for recording decisions on new use cases.
- A one-page quick reference version, which is the one people actually use.
Let's solve your legal matter
Every case starts with an honest conversation. Book 30 minutes, no commitment.
Request the policy →