Acutis Gate logo Acutis Gate identity for AI at work

AI policy for the employee handbook: sample language

Short answer: keep the handbook section short and practical: what staff can do with AI, what they must always do (check the output, keep confidential data in approved tools, report mistakes), what they must never do (let AI decide about a person, get around access controls, impersonate anyone), and that AI use is logged. Point to the full policy for the details, and collect an acknowledgment.

This is the staff-facing companion to the AI acceptable use policy template. Replace each [bracket] and have HR review it.

Using AI at Work

Employee handbook section · [Organization] · See the full AI Acceptable Use Policy, number [###]

AI tools can make your work faster: drafting letters, summarizing long documents, answering questions and getting a first version on the page. [Organization] wants you to use them well and safely. Here is what that means day to day.

You can

  • Use the AI tools on the approved list, with your [Organization] account, for your everyday work.
  • Use AI to draft, summarize, brainstorm, translate, and check your writing.
  • Ask [IT] to review a new AI tool you would like to use.

Always

  • Read and check what the AI gives you before you use it. You own the final result.
  • Keep confidential information (anything about residents, students, patients or coworkers, health, money, legal or security matters) in the tools approved for it.
  • Tell your supervisor or [IT] right away if confidential information went into the wrong tool, or if an AI tool did something unexpected.

Never

  • Let AI make a decision about a person: hiring, discipline, benefits, services or eligibility. People make those decisions.
  • Use AI to reach information you could not open yourself, or to get around a security control.
  • Use AI to impersonate someone or to create fake images, audio or video.
  • Install AI apps or browser extensions on work devices without [IT] approval.

Good to know

  • AI use on [Organization] systems is logged, and your prompts and the AI's answers can be public records.
  • An AI tool connected to work systems can only see what you can see. If you cannot open a file, your AI cannot either.
  • Questions? Ask [IT contact] or [HR contact].

Acknowledgment

I have read the Using AI at Work section and the AI Acceptable Use Policy, and I agree to follow them.

Name: ____________________ Signature: ____________________ Date: __________

Sample language, not legal advice. Have HR and your attorney review it alongside your other personnel policies.

Tips for HR

  • Keep it to one page. Staff read dos and don'ts; the full policy holds the definitions and procedures.
  • Name the approved tools in an appendix or on the intranet, so "approved" is never a guess.
  • Say it plainly that AI use is logged. It sets expectations and supports public records requests.
  • Train before access. A short session on checking AI output and spotting confidential data prevents most problems.
  • "Your AI can only see what you can see" is only true if your IT setup makes it true. That is the job of an identity-aware AI gateway.

Make "your AI can only see what you can see" true

Acutis Gate runs every AI action with the employee's own access and logs it, so the handbook promise holds.

Start a 14-day trial Tour the live Gate

Frequently asked questions

Should an employee handbook have an AI policy?

Yes. A short "Using AI at work" section tells staff what is allowed, what to avoid and how to report mistakes, and points to the full AI acceptable use policy for details.

What should employees never do with AI?

Let it make decisions about people, put confidential data into unapproved tools, use it to get around access controls, impersonate anyone, or install AI apps on work devices without approval.

Do employees need to sign an AI policy acknowledgment?

It is good practice: a signed acknowledgment shows staff read the rules, the same way other handbook policies are acknowledged.

Can we tell employees AI use is monitored?

You should. Stating that AI use on organization systems is logged sets clear expectations and matches how most organizations handle email and network use.