AI GOVERNANCE
Your employees are already using AI. What should your workplace policy say?
Give employees a safe, useful path for everyday AI work while protecting customer information, important decisions and organisational responsibility.

Somebody in your business may already be using an AI tool to rewrite an email, summarise a meeting, compare supplier proposals or prepare a customer response.
They may be doing useful work. They may also be pasting customer details, internal prices or an employment matter into a personal account because nobody has explained the boundary.
A workplace AI policy should not begin with the assumption that every use is dangerous or that every employee understands how the tools handle information. It should answer the practical question an employee faces in the moment:
May I use this tool, with this information, for this job—and what must I check before I use the result?
The policy should make safe work easier, sensitive work clearer and uncertain situations easy to escalate.
The executive answer
A useful workplace AI policy should state:
- why the organisation permits or restricts AI use;
- which tools and account types are approved;
- what information employees may and may not enter;
- which tasks are allowed, require approval or are prohibited;
- how every output must be checked;
- which decisions must remain with authorised people;
- how AI-assisted work should be recorded when necessary;
- what employees should do after a mistake or suspected disclosure;
- who can answer questions and approve a new use; and
- when the policy will be reviewed.
Do not make the policy a long lecture about artificial intelligence. Make it a decision tool people can use while working.
Why “do not use AI” is rarely a complete policy
A prohibition may be appropriate for a particular tool, dataset or high-risk process. A blanket sentence does not tell employees whether built-in AI in email, office software, search, customer platforms or meeting tools is included. It also does not provide an approved alternative for legitimate work.
The result can be hidden use, inconsistent judgement and missed opportunities to learn which tasks genuinely help the business.
On the other hand, “use AI responsibly” is too vague. An employee should not have to invent the organisation's definition of responsibility while a customer is waiting.
The policy needs examples, boundaries and a route for asking.
Begin with an honest inventory
Before writing rules, find out what is already happening. Ask teams which AI-enabled products they use, through which accounts and for what work.
Include AI features embedded in existing software, not only standalone chatbots. Your inventory might contain:
- writing and research assistants;
- meeting transcription and summary tools;
- design and image generators;
- spreadsheet and reporting assistants;
- customer-service or sales features;
- coding assistants;
- recruitment or HR tools; and
- AI features added to products the business already licenses.
For each use, record the tool, owner, users, information involved, output, affected people and current review. The purpose is to understand the actual work, not to run a trap.
Employees are more likely to disclose uncertain use when management explains that the inventory is intended to create workable guidance. If the first conversation is disciplinary, the next tool may simply become harder to see.
Use three practical policy zones
A green, amber and red model gives employees a quick first answer. The examples must be adapted to your organisation, systems, contracts and applicable law.
Green: permitted within normal checks
These uses involve approved tools, information the organisation permits and outputs with limited consequence.
Examples might include:
- brainstorming headings for an internal presentation;
- rewriting a non-confidential paragraph for clarity;
- summarising public information;
- preparing questions for a meeting;
- formatting an employee's own rough notes; and
- producing a first draft that a person will substantially review.
Green does not mean “no checking.” The employee still owns the facts, tone and final use.
Amber: approval or additional controls required
These uses involve internal, personal, customer or commercially sensitive information; an external audience; a significant decision; or a connection to another system.
Examples might include:
- summarising a customer conversation;
- analysing internal financial information;
- drafting a reply about an active order;
- recording or transcribing a meeting;
- comparing job applications;
- using approved company documents to answer staff questions;
- generating marketing material that makes product claims; and
- connecting an AI assistant to email, CRM, ERP or cloud storage.
Amber work may be allowed only in an approved enterprise account, with specific access, notice, consent, review or record-keeping. The responsible manager, privacy lead, IT or another named role should decide the controls before use.
Red: prohibited
Examples commonly requiring prohibition include:
- entering passwords, authentication codes or payment credentials;
- pasting information into an unapproved personal AI account;
- impersonating a customer, colleague or public figure;
- fabricating evidence, references, records or approvals;
- letting a tool make an unauthorised employment, credit, medical, legal or safety decision;
- sending an AI-generated customer commitment without required approval;
- bypassing copyright, licence, confidentiality or access restrictions;
- disabling safeguards or logs; and
- using AI to conceal misconduct or misrepresent completed work.
Some organisations will prohibit additional information and activities because of their sector. Name them explicitly.
| Employee question | Green example | Amber example | Red example |
|---|---|---|---|
| May I enter this information? | Public or approved non-sensitive text | Customer or internal information in an approved controlled tool | Credentials or information prohibited by policy |
| May I use this result? | Private draft checked by the employee | External or consequential output after required review | Fabricated record or unauthorised decision |
| May the tool take an action? | No external action | Prepared action waiting for an authorised person | Payment, dismissal or commitment without authority |
Define approved tools and accounts
The same product can present different conditions in a personal free account and an organisation-managed service. Do not write only “ChatGPT is allowed” or “AI is prohibited.” State:
- approved product and plan;
- permitted account or login method;
- approved devices or browser profiles;
- enabled and disabled features;
- information classifications permitted;
- retention and deletion expectations;
- whether submitted content may be used by the provider to improve services;
- available audit and administration controls; and
- the internal owner.
Product terms and settings change. Assign someone to review them, and date the approval.
If no suitable tool is approved for a task, give employees an alternative. “Do not paste the customer spreadsheet into a public chatbot; ask the data team for an approved analysis route” is more useful than a prohibition alone.
Set information boundaries employees can recognise
Do not assume every employee can translate legal or security categories into daily decisions. Provide familiar examples from your business.
| Information type | Examples | Policy direction |
|---|---|---|
| Public | Published website copy, public price list, public reports | May be used in approved tools, subject to normal checking |
| Internal | Draft plans, procedures, internal meeting notes | Use only where the approved tool and purpose allow it |
| Confidential | Customer records, supplier terms, non-public prices, financial results | Specific approval and controlled environment required |
| Highly restricted | Passwords, payment credentials, identity documents, health records, sensitive HR cases | Do not enter unless an explicitly authorised system and process exists |
Data protection obligations do not disappear because an employee used a convenient interface. Kenya's Office of the Data Protection Commissioner states that organisations processing personal data with AI should consider the scope of data-protection law, data-subject rights, safeguards and whether a Data Protection Impact Assessment is necessary. Read the ODPC statement on AI and personal data.
The ODPC also publishes guidance covering consent, impact assessments, cross-border transfers and particular sectors. See the ODPC guidance library.
This guide is operational guidance, not legal advice. The organisation should obtain appropriate advice about its processing, contracts, employees, customers and jurisdictions.
Keep consequential decisions with authorised people
AI can organise information or prepare a recommendation without becoming the decision-maker.
The policy should name decisions that require human authority. Depending on the organisation, these may include:
- hiring, discipline, promotion and termination;
- customer refunds, compensation and complaints;
- credit, pricing, discounts and payment;
- legal advice or contractual commitments;
- medical, safety or safeguarding decisions;
- tax and accounting treatment;
- public claims and crisis communication; and
- access to sensitive systems or information.
“A human is involved” is not enough. State which role must decide, what evidence they should see and whether the AI output is merely a draft or recommendation.
Where an AI agent can use business systems, apply a separate permission design covering read, recommend, prepare, act after approval and tightly bounded action. Garatropic's AI-agent permissions guide explains that distinction in detail.
Define the minimum human check
Employees need more than “check the output.” Give them a short review relevant to the work.
Before using AI-assisted work, confirm:
- Facts: Are names, amounts, dates, products and claims correct?
- Source: Can important statements be traced to an approved and current source?
- Missing context: Has the tool omitted an exception, qualification or previous decision?
- Authority: Is the employee allowed to make or communicate this decision?
- Information: Does the output reveal confidential or unnecessary personal information?
- Fairness and effect: Could the result treat someone unfairly or create an unexplained adverse decision?
- Promise: Does it create a price, delivery, refund, legal or other commitment?
- Tone and audience: Would the responsible employee be comfortable signing their name to it?
The check should become stricter as the consequence rises.
State when AI use must be disclosed or recorded
Not every spelling suggestion needs an entry in a register. Some uses need a traceable record.
Require recording when AI:
- materially contributes to a consequential recommendation;
- processes protected or sensitive information in an approved workflow;
- generates a customer-facing answer in a controlled process;
- uses a connection to another business system;
- supports a regulated or professionally accountable activity; or
- produces an incident, complaint or unexpected result.
The record might include the tool, date, purpose, source information, reviewer and final decision. Match the detail to the risk and existing organisational requirements.
Avoid disclosure theatre. A label stating “made with AI” does not correct an inaccurate result or create accountability. Record what helps people understand, challenge and manage the work.
Create a route for new tools and new uses
Employees will encounter useful features before the policy is updated. Give them a small request process rather than forcing a choice between delay and unapproved use.
Ask for:
- tool and provider;
- business task;
- intended users;
- information involved;
- output or action;
- people affected;
- expected benefit;
- required integrations; and
- proposed human check.
Review should be proportional. A public-information drafting aid should not wait behind a high-risk automated-decision system for three months.
The reviewer may approve, approve with conditions, request a controlled test or reject the use with reasons. Record the decision and review date.
Prepare for mistakes and incidents
An employee may paste information into the wrong tool, send an unchecked answer or discover that an AI feature was enabled unexpectedly.
The policy should say:
- stop the activity;
- preserve relevant evidence without spreading the information further;
- report promptly through a named channel;
- do not conceal or privately “fix” the incident;
- follow instructions from the responsible security, privacy, legal or management role; and
- document any customer, employee or regulator response required.
Early reporting gives the organisation more options. Do not write an incident rule so punitive that employees learn to remain quiet.
Worked example: replying to a customer complaint
A customer writes that an installation was delayed twice and damaged part of a wall. An employee wants an AI tool to make the reply sound calmer.
The relevant policy questions are:
- Is the tool and account approved?
- Does the message contain the customer's name, address, order information or photographs?
- May that information be used in this tool for this purpose?
- Can the employee remove unnecessary personal details?
- Is the tool preparing language only, or recommending compensation?
- Who may decide whether the company accepts responsibility, sends a technician or offers a refund?
- Who checks the final facts and promise?
A controlled use might provide the tool with a de-identified summary and approved facts, then ask it to prepare a courteous draft without admitting liability, inventing a visit date or offering compensation. The service manager reviews the case, decides the remedy and sends the final response.
The AI assists with expression. The responsible manager owns the decision and customer relationship.
A concise policy structure
A usable policy can follow this order:
- Purpose and scope — who and which tools it covers.
- Approved tools and accounts — where use is permitted.
- Allowed, controlled and prohibited uses — with real examples.
- Information rules — what may be entered and where.
- Human responsibility — checking, approvals and prohibited decisions.
- Transparency and records — when use must be disclosed or logged.
- New-use approval — a proportionate request route.
- Incident reporting — immediate actions and contact.
- Training and questions — practical support for employees.
- Owner and review date — who maintains the policy.
Have employees from several roles test the draft using realistic scenarios. If they reach different answers, clarify the policy before publication.
Train through decisions, not definitions
Employees need to practise situations such as:
- a customer sends an identity document in WhatsApp;
- a manager wants to upload performance reviews for summarisation;
- a salesperson wants a draft based on a confidential price list;
- an AI meeting tool joins a customer call;
- a built-in assistant asks permission to access the shared drive; and
- an employee notices that a generated report cites a source that does not exist.
Ask what they would do and why. Show the approved route. Definitions of machine learning can wait.
NIST's Generative AI Profile describes risks including confabulation, privacy, information security, harmful bias, human over-reliance and third-party dependencies. It is a voluntary risk-management reference, not a substitute for local law or sector requirements. Read the NIST Generative AI Profile.
Make the approved path easier to follow
The purpose of a workplace AI policy is not to prove that management has considered AI. It is to improve everyday decisions.
Give people an approved tool for suitable work. Explain the information boundary in familiar terms. Keep important decisions with authorised people. Make questions and incident reporting safe. Review the policy as tools, contracts, work and regulation change.
Employees should leave knowing both what they may do and where to stop. That is more useful than either enthusiasm without limits or a ban nobody can apply.
Research and helpful links
- Kenya Office of the Data Protection Commissioner: AI and data-protection compliance
- Kenya Office of the Data Protection Commissioner guidance library
- NIST Artificial Intelligence Risk Management Framework
- NIST Generative AI Profile
- UK National Cyber Security Centre guidance on adopting agentic AI
Research checked on 20 September 2026. This article is general operational guidance, not legal advice. Apply the laws, contracts, professional duties and sector requirements relevant to your organisation.
