AI Tool Usage Guidelines

REFERENCE / 3-PAGE POLICY

AI Tool Usage Guidelines

Policy language for governing employee use of generative-AI tools. What data can and cannot be entered, and how to use AI safely at work.

Purpose and Scope

This policy establishes guidelines for the safe and appropriate use of generative AI tools (such as ChatGPT, Microsoft Copilot, Google Gemini, and similar services) in the workplace. It applies to all employees, contractors, volunteers, and partners who use AI tools for work-related tasks.

Approved AI Tools

Enterprise AI tools with data protection agreements are approved for work use. Examples include Microsoft Copilot for M365 and Google Gemini for Workspace.
Public AI tools (free ChatGPT, free Google Gemini, etc.) are NOT approved for use with organizational data.
Request new AI tools through IT. STM can help vet tools for security and compliance.
Check with IT before using any new AI tool for work tasks.

Data You Must Never Enter Into AI Tools

Prohibited Data

  • Patient Health Information (PHI): Names, diagnoses, treatment details, insurance information, or any data protected by HIPAA.
  • Attorney-client privileged information: Case details, client communications, settlement information, or litigation strategy.
  • Financial data: Bank account numbers, credit card numbers, financial statements, or tax information.
  • Student records: Names, grades, disciplinary records, or any data protected by FERPA or COPPA.
  • Donor information: Donor names, donation amounts, or contact information.
  • Credentials: Passwords, API keys, security certificates, or access tokens.
  • Proprietary information: Trade secrets, source code, internal procedures, or competitive strategy.
  • Personal information: Social Security numbers, birth dates, home addresses, or other PII.

Safe AI Tool Usage

Remove all sensitive identifiers before entering any text into an AI tool. If you cannot remove identifiers, do not use the AI tool.
Use enterprise versions when available. They have data protection agreements that prevent your data from being used to train the AI.
Verify AI output. AI can generate incorrect information (hallucinations). Always verify facts before using AI-generated content.
Do not use AI for legal or compliance advice. AI is not a substitute for professional legal or compliance counsel.
Do not use AI to generate or store passwords. AI providers may retain conversation data.
Document AI use in work products. If AI was used to draft or summarize content, note this for transparency.
Do not enter confidential company information into AI tools, including internal policies, procedures, or strategic plans.

AI-Enhanced Threat Awareness

Attackers also use AI. Be aware of these AI-enhanced threats:

AI-Enhanced Threats

  • AI-enhanced phishing: Flawless, personalized emails that reference real projects and colleagues. Focus on the request, not the grammar.
  • Voice cloning: AI can replicate a person’s voice from 3 seconds of audio. Always verify financial requests by calling back at a known number.
  • Deepfakes: AI-generated video or audio of executives making fraudulent requests. Verify through a different channel.
  • AI-generated content used in social engineering attacks that appears highly legitimate.

Consequences of Policy Violations

Entering restricted data into public AI tools may constitute a data breach under HIPAA, GDPR, CCPA, or other applicable regulations. Violations of this policy may result in:

  • Disciplinary action up to and including termination of employment
  • Mandatory retraining on data handling and AI tool safety
  • Regulatory notification requirements if protected data was exposed
  • Legal liability for the individual and the organization

Need Help?

If you are unsure whether a task is appropriate for AI tools, contact IT or STM before proceeding. We can help you identify safe ways to use AI tools without exposing sensitive data.

STM can also help your organization deploy enterprise AI tools with proper data protection agreements in place.

These guidelines are a supplement to Module 09: AI-Era Threat Awareness and Module 06: Acceptable Use and Secure Browsing. Complete the full modules for interactive training and knowledge checks.

Go to Module 09