AI Tool Usage Guidelines
Policy language for governing employee use of generative-AI tools. What data can and cannot be entered, and how to use AI safely at work.
Purpose and Scope
This policy establishes guidelines for the safe and appropriate use of generative AI tools (such as ChatGPT, Microsoft Copilot, Google Gemini, and similar services) in the workplace. It applies to all employees, contractors, volunteers, and partners who use AI tools for work-related tasks.
Approved AI Tools
Data You Must Never Enter Into AI Tools
Prohibited Data
- Patient Health Information (PHI): Names, diagnoses, treatment details, insurance information, or any data protected by HIPAA.
- Attorney-client privileged information: Case details, client communications, settlement information, or litigation strategy.
- Financial data: Bank account numbers, credit card numbers, financial statements, or tax information.
- Student records: Names, grades, disciplinary records, or any data protected by FERPA or COPPA.
- Donor information: Donor names, donation amounts, or contact information.
- Credentials: Passwords, API keys, security certificates, or access tokens.
- Proprietary information: Trade secrets, source code, internal procedures, or competitive strategy.
- Personal information: Social Security numbers, birth dates, home addresses, or other PII.
Safe AI Tool Usage
AI-Enhanced Threat Awareness
Attackers also use AI. Be aware of these AI-enhanced threats:
AI-Enhanced Threats
- AI-enhanced phishing: Flawless, personalized emails that reference real projects and colleagues. Focus on the request, not the grammar.
- Voice cloning: AI can replicate a person’s voice from 3 seconds of audio. Always verify financial requests by calling back at a known number.
- Deepfakes: AI-generated video or audio of executives making fraudulent requests. Verify through a different channel.
- AI-generated content used in social engineering attacks that appears highly legitimate.
Consequences of Policy Violations
Entering restricted data into public AI tools may constitute a data breach under HIPAA, GDPR, CCPA, or other applicable regulations. Violations of this policy may result in:
- Disciplinary action up to and including termination of employment
- Mandatory retraining on data handling and AI tool safety
- Regulatory notification requirements if protected data was exposed
- Legal liability for the individual and the organization
Need Help?
If you are unsure whether a task is appropriate for AI tools, contact IT or STM before proceeding. We can help you identify safe ways to use AI tools without exposing sensitive data.
STM can also help your organization deploy enterprise AI tools with proper data protection agreements in place.
These guidelines are a supplement to Module 09: AI-Era Threat Awareness and Module 06: Acceptable Use and Secure Browsing. Complete the full modules for interactive training and knowledge checks.