Why Your Business Needs an AI Policy

Staff can already open ChatGPT, Copilot, a meeting notetaker, or a website bot. The company did not need to buy those tools for that to be true. Informal use is still the company’s use.

When there is no written instruction, each person decides what may go into a tool and what may leave the building as the company’s work. A downloaded template does not change that. Treating the tools as an IT problem does not change it either.

The business needs a short written AI policy because the tools are already in the building, and the company has no record of what it allows. This post explains why that gap matters before it explains what a short rule contains.

Why Informal Use Is Already Company Use

The tools are already in the building. Free ChatGPT, Copilot, meeting notetakers, and website bots do not wait for a purchase order. If a person can open them at work, the company is already using them.

Informal use is still company use. A website bot’s answer is the company’s answer. An AI-drafted clause is the company’s clause once it is sent. Air Canada’s public chatbot dispute is a usable example of that point. It is not a statement of Arizona law.

Without a written instruction, the company has no record of what it allows. Each person makes a different call about what may go into a tool. When someone later asks what the staff were told, the answer is a conversation. That conversation will not hold up as the company’s rule.

Existing consumer-fraud, confidentiality, employment, and contract rules can still apply after something goes wrong. A customer file in a consumer chatbot is a confidentiality problem. A chatbot promise is a contract problem. Personal information that leaks through a tool can become a notice problem. The company does not get a free pass because nobody wrote the instruction down.

A downloaded template does not close the gap. A SHRM or Attestly file that nobody trained on is not a record a judge or mediator will credit as this company’s actual instruction.

A Short Example

Consider a professional-services shop that already lets staff use consumer ChatGPT for drafts. A person puts a customer file into the tool to finish a letter faster. The letter goes back to the customer the same afternoon.

Nobody had written which tools were approved. Nobody had written that a customer file stays out of a consumer chatbot. Nobody read the letter as the company’s work before it left.

When someone later asks what the company allowed, the argument is about memory. That is why the business needs the written rule. The tool is not the problem. The missing instruction is.

What a Short Rule Makes Concrete

The rule is a written instruction the staff can follow on a Tuesday. It does not need six chapters.

It names the tools people actually use, including tools the company never bought. Free ChatGPT, Copilot, meeting notetakers, and website bots belong on that list if they are already in use. It says what must never go in: client and customer files, personal information, passwords, non-public strategy. If a file should not be emailed to a stranger, it does not go into a consumer chatbot.

A person then reads anything customer-facing, legal, financial, or contractual before it leaves the building. That includes a website bot. An AI-drafted clause is still the company’s clause.

Name who reviews the rule, and who gets told if a file already went into a consumer tool. One look at the main vendor’s terms—training on company data, confidentiality of prompts, ownership of output—is enough. Discipline belongs in the same handbook as the rest of the company’s rules.

What the Rule Is Not

Volume is not a policy. A forty-page “AI program” is not a rule a fifteen-person shop will follow. A downloaded SHRM or Attestly template is a starting point, not a record a judge or mediator will credit as the company’s actual instruction.

This article is not about Copilot or ChatGPT implementation. It is not a bias audit or a hiring-algorithm program. It is not a certificate, a badge, or “AI Act compliance.” It is not a guarantee that an insurer or a regulator will accept the paper. Ranked hiring tools belong in a separate employment-law file. A full healthcare or business-associate program belongs with someone who intends to own that work.

This is not legal advice to a particular reader. A company whose product is AI needs different work.

Arizona currently has no statute that forces a generic small business to adopt a named AI-use policy. Existing consumer-fraud, confidentiality, employment, and contract rules can still apply after something goes wrong, including Arizona’s breach-notice statute if personal information leaks. Those rules do not wait for a named “AI policy” statute.

That qualifier is not the reason to write the rule. The reason is that the tools are already in use.

A Practical Takeaway

If you are deciding whether the company has a workplace AI rule, ask whether you could produce a short written instruction of what the staff were told to do with these tools.

If the answer is a conversation, the company does not have a rule. It has a habit. Habits are hard to explain after a customer file, a chatbot promise, or a leaked record is already in dispute.

From the Bench

I am a former Pima County Justice of the Peace. In that work, a later dispute was easier to decide when the company could produce the instruction it actually gave, dated, in ordinary words. A template nobody trained on did not help. Neither did a long program nobody read.

Closing

A workplace AI-use rule is less dramatic than the tools. It is a short instruction, in ordinary words, for a business that already uses ChatGPT, Copilot, or something like them.

The company needs that instruction because the tools are already in the building, informal use is already company use, and there is otherwise no record of what the company allows.