AI Usage Policy

A usage policy has exactly one job: help an employee make a safe call in the moment — cursor blinking, deadline today. Policies fail in two familiar ways: so vague they answer nothing ("use AI responsibly"), or so long nobody opens them twice. The fix is the same for both — short enough to use, specific enough to enforce, and connected to the policies your company already has.

The specificity test

Compare:

Employees should exercise caution when sharing sensitive information with AI tools.

Customer personal data may be used only in the company Claude workspace, only for approved support workflows, and never in personal AI accounts. Unsure whether data qualifies? Ask #ai-help before pasting.

The first sentence cannot be followed or enforced — every reader decides privately what "caution" means, and each decides differently. The second can be followed by a new hire on day one. Write every rule to that standard: a reasonable person, mid-task, knows what to do next.

Five decisions the policy must make

  • Approved use. Which accounts, Claude surfaces, and user groups — and the common low-risk tasks people can adopt without asking. Naming what is encouraged matters as much as naming what is banned; silence reads as risk, and quiet non-use is a policy failure too.
  • Restricted and prohibited use. The data that needs extra controls or may never be entered, and the decisions Claude may assist with but never make: employment, legal, financial, safety.
  • Human accountability. Approval to use a tool is not approval to share every kind of data — and someone verifies claims, approves external sends, and owns connected actions. Name the roles.
  • Disclosure and records. When AI assistance is disclosed, and which prompts, outputs, approvals, or tool actions are retained — aligned with existing records policy, not invented from scratch.
  • Escalation. One well-known place for "may I use it for this?", for reporting problems, and for requesting new connections. If asking is slow or embarrassing, people stop asking; they do not stop using.

Three categories, one page

CategoryMeaning
ApprovedUse within stated accounts, data, and review rules
RestrictedUse only with named controls or approval
ProhibitedDo not use Claude for this data, decision, or action

Everything in this course maps onto these three words. If a proposed use does not clearly land in one, that is what the escalation path is for — and each escalation that gets answered becomes the policy's next example.

Practice

Draft one page for your organization that answers:

  1. Which Claude environments are approved?
  2. What information may not be shared, stated concretely?
  3. Which outputs require qualified review?
  4. Which actions always require approval?
  5. Where do employees escalate questions and incidents?

Route each section to the function that owns it — IT, security, privacy, legal, HR, business owners — for review of their part. A policy assembled from owned answers gets enforced; one written by a single author gets filed.

Definition of done

An employee mid-task can classify their use case, find the relevant rule, and name the accountable person — in under a minute, without interpreting a principle.