Think of two organisations in the same industry, facing the same wave of AI tools flooding their workflows. One has a formal AI policy: it defines which tools employees can use, what data they can share with AI systems, and where human judgement must stay in the loop. The other hasn’t formalised anything yet. People are using whatever tools they find helpful, making their own calls about what data to share, and no one has set any guidelines around it.
In a recent live webinar, Michael Werle, Director of HR Consulting Australia and a member of the Mentorloop Industry Advisory Council, sees this split constantly across the organisations he works with. Some are actively moving toward a formal AI position. Others acknowledge that AI is being used widely but haven’t made it official. “People are just going off and using it anyway,” he notes, “so there’s no clear policy on it.”
That gap between informal use and formal governance is where risk accumulates. And with the regulatory environment around workplace AI tightening across jurisdictions, it is a gap that is becoming harder to justify.
What is a workplace AI policy?
A workplace AI policy is an internal governance document that defines how employees can use artificial intelligence tools safely, responsibly, and in line with the organisation’s legal and ethical obligations. It sets out which tools are approved, how data should be handled, which decisions require human oversight, and what training employees are expected to complete.
Why "we'll figure it out" has become the riskiest position
The most common reason organisations delay formalising an AI policy is that things seem to be working well enough without one. But AI changes the cost of that delay.
Employees are using these tools regardless of whether guidance exists. A study conducted by the University of Melbourne and KPMG in early 2025 found that 48% of employees admit to using AI in ways that contravene company policies, including uploading sensitive information to public tools like ChatGPT or similar, in many cases without understanding that the data could be used to train the underlying model. Research from EisnerAmper in 2025 found that 60% of employees rely on free, consumer-grade AI tools rather than company-approved platforms, creating data exposure risks the organisation has no visibility over. Only 22% of organisations actively monitor how their people are using AI.
Without a policy, you do not have rules. And without a policy, another thing you don’t have is a feedback loop.
There is also a growing regulatory dimension to this. The EU AI Act explicitly classifies AI systems used in hiring, performance management, and employment decisions as high-risk, with binding compliance obligations phasing in through 2027. In the United States, state-level AI frameworks continue to multiply, and Australia’s voluntary AI framework is under increasing pressure to harden into compliance requirements. Organisations that establish internal governance standards now are shaping employee behaviour before regulators impose it. You do not want to be one of the organisations scrambling to retrofit compliance into habits that your teams have already formed.
Michael flags another risk that is easy to overlook: even well-intentioned AI use can create problems when employees do not know where the limits are. Some of his clients are wary about confidential information being entered into AI systems. A particular concern is that the data could be used for model training. However, without a policy explaining the difference between enterprise-grade tools with formal data protections and consumer apps without them, employees are left to make those judgement calls themselves.
What should a workplace AI policy include?
Formalising AI governance can feel like a huge, complicated endeavour and it’s for this reason that a lot of organisations push the can down the road. It doesn’t have to be though.
Publishing a basic policy now, even one that covers just five or six elements, is infinitely more useful than a comprehensive policy that is languishing in drafts.
Here are a few basic suggestions on what to cover:
| Element | What it covers |
|---|---|
| Approved and prohibited tools |
List which AI tools employees can use for work, and define how new tools get reviewed and added. Enterprise-grade platforms with formal data processing agreements behave very differently from consumer apps. It’s important your people understand that distinction as well.
|
ExampleMicrosoft Copilot and ChatGPT Enterprise are approved for internal use. Free accounts on ChatGPT.com, Claude.ai, or Gemini are not approved for work tasks. To request a new tool for review, submit a request via the IT help desk — allow up to 10 business days for assessment. |
|
| Data classification rules |
Define which categories of information can and cannot be entered into AI systems. Customer records, confidential financial data, employee information, and legally sensitive materials belong in the “do not enter” category. Michael identifies this as the element his clients find most urgent and the one that tends to produce the most serious consequences when it goes wrong so be sure to be extremely clear on what each category includes and why they are categorised as such.
|
ExamplePublic data (published reports, marketing copy) may be used in any approved tool. Internal data (strategy documents, financial projections) is approved for enterprise-grade tools only. Confidential data (client records, employee files, legal documents) must not be entered into any AI system without specific approval from IT and Legal. |
|
| Acceptable use cases |
Be equally explicit about what AI is authorised to do and what it is not. As a general example, drafting internal communications, summarising meeting notes, and generating first-draft reports are commonly approved. On the other hand, making employment decisions, producing client-facing legal or financial content without human review, and handling regulated data are not.
|
ExampleApproved: drafting internal communications, summarising meeting notes, generating first-draft reports, researching publicly available information. Not approved: making hiring or promotion decisions, generating client-facing legal or financial content without human review, processing any data subject to privacy regulation. |
|
| Human oversight requirements |
Specify which tasks and decisions cannot be delegated to AI systems, and define what meaningful “review before use” looks like in practice. Michael is direct on this point from an HR perspective: AI should support manager judgement in decisions about people, not replace it. That principle needs to be stated in policy, not left to assumption.
|
ExampleAny AI-generated input to a performance review must be reviewed and edited by the employee’s direct manager before it enters the formal record. AI may not be the sole input for a hiring, promotion, or termination decision — a named human must approve and take responsibility for the outcome. |
|
| Training expectations |
SHRM research finds 83% of HR leaders identify upskilling as critical in an AI-driven economy yet most organisations have no definition of what AI competency actually means, let alone what it looks like in practice. It’s important then to define what it means for an employee to be prepared to use AI tools in your organisation. This doesn’t necessarily mean requiring formal certification, but it does need to mean something concrete.
|
ExampleBefore using any approved AI tool for client-facing work, employees must complete the company’s AI Essentials module (approx. 2 hours) and have their manager confirm readiness. New starters complete this during onboarding. Completion is logged in the HR system. |
|
| Accountability and review |
Name the person or team responsible for the policy, set a review cadence, and define consequences for breaches. AI is evolving faster than most annual review cycles can accommodate so quarterly or biannual updates are more realistic in the current environment.
|
ExampleThis policy is owned by the People & Culture team and reviewed every six months. Suspected breaches should be reported to your line manager and P&C within 48 hours. A first breach results in a coaching conversation; repeated breaches may result in suspension of AI tool access pending a formal review. |
|
Why adoption is where most AI policies fall flat and how mentoring fixes it
Having a policy is step one. Getting employees to change or adapt how they work is the harder, slower problem.
Even where organisations have moved quickly on AI access, activation has consistently lagged behind. Deloitte’s 2026 research found that fewer than 60% of employees with access to approved AI tools use them regularly.
A policy document addresses access and tells people what they are permitted to do with which tools. However, it does not solve the activation problem because it doesn’t tell them how to use these tools well, safely, and in ways that actually improve their work within the framework the policy sets.
This gap is where structured mentoring can become incredibly useful.
Mentoring programs built around AI adoption give your people access to a trusted colleague who has already figured out how to work within the framework, and who can show what that looks like in practice within the context of their work.
A mentor who uses an approved AI tool in their daily workflow can demonstrate where the data rules matter, what human oversight should look like and why it’s important for your organisation’s specific use cases, and how to recognise when AI output is technically plausible but contextually wrong.
Personalised, ongoing learning embedded in real work helps make governance stick. Having someone actively helping your teams upskill in AI while playing within the confines of your organisation’s rules can be the difference between employees knowing the rules on paper and building the reflexes to apply them consistently.
Where to start if you don't have a policy yet
If your organisation doesn’t have a formal AI policy yet, the window to shape behaviour before it becomes entrenched is narrowing so it’s best to do this sooner rather than later. Here’s where to start:
Audit first. Find out what tools your employees are already using and for what. Survey teams, talk to managers, review network activity if you can. You can’t govern what you don’t know , and the audit will shape the policy you actually need.
Start narrow. You don’t have to start with a completely comprehensive document. Start with a clear, one-page document covering approved tools and your most crucial data handling rules. You can iteratively build towards a 20-page governance framework but while you’re waiting for that to clear legal review, you at least have the bones of your policy in place.
Involve the right people early. An AI policy touches HR, legal, IT, and increasingly, operations. So instead of routing a completed draft for sign-off, involve and consult with all stakeholders at the start. This dramatically reduces revision cycles and produces a document that your stakeholders will actively enforce in their respective functions.
Set a review cadence and assign ownership. Without a named owner who is officially responsible for the policy’s stewardship, it can be very difficult to keep it updated. So make sure it’s clear who owns this document, set a review cadence, and treat this policy as a living, working document instead of a finished project.
Pair the policy with a development plan. A policy only tells people the rules. You still have to help them build the capability they need to follow them well. Building a future-ready workforce means combining governance with investing in your people. Both are necessary for AI to deliver on its potential and for your teams to feel confident in using it safely and effectively.
Frequently Asked Questions About Workplace AI Policies
-
What is a workplace AI policy?
A workplace AI policy is an internal governance document defining how employees can use AI tools responsibly and safely. It typically covers approved and prohibited tools, data handling rules, acceptable use cases, human oversight requirements, and training expectations. The goal is to enable productive AI use across the organisation while managing legal, security, and ethical risk.
-
What should a workplace AI policy include?
At minimum, a workplace AI policy should cover approved and prohibited tools, data classification rules, acceptable use cases, human oversight requirements, training expectations, and accountability procedures. A focused policy covering these elements — even briefly — is more effective than waiting to produce a comprehensive document.
-
What are the risks of not having an AI policy?
Without a policy, employees make their own decisions about which tools to use and what data to share. Research from EisnerAmper found that 60% of employees rely on free, consumer-grade AI tools rather than company-approved platforms, creating significant data exposure risk. There are also growing compliance obligations in the EU, US, and other jurisdictions that require demonstrable AI governance.
-
Who is responsible for a workplace AI policy?
Responsibility typically sits across HR, IT, and legal. However, one function needs to own it. HR is well-placed to lead on the people-facing elements: training standards, acceptable use, and oversight requirements. IT and legal manage the technical and compliance dimensions. Without a named owner, policies tend to go stale as the landscape shifts around them.
-
How often should a workplace AI policy be updated?
At minimum every six months, and immediately following any significant change in the tools your organisation uses or in the applicable regulatory environment. AI is evolving faster than most annual review cycles can accommodate so treating the policy as a living document is the practical standard.
-
How do you make sure employees actually follow an AI policy?
Communication and onboarding training are necessary but not sufficient on their own. Organisations seeing the most consistent policy compliance tend to pair governance with structured learning. Mentoring in particular is effective because it builds the practical judgement employees need to apply policy in real, ambiguous situations, not just the awareness that the rules exist.
Have you built your workplace AI policy and are now ready to build read AI-readiness in your organisation?
Let’s chat! Book a demo with a mentoring program expert and see how Mentorloop can help you run a structured program that closes the gap between having governance on paper and having a team that’s truly AI-capable.


