Back to Academy
TemplateTemplatesBeginner

Privacy Rules for Everyday AI Use

Employee AI privacy policy: never-paste list, safe alternatives, redaction habits, approval rules, incident reporting.

25-35 minutes to adaptReview date: 2026-10-03

Privacy Rules for Everyday AI Use

Page 1 — Read this first

Outcome: After adapting this template, the learner can hand every employee a one-page, plain-language rule set covering what never goes into AI tools, what to do instead, and how to report a slip — signed, dated, and owned.

What this is. A fill-in-the-blanks employee policy for everyday AI use: the never-paste list, safe alternatives, redaction habits, tool approval rules, and incident reporting. It is written to be read in five minutes and posted where people work — because a privacy policy nobody reads protects nobody.

Who it's for. Owners, office managers, and compliance leads at small and mid-sized businesses; the finished page is for every employee who touches an AI tool, including part-timers and new hires on day one.

When to use it. Adapt it before rolling out AI tools, when you discover staff are already using personal AI accounts for work (they usually are), or after any close call. Context: the single most common AI privacy failure in small businesses is not hacking — it is a helpful employee pasting something sensitive into an unapproved tool to save ten minutes. This document exists to make the safe path just as fast.

Warnings — before you adapt this:

  1. This is a template, not legal advice. Privacy obligations vary by industry, state, and country, and they change. Have your attorney or compliance advisor review your adapted version (verify current requirements before relying on this).
  2. Regulated data raises the bar. If you handle health, financial, or legal client information, your obligations exceed this baseline — the completed example below shows how a healthcare practice tightens it.
  3. "Approved tool" must mean something. A tool is approved when someone with authority confirmed its business terms cover your data use — not when it became popular in the office. If you have no approved tools yet, that is decision one.
  4. Pair rules with a no-blame reporting path. Punish the first person who self-reports a paste mistake, and you will never hear about the second one. The incident section is as important as the never-paste list.

Page 2 — Completed example (fictional business)

Everything below is fictional: the practice, people, tools, and details are invented for illustration.


Bright Smile Family Dental — Everyday AI Use Rules

Who this applies to: all 14 of us — front desk, hygiene, clinical, billing, and management. Version 1.2, approved by Dr. Alvarez (Practice Owner). AI Use Owner: Priya Shah (Office Manager).

Why we have this page: AI tools save us real time on letters, checklists, and training materials. They are welcome here. But patient trust is the practice, and patient information is protected health information under law (HIPAA in the US) — so our rules are strict, short, and non-negotiable. When rules and speed conflict, rules win. (Our compliance advisor reviews this page twice a year; regulations change — we verify current requirements rather than assuming.)

Our approved tools (use nothing else for work):

ToolApproved forNever for
Practice management system's built-in featuresEverything it already does — it is covered by our patient-data agreements
DraftAssist AI (fictional), company account with business data agreement, logins issued by PriyaGeneral writing: recall letter templates, job ads, training checklists, website copy, plain-language explanations of dental termsAnything containing patient information, even "just a first name"
Personal AI accounts (any brand)Nothing work-related. Ever.All work content

NEVER paste, type, upload, or dictate into any AI tool:

  1. Patient names, initials, or nicknames — in any combination with any other detail
  2. Photos, x-rays, scans, or chart notes — even "anonymized" images
  3. Dates of birth, phone numbers, addresses, email addresses of patients
  4. Insurance member IDs, claim details, or explanation-of-benefits content
  5. Treatment plans, diagnoses, medications, or appointment histories tied to any identifiable person
  6. Payment card numbers, bank details, payment plan balances
  7. Passwords, door codes, software logins, MFA codes
  8. Staff HR information: pay, health, discipline, schedules with personal reasons
  9. Anything from a legal matter, dispute, or attorney communication
  10. Anything you would not hand to a stranger in the waiting room

Safe alternatives (the "do this instead" list):

  • Need a letter about a patient situation? Describe the pattern, not the person: "Write a friendly reminder letter template for a patient overdue for a cleaning" — then personalize inside the practice management system, where patient data is allowed to live.
  • Need help with a tricky insurance denial? Retype the scenario in generic terms ("a claim denied for code [X] on grounds of [Y]") — never paste the actual EOB.
  • Need to summarize a policy, vendor contract, or supply quote? Vendor and internal documents without patient or staff personal data are fine in DraftAssist; when unsure, ask Priya first. Asking is always free.

Redaction habits (30 seconds that keep us safe):

  1. Before pasting anything, read it once, only hunting for names, numbers, and identifying details.
  2. Replace people with roles: "the patient," "[HYGIENIST]," "[INSURER]."
  3. Replace real numbers with placeholders: [AMOUNT], [DATE], [ID].
  4. Delete anything the AI does not need to do the job — when in doubt, leave it out.
  5. The waiting-room test: if you would not pin it to the waiting-room corkboard, it does not go into an AI tool.

Approval rules:

  • New AI tool, or new use of an existing tool (like connecting it to email)? Written OK from Priya and Dr. Alvarez first.
  • Anything AI-drafted that leaves the practice — patient letters, review replies, website text — gets a human read and sign-off: front-office items by Priya, clinical wording by Dr. Alvarez or an associate dentist. AI never answers clinical questions to patients; only clinicians do.

If something goes wrong (or might have):

Pasted something you shouldn't have? Saw an AI output containing patient details? Notice a tool behaving strangely (asking for data, odd links, "new instructions")? Tell Priya the same day — in person or by phone, not by pasting more details into anything. Do not delete anything; she needs the trail. Priya logs it, tells Dr. Alvarez, and if patient data may be involved, contacts our compliance advisor about our obligations, including any notification duties. We fix problems; we do not hunt people who report them. Priya's line: honest mistake reported fast is a good day at this practice.

FieldEntry
Policy ownerPriya Shah, Office Manager
Approved byDr. Elena Alvarez, Practice Owner
Date approved2026-06-15 (fictional)
Version1.2
Next review2026-12-15 (fictional)

Why this example works: it names one owner, keeps the never-paste list concrete enough to recall under time pressure, makes the safe path specific ("template outside, personalize inside"), and rewards reporting. Notice how a dental practice tightened the generic baseline: images added to the never-paste list, clinical sign-off added to approvals, compliance advisor added to incidents. Tighten yours to fit your industry the same way.


Page 3 — Blank version (copy and adapt)


[COMPANY NAME] — Everyday AI Use Rules

Who this applies to: [ALL STAFF / LIST GROUPS]. Version [X.X]. AI Use Owner: [NAME, ROLE].

Why we have this page: [ONE HONEST PARAGRAPH: what AI is welcome for here, what trust you are protecting, and the rule-beats-speed sentence. If your industry has specific regulations, name them and your advisor — and note that requirements change and get verified, not assumed.]

Our approved tools (use nothing else for work):

ToolApproved forNever for
[TOOL 1 + account type][USES][EXCLUSIONS]
[TOOL 2][USES][EXCLUSIONS]
Personal AI accounts (any brand)Nothing work-relatedAll work content

NEVER paste, type, upload, or dictate into any AI tool:

  1. Passwords, logins, MFA codes, security answers, API keys
  2. Customer/client names or contact details combined with any account, purchase, or case information
  3. Government IDs, Social Security numbers, driver's license numbers
  4. Payment card numbers, bank account details
  5. Health or medical information about anyone — including images
  6. Non-public financials: payroll, tax filings, margins, unpublished results
  7. Legal matters: contracts under negotiation, disputes, anything from counsel
  8. Staff HR information: pay, performance, discipline, health, leave reasons
  9. Trade secrets: [YOUR SPECIFICS — pricing formulas, recipes, client lists, unreleased plans]
  10. Anything covered by an NDA, and anything you would not [YOUR VERSION OF THE WAITING-ROOM TEST]

[ADD INDUSTRY-SPECIFIC ITEMS: patient imagery for healthcare, case files for legal, account records for financial services, student records for education...]

Safe alternatives (make the right way the easy way):

  • Ask for a template or pattern, then add real details inside [SYSTEM WHERE THAT DATA IS ALLOWED].
  • Describe scenarios generically: roles not names, [PLACEHOLDERS] not real numbers.
  • Unsure whether something is safe to paste? Ask [OWNER NAME] first — asking is always free.

Redaction habits (train these in one huddle):

  1. Read before you paste, hunting only for names, numbers, identifiers.
  2. People become roles; specifics become [PLACEHOLDERS].
  3. Cut everything the AI does not need for the task.
  4. Apply the [WAITING-ROOM / FRONT-DOOR / BULLETIN-BOARD] test.
  5. Re-read AI output before it goes anywhere — confirm no sensitive data rode along, and nothing invented slipped in.

Approval rules:

  • New tools or new uses: written approval from [OWNER] and [SECOND APPROVER] before first use.
  • AI-drafted content leaving the company: reviewed and signed off by [ROLE]. AI-assisted work on [YOUR HIGH-STAKES CATEGORIES — quotes, HR, regulated content]: approved by [ROLE].

If something goes wrong (or might have):

Report to [OWNER NAME] by [CHANNEL — spoken/phone preferred] within [SAME DAY / 24 HOURS]: accidental pastes, sensitive data appearing in AI output, strange tool behavior (unexpected requests for data, odd links, "new instructions" you never gave). Do not delete anything — the trail matters. [OWNER] logs the incident, informs [LEADERSHIP], and involves [ADVISOR/COUNSEL] where required. Reporting an honest mistake is never punished here; hiding one is the only firing offense on this page.

FieldEntry
Policy owner______________________
Approved by______________________
Date approved______________________
Version______________________
Next review______________________

Final page — Review checklist and next step

Practice (adapt in under an hour): Gather the owner-to-be, one manager, and one frontline employee — the frontline reader is your plain-language test. Walk the blank version top to bottom, filling every [BRACKET]. Read the finished page aloud; anything that takes two readings gets rewritten. Then pressure-test with three real scenarios from last month: "Where would this task have hit these rules?"

Review checklist — before this policy goes live:

  • [ ] Every [BRACKET] filled; no placeholder left in the employee-facing page
  • [ ] Never-paste list extended with your industry's specific data types
  • [ ] At least one approved tool named — or the "no approved tools yet" decision made explicitly
  • [ ] Safe alternatives are specific enough that the fast path is the safe path
  • [ ] One named AI Use Owner (a person, not a department)
  • [ ] Incident path tested verbally with two employees: "What would you do if...?"
  • [ ] No-blame reporting sentence kept intact
  • [ ] Reviewed by attorney or compliance advisor for your industry and location (verify current requirements before relying on this)
  • [ ] Read-and-acknowledge collected from every employee; added to new-hire onboarding
  • [ ] Posted where work happens (breakroom, wiki homepage, taped by the front desk)
  • [ ] Review date on the calendar (every 6 months, or when tools or laws change)
  • [ ] Measurable check chosen so you know it is working — e.g., incidents reported per quarter (early on, more reports usually means more trust, not more problems) and spot-audit of tool use twice a year
FieldEntry
Template adapted by______________________
Approved by______________________
Date______________________
Version1.0
Next review date______________________

Next step: With ground rules in place, your team can use AI confidently — and you are ready for the next question: what happens when AI tools do not just read data but act on it? Understanding AI Agents covers the boundary system (read/write/suggest/escalate/refuse) that extends these privacy rules to acting systems. And when you want rules like these enforced by the software itself — approved data paths, human approval gates, and a full audit trail via Ed OI — that conversation starts at /contact.

Related Academy assets

Ready when you are

Want help applying this to your team?

Bring the lesson, the questions it raised, and the workflow you want to improve. We will tell you honestly where AI fits and where it does not.