AI tools are now part of the working day for most organisations whetherleadership knows it or not. Staff are using ChatGPT to draft emails, summarisedocuments, and speed up repetitive tasks. They are doing it on work devices,with work data, without any formal guidance on what is and is not acceptable.
This is not a technology problem. It is a governance and information securityproblem.
The risk nobody is talking about
When an employee pastes a client name, a contract summary, or a set of personaldetails into an AI tool, that data leaves your environment. Depending on thetool and its data retention settings, that information may be used to trainfuture models, stored on third party servers, or accessible to the vendor.
Most employees do not know this. They are not being careless. They have simplynever been told.
Under GDPR, the organisation is responsible for how personal data is processed,including by third party tools that staff use in the course of their work. Ifthere is no policy, there is no defence.
What ISO 27001 says about this
Information security management under ISO 27001 requires organisations toidentify and manage risks to the confidentiality, integrity, and availabilityof information. AI tool usage by staff is a risk that most organisations havenot formally assessed, documented, or controlled.
If you are working toward ISO 27001 certification or maintaining an existingISMS, the absence of an AI usage policy is a gap that an auditor will find.
What a basic policy looks like
You do not need a fifty page document. A practical AI usage policy for staffcovers the following:
- What tools are approved for use and which are not. What categories of data must never be entered into any AI tool, specifically personal data, client data, commercially sensitive information, and anything subject to confidentiality obligations.
- What to do if an employee is unsure whether something is safe to share.
- Who is responsible for reviewing and updating the policy as tools evolve.
A simplerule to start with: if the data is masked or anonymised in any other context,it should not go into an AI tool in its original form.
The governance angle
Policies without awareness are not policies. Staff need to know the ruleexists, understand why it matters, and know what to do when they are unsure.That means communication, not just documentation.
If you are responsible for governance or compliance in your organisation, AIdata hygiene is worth putting on the risk register now before an incident makesit urgent.
