Your company has no AI policy you can find. Nobody has told you whether ChatGPT is allowed. You can see obvious ways it might help—but you do not want to become the example that causes a policy to be written after something goes wrong.
Quick answer: The absence of a visible AI policy is not reliable permission to send company information to a personal or unapproved AI tool. Use a conservative default: ask an accountable person which tool, account, data, and tasks are approved. Until you know, keep real nonpublic work information out. You can still learn the workflow with public information, fictional examples, blank templates, and placeholders.
This is practical risk-reduction guidance, not a legal opinion or a substitute for your employer's rules. Existing confidentiality, privacy, security, records, intellectual-property, and acceptable-use requirements may still apply even when they never mention AI by name.
Why “there is no policy” is not a complete answer
An AI-specific policy is only one part of the rulebook. A workplace may already control the same information through:
- acceptable-use and information-security policies;
- confidentiality agreements;
- customer or vendor contracts;
- privacy and records-retention requirements;
- restrictions on software, browser extensions, or cloud services;
- rules for source code, financial information, employee records, and customer data; and
- manager, IT, security, privacy, legal, or compliance instructions.
OpenAI's current workplace guidance says company rules come first and recommends human review for important work. Microsoft likewise advises employees to follow organizational policies, use company-authorized AI services, avoid disclosing sensitive or confidential company details, and double-check AI-generated results.
The practical conclusion is not “never use AI.” It is “do not make yourself the person who silently decides what the company accepts.”
Ask these seven questions before using real work information
You do not need a 40-page policy to get a useful answer. Ask for decisions on seven concrete points.
1. Which AI tools are approved?
“AI” is not one product. Your employer may permit one service and prohibit another, or permit a company-managed account while excluding personal accounts.
Ask for the exact product, account type, and sign-in method.
2. Which information may be entered?
Ask whether the approved tool can receive:
- public information;
- internal but nonconfidential information;
- customer or employee information;
- proprietary documents or code;
- financial or strategic information; or
- regulated, privileged, or security-sensitive material.
Do not infer that an approved tool means every category of data is approved.
3. Which tasks are allowed?
A company might encourage brainstorming and blank templates but require additional review for customer messages, hiring, legal work, financial analysis, code, or decisions affecting people.
Name the task rather than asking only, “Can I use ChatGPT?”
4. Who reviews the output?
AI can produce confident mistakes, invented facts, weak citations, biased framing, or language that creates an unintended promise. Ask who owns fact-checking, approval, and the final decision.
For consequential work, “the AI said so” is not an approval path.
5. Must AI use be disclosed or documented?
Your employer or client may expect disclosure, retained source links, saved prompts, version history, or a description of what a person reviewed. Ask before delivering the work.
6. May the tool connect to company systems?
Access to email, calendars, cloud storage, code repositories, websites, or business systems is a separate decision from using a chat box. Connected tools can expose more data and may take actions rather than merely draft text.
Ask before connecting anything or granting permissions.
7. Where do questions or incidents go?
Get a named route for uncertainty: a manager, IT help desk, security team, privacy contact, legal team, compliance owner, or AI program lead. You should know whom to ask before a questionable prompt becomes a reportable problem.
A safe default while you wait for an answer
You can still build useful AI skills without submitting real private material.
Green: generally safer practice material
Use:
- public information you are allowed to reuse;
- your own non-work writing;
- invented people, companies, products, and numbers;
- blank templates;
- generic checklists;
- fictional datasets; and
- abstract descriptions of a task.
Even here, review the output and follow the AI provider's usage rules.
Yellow: hold or minimize until the rule is clear
Pause before using:
- internal documents;
- nonpublic project details;
- meeting notes;
- customer or employee situations;
- exact dates, amounts, or locations;
- unpublished plans;
- company-specific processes; and
- material that remains identifiable after names are removed.
Use placeholders or a fictional example if that preserves the learning objective. Otherwise, wait for the approved environment and answer.
Red: do not paste into an unapproved AI tool
Keep out:
- passwords, API keys, tokens, private keys, and recovery codes;
- personal records and government identifiers;
- privileged legal communications;
- security incidents and vulnerability details;
- proprietary source code or architecture;
- confidential financial, customer, employee, or strategy information; and
- any data your employer, contract, or professional duty requires you to protect.
Five useful tasks you can practice without company data
1. Build a neutral email structure
Create a professional follow-up email template for a delayed project. Use placeholders for the project, owner, date, reason, and next step. Do not invent commitments.
2. Design a meeting-summary template
Create a blank meeting summary with sections for decisions, open questions, owners, deadlines, risks, and facts requiring verification. Use no real names or events.
3. Learn a spreadsheet method with fictional rows
Show how to compare planned and actual spending using a five-row fictional dataset. Explain the formulas and include two checks for mistakes.
4. Prepare questions instead of uploading the document
Give me a checklist for reviewing a project status report for clarity, unsupported claims, missing owners, ambiguous dates, and accidental promises.
5. Create a tiny fictional technical example
Explain this programming concept with a minimal invented example. Do not request proprietary code, credentials, internal URLs, or system details.
These prompts teach repeatable methods. Real facts can be applied later only inside an approved environment.
A copy-ready message to your manager or IT team
I would like to use [AI TOOL] for [SPECIFIC TASK].
Before I begin, can you confirm:
1. whether this tool and account type are approved;
2. what categories of company information may be entered;
3. whether this task needs disclosure, recordkeeping, or a reviewer;
4. whether connected files, email, calendars, or other systems are permitted; and
5. whom I should contact when a prompt or use case is unclear?
Until I have that guidance, I will use only public, fictional, or placeholder information and will keep nonpublic company data out.
This makes the request easier to answer than “Do we have an AI policy?” and leaves a clear record of the scope you proposed.
If your manager says “just be careful”
Ask for one more level of specificity:
- Which tool and account?
- Which data categories?
- Which tasks?
- Which reviewer?
- Which actions or connections?
“Be careful” is a good intention, but it does not tell employees what the boundary is. A short written answer to those five questions is more useful than guessing.
If different people give different answers
Do not pick the answer you like best. Ask the responsible owner to resolve the conflict. Until then, use the more restrictive instruction and keep real nonpublic data out of the tool.
If you already used AI before asking
Do not hide, delete, or alter records to make the situation look different. Stop entering additional work data, preserve the relevant facts, and use your employer's normal support or incident-reporting route. The appropriate response depends on the information, tool, account, settings, and company requirements.
Keep a practical checklist beside you
The Safe AI at Work: Employee Quickstart Kit turns this safe default into a reusable daily system. It includes a green/yellow/red data guide, the five-question Safe to Paste check, an abstract-first workflow, 30 workplace prompts, human-review reminders, worksheets, and an AI Wins Tracker.
Get the $19 Safe AI at Work Employee Quickstart Kit
It is a one-time download with no live call or subscription. Employer rules always come first.
Are you responsible for writing the company’s AI rules?
If you are the manager or operations lead who needs a starting draft, the RoleReady AI Policy Pack includes 11 editable documents: an acceptable-use policy template, staff one-pager, vendor checklist, incident plan, rollout memo, and training outline. It is a template pack, not legal advice or a compliance certification; adapt it to your organisation and have a qualified adviser review the finished policy.
See the $79 AI Policy Pack for Small Business