NotesAI tools
Using AI chat tools at work: a one-page policy for a small team
Canadian privacy regulators and the federal government have already written the hard parts. Here is what they say, and a short policy a small business can adopt this week.
It is easy for AI chat tools to arrive in a small business without anyone deciding anything. One person tries one, it saves them an hour, and soon everyone uses whatever they signed up for, with no agreement on what may be pasted in or who checks what comes out.
That is worth fixing, and it does not need a consultant. Canadian regulators and the federal government have published clear guidance. This note summarizes the parts that apply to a small team and ends with a one-page policy you can adapt. It is general information, not legal advice.
What the regulators have said
Privacy law already applies. In December 2023 Canada's federal, provincial and territorial privacy commissioners issued joint principles for generative AI. Their starting point is that these tools do not sit outside existing privacy law. The principles cover familiar ground: having legal authority and consent for what you do with personal information, collecting and using only what is necessary, being open about how it is used, and keeping it accurate.
You stay responsible for what you hand over. The federal Office of the Privacy Commissioner has long held that when a business transfers personal information to another company for processing, the business remains accountable for that information in the other company's hands. Pasting a customer's details into an outside AI service is, in substance, that kind of transfer.
The security agency expects a policy. The Canadian Centre for Cyber Security warns that users may unknowingly put sensitive business data or personal information into prompts. Among its recommendations: have a usage policy with oversight and review, consider whether an AI tool is actually needed for the task, and protect accounts with multi-factor authentication.
A model worth borrowing
The Government of Canada's own Guide on the use of generative AI, written for federal institutions, is one of the clearest documents on the subject. It sums up its approach in six principles, spelled FASTER:
- Fair: make sure content from these tools does not include or amplify biases.
- Accountable: take responsibility for the content generated and the impacts of using it.
- Secure: make sure the tools are appropriate for the sensitivity of the information.
- Transparent: identify content produced with generative AI, and tell people when they are interacting with an AI tool.
- Educated: learn the strengths, limitations and responsible use of the tools.
- Relevant: use the tools where they support real user and organizational needs.
Two of its rules translate directly to a small business. The first is about input: public servants must not put personal information into publicly available online AI tools, because the supplier might store a copy. The second is about output. The guide warns that these tools can produce content that looks credible and is wrong, and it is plain about what to do: do not treat generated content as authoritative, and if you cannot confirm its quality, do not use it.
Know what your tools do with your chats
Each of the major chat tools has a setting that governs whether your conversations can be used to improve its models, and the business versions usually handle this differently from the consumer ones. As their own help pages describe it at the time of writing:
- OpenAI: individual users of its chat app can turn off "Improve the model for everyone" under Data controls. OpenAI says its business, enterprise and education workspaces are not used for training by default. Temporary chats are not used for training.
- Claude: users of Anthropic's consumer plans choose in their privacy settings whether chats may be used to improve its models. Its commercial plans are not covered by that consumer setting.
- Gemini: turning off Keep Activity stops future chats from being used to improve Google's AI, though Google keeps chats for a short period regardless. On work accounts, an administrator controls the setting. Google's own advice is not to enter confidential information you would not want a reviewer to see.
These settings change. Check them when you adopt a tool, and again when its terms change.
The one-page policy
Adapt the wording, keep the structure, and have everyone read and sign it.
1. Approved tools. We use only these AI tools: [list], on these accounts: [business accounts where available]. New tools are added by [owner or manager] after checking their data settings.
2. Never paste. The following never go into an AI tool:
- personal information about customers, staff or anyone else: names with contact details, addresses, health details, identification numbers;
- passwords, access codes, API keys or financial account numbers;
- anything a customer or partner gave us in confidence, such as contracts or pricing, unless the tool is approved for it in writing.
When in doubt, remove the names and specifics first, or do not use the tool.
3. Settings. Model-training settings are turned off on every account that allows it. Accounts use multi-factor authentication.
4. A person owns every output. Whoever uses the tool is responsible for the result as if they wrote it alone. Facts, figures, dates, prices, legal or tax statements and quotations are checked against an original source before anything leaves the business. If it cannot be checked, it is not used.
5. Say when it matters. Where a customer would reasonably want to know, such as published writing or an automated chat on our website, we say that AI was used.
6. Fit for purpose. We use AI tools where they save time on drafts, summaries and routine writing, not as a substitute for our own judgment.
7. Review. This policy is reviewed every six months, and whenever we add a tool.
Why a page is enough
A small team does not need a governance framework. It needs everyone to know three things: which tools are allowed, what never goes into them, and that a person checks what comes out. Written down once, those three answers cover what the guidance above is most concerned about.
Drafted with AI assistance.
Sources
- Government of Canada — Guide on the use of generative artificial intelligence canada.ca
- Office of the Privacy Commissioner of Canada — Principles for responsible, trustworthy and privacy-protective generative AI technologies (7 December 2023) priv.gc.ca
- Office of the Privacy Commissioner of Canada — Guidelines for processing personal data across borders priv.gc.ca
- Canadian Centre for Cyber Security — Generative artificial intelligence (ITSAP.00.041) cyber.gc.ca
- OpenAI Help Center — Data Controls FAQ help.openai.com
- Anthropic — Updates to consumer terms and privacy policy anthropic.com
- Google — Gemini Apps Privacy Hub support.google.com