Internal AI Use Policies for Businesses
A written AI use policy addresses how employees handle confidential information, use generated content, and evaluate people with automated tools. It identifies approved accounts, limits what employees may submit, and assigns responsibility for reviewing output and responding to incidents.
An employee may paste a customer contract into a chatbot, draft sales emails with an assistant, or upload résumés to a screening product. Each use involves different information, contractual restrictions, and legal duties, even when the employee uses the same tool.
You should address those differences in an internal AI use policy. Employees need to know which uses are permitted, which require approval, and whom to contact when a task involves restricted information or a decision about another person.
What Employees Put In
Under the Defend Trade Secrets Act, information qualifies as a trade secret only if its owner takes reasonable measures to protect its secrecy and it has economic value because it isn't generally known or readily ascertainable through proper means by others who could benefit from its use or disclosure. Uploading source code, pricing models, or unreleased product plans to an outside AI provider requires attention to those measures. The governing statute is 18 U.S.C. § 1839(3).
Whether an upload undermines trade secret protection depends on the circumstances, including the provider's confidentiality obligations, permitted uses, access controls, and the business's precautions. A commercial account is one part of that assessment. Its label alone doesn't establish that the business took reasonable measures, and an unauthorized employee upload doesn't automatically extinguish trade secret protection.
Customer confidentiality requires a separate contract review. A nondisclosure agreement may permit disclosure to service providers subject to confidentiality obligations, require customer consent, or prohibit the proposed use. You should classify information subject to those agreements and limit AI use to what each agreement permits. Accepting an AI provider's terms doesn't expand your rights to disclose a customer's information.
Personal data adds statutory requirements when the business and processing fall within a privacy law's scope. Under the Texas Data Privacy and Security Act, a covered controller must limit collection to information reasonably needed for the purposes disclosed to consumers. When a provider processes that information on the controller's behalf, the parties must have a contract meeting § 541.104, including instructions, confidentiality duties, and provisions governing deletion or return.
An AI provider's role depends on what it does with the information, including whether it determines purposes beyond the customer's instructions. A required data processing agreement may be incorporated into accepted commercial terms, as Anthropic's commercial agreement does. You should confirm that a binding agreement covers the service and intended processing before employees submit personal data.
Privacy statutes also differ in whose information they cover. Texas excludes individuals acting in an employment or commercial context from its definition of consumer, while the California Consumer Privacy Act applies to employee and applicant information held by covered businesses. California's § 1798.100(c) requires collection, use, retention, and sharing to be reasonably necessary and proportionate to permitted purposes.
Provider Terms and Training
An internal policy should distinguish the specific services employees use within each provider's product line. ChatGPT, Claude, Gemini, Grok, and Copilot have different account types, contractual commitments, and data settings. You should identify the approved product and account, including whether employees use a personal subscription, a company workspace, or a developer service accessed through an application programming interface, or API.
OpenAI's business privacy commitments state that inputs and outputs from ChatGPT Business, ChatGPT Enterprise, and its API aren't used for model training by default. For individual ChatGPT services, OpenAI may use conversations for training unless the user opts out; Temporary Chats aren't used for training. If a consumer voluntarily submits feedback, OpenAI may use the entire associated conversation for training even after the consumer opts out. A paid personal subscription requires review under the terms applicable to that subscription.
Anthropic's commercial terms prohibit training models on customer content from the covered services and impose confidentiality obligations. Its consumer training guidance describes different treatment, including user choices and specified exceptions. You should confirm which agreement governs the employee's Claude account and whether anyone has authorized separate sharing for training or feedback.
Google distinguishes consumer Gemini Apps from qualifying business services. Its Gemini Apps Privacy Hub describes training and human review practices tied to activity settings and feedback. For qualifying Google Workspace services, Google states that customer content isn't used for generative AI training outside the customer's domain without permission. You should confirm the Workspace edition and the particular Gemini feature before approving confidential information for use.
Google's Gemini API terms separately distinguish paid and unpaid developer services. Under the unpaid service provisions, Google uses submitted content and responses to develop its products and prohibits submissions containing sensitive, confidential, or personal information. The paid service provisions restrict that use of prompts and responses, and billing arrangements and regional exceptions affect which provisions apply. You should confirm those conditions for the relevant account and project before authorizing a developer to submit company or customer information.
Google also permits customers to contribute Gemini API logs through optional data sharing features. Under its data sharing policy, a voluntarily shared dataset receives the unpaid service data treatment, including training and human review, even when the logs originated from paid services. You should require approval before employees contribute company or customer information through feedback or data sharing features.
For Grok, the enterprise terms at x.ai restrict using customer inputs and outputs for model training or developing new products, services, or features, subject to disclosures to the customer and settings the customer controls. The consumer FAQ states that consumer conversations may be used for training, describes controls for excluding new conversations, and identifies an exception for voluntarily submitted feedback. Grok accessed through X has separate account controls that employees must use to manage that setting.
Microsoft's enterprise data protection documentation states that prompts, responses, and organizational information accessed through covered Copilot services aren't used to train foundation models. The same documentation explains that queries sent to Bing for web searches have separate data handling terms. You should identify the Copilot service, organizational account, and enabled features when deciding what employees may submit.
GitHub Copilot has separate data terms for software development. Under GitHub's policy effective April 24, 2026, interactions from Copilot Free, Pro, and Pro+ may be used for training unless the user opts out, subject to stated exclusions. Those interactions include code and surrounding context submitted during active use, including from private repositories. The policy excludes interactions from Copilot Business, Copilot Enterprise, and repositories owned by enterprises.
Training restrictions address one use of information. Retention, access by provider personnel, connected services, and disclosure required by law require separate review. You should record those conditions for each approved service, including optional feedback or data sharing programs that employees can enable.
Which Tools and Accounts
You should maintain a list of approved products, account types, permitted uses, and permitted information. The list should identify the governing agreement, relevant settings, retention terms, and the person responsible for approval. A product's approval for public marketing material needn't extend to customer records or confidential development projects.
Company administered accounts help you manage access and departures, but administrative features vary by service and plan. You should have the person responsible for the technology confirm the available controls for account access, retention, export, and deletion. Connected applications and optional features may involve additional recipients or different terms.
Retention differs by service, feature, and account settings. OpenAI's API data controls documentation describes a default retention period of up to 30 days for abuse monitoring logs, subject to exceptions, while some stored files and conversations persist until deleted. Anthropic's retention documentation generally provides for deletion of API inputs and outputs within 30 days, with exceptions for particular services, agreed arrangements, policy enforcement, and legal requirements.
Google's Gemini Apps Privacy Hub states that temporary chats and chats created with Keep Activity disabled are retained for 72 hours. It also describes longer retention for certain material reviewed by people. You should confirm the retention rules for each approved product and feature, including stored files, conversation histories, and connected services.
A court order can require preservation beyond a provider's ordinary deletion schedule. In In re OpenAI, Inc. Copyright Infringement Litigation, No. 25-md-3143 (S.D.N.Y.), the court required OpenAI to preserve certain output logs that otherwise would have been deleted. An October 9, 2025 order ended the broad ongoing obligation effective September 26, 2025, while requiring continued preservation of previously segregated logs subject to geographic exceptions and separate obligations for specified accounts.
What Comes Out
Copyright protection depends on human authorship. In its January 2025 report on AI and copyrightability, the U.S. Copyright Office concluded that protection extends to human expression in AI assisted material, including sufficiently creative human modifications or selection and arrangement. With current generative systems, prompts alone generally don't supply the control over expressive details necessary to make the user the author of the resulting output.
You should identify and document human contributions when copyright protection is part of the business's plans for a deliverable. Protection for those contributions doesn't automatically extend to every generated element. A provider's contractual assignment of output rights also doesn't establish that copyright exists in the output.
Accuracy requires a separate review. You should assign responsibility to someone qualified to check the facts, calculations, sources, and other material the business will use. The level of review should reflect the consequences of an error, with additional approval for customer commitments, public claims, regulatory submissions, and professional advice.
Disclosures depend on the activity and applicable law. Utah's generative AI disclosure statute, for example, requires a person providing services in a regulated occupation to disclose when an individual is interacting with generative AI in a covered high risk interaction. You should distinguish that interaction from an employee's use of AI to prepare a draft that a human reviews and delivers.
AI in Decisions About People
Using AI to recruit, screen, evaluate, or discipline people requires review beyond ordinary drafting assistance. Federal employment discrimination laws apply to covered employers' selection practices, including the use of automated tools. The EEOC's guidance on employment tests explains discrimination, validation, and disability accommodation requirements that apply to selection procedures.
New York City's rules apply to a defined category of automated employment decision tools used for covered hiring and promotion decisions. Under Local Law 144, an employer or employment agency must obtain an independent bias audit conducted within the preceding year and publish the required audit summary and tool distribution date before use. Whether a tool qualifies depends partly on how substantially its output assists or replaces human discretion.
Covered candidates and employees who reside in the city must receive notice at least 10 business days before use, including the qualifications and characteristics the tool will assess. They must be permitted to request an alternative selection process or accommodation. The city's official guidance explains that Local Law 144 itself doesn't require the employer to provide an alternative process, although disability accommodation duties may apply under other laws.
Illinois's AI employment provisions took effect January 1, 2026. Under 775 ILCS 5/2-102(L), an employer violates the Human Rights Act by using AI in specified employment activities with an effect that discriminates on a protected basis, or by using zip codes as substitutes for protected characteristics. The statute also requires notice to an employee when AI is used for those purposes and assigns the Department of Human Rights responsibility for rules on notice timing, circumstances, and delivery.
California's employment regulations on automated decision systems took effect October 1, 2025. They apply existing employment discrimination rules to automated systems and require covered employers and other covered entities to retain relevant employment records, including covered automated decision data, for at least four years. An automated assessment that elicits disability information also requires review under restrictions on medical inquiries.
California businesses covered by the CCPA face separate risk assessment and automated decisionmaking requirements. Specified processing begun on or after January 1, 2026 requires a prior risk assessment, including automated inferences about applicants or employees based on systematic observation. Covered processing begun earlier and continuing afterward has a December 31, 2027 assessment deadline.
Beginning January 1, 2027, covered uses of technology that replaces or substantially replaces human decisionmaking in significant employment decisions require advance notice, access rights, and an opportunity to opt out unless an exception applies. One exception requires an appeal procedure with a qualified human reviewer who considers relevant information and has authority to overturn the decision. You should document the applicable exception and its conditions before relying on it.
Colorado enacted Senate Bill 26-189 on May 14, 2026, replacing its earlier AI framework. Its requirements apply to covered consequential decisions made on or after January 1, 2027, including specified employment decisions materially influenced by automated technology. The act includes notice duties for businesses using that technology and documentation duties for developers.
Texas's Responsible Artificial Intelligence Governance Act, effective January 1, 2026, prohibits developing or deploying AI with intent to discriminate unlawfully against a protected class. Disparate impact alone is insufficient to establish intent under that provision. You should assess applicable federal and other state employment duties separately, including requirements that don't depend on discriminatory intent.
Before approving AI for an employment decision, you should identify the affected jurisdictions, the tool's function, the employer's role, and the required notices, assessments, records, and review procedures. Qualified personnel should evaluate the tool for the intended use and document the results. The applicable legal requirements determine when an independent audit is mandatory and what it must include.
Records, Holds, and Departures
AI prompts, outputs, and related communications may contain evidence relevant to a dispute. You should identify which records the business needs to retain, where they are stored, and who controls them. The retention schedule should address business purposes, applicable recordkeeping requirements, and deletion obligations.
When litigation is reasonably anticipated, the business must preserve relevant information subject to its preservation duty. Federal Rule of Civil Procedure 37(e) addresses the loss of electronically stored information that should have been preserved for anticipated or pending litigation. You should include relevant AI records in litigation hold instructions and coordinate any suspension of automatic deletion with the people administering the accounts.
Departures require both access control and attention to retained records. You should require company work to occur through approved accounts the business can administer and include AI access in employee offboarding. Before closing an account or deleting its contents, the responsible person should preserve records required by law, contract, or a litigation hold.
Disposal duties apply to covered records once they are no longer retained. Texas Business and Commerce Code § 521.052(b) requires businesses subject to that provision to destroy customer records containing sensitive personal information within their custody or control when those records aren't to be retained. An exported AI conversation containing that information requires the same attention as another customer record.
Vendors, Incidents, and Change
You should require approval before employees introduce an external AI service or enable a new connection to company information. Review should address permitted data uses, confidentiality, retention, security, required processing terms, and the provider's use of other companies to process information. Uses involving regulated information require an assessment of the additional conditions applicable to that information.
Employees also need a reporting procedure for accidental uploads, unauthorized sharing, account compromise, and other suspected incidents. You should designate who receives reports, who contacts the provider, and who coordinates investigation and any required notifications. Prompt internal reporting allows the business to determine which information and people were affected.
A provider incident triggers statutory breach notice duties when the applicable legal conditions are met. Under Texas Business and Commerce Code § 521.053, those conditions include a breach involving specified sensitive personal information acquired, or reasonably believed acquired, by an unauthorized person. Notice duties depend on the facts, the business's role, and the applicable jurisdiction; a contract may also require notification of events beyond the statutory definition.
You should assign responsibility for reviewing changes to provider terms, settings, retention practices, and connected services. A change in plan or model warrants review when it affects the approved use or handling of information. The approved tool list should record the date and result of that review.
Writing the Policy
You should write the policy around decisions employees encounter during their work. An employee needs to know whether a customer document may be uploaded, whether an output requires review, and whether a proposed use in hiring needs separate approval. Examples tied to those activities make the restrictions easier to apply.
The policy should identify responsible roles, required approvals, and a process for questions and incidents. You should train employees on those requirements, provide access to the approved tools, and review the policy when the business changes how it uses AI. Contractors using company information should receive applicable requirements through their agreements and onboarding instructions.
Related practice area: Artificial Intelligence
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry