Your Employees Already Use AI. Does Your Company Have Rules?
Insights / Compliance / Thought Leadership
One of the less glamorous parts of being a lawyer is drafting internal company policies. Whether I particularly enjoy it is another question, but over the years I have written more of them than I can count. Remote work policies, whistleblowing procedures, company car rules, expense reimbursement policies, cybersecurity guidelines, internal approval processes – the list goes on. Some requests are surprisingly specific. At one point, I was even asked to prepare internal rules on the use of electric scooters at work.
At first glance, these documents rarely seem exciting. They are not the kind of legal work people usually imagine when they think about lawyers. Yet they often turn out to be some of the most valuable documents a company has. They provide clarity, create consistency and, perhaps most importantly, reduce the likelihood that ordinary operational issues will later become legal disputes.
Lately, however, I have found myself wondering about one particular omission.
Most companies today already have employees using artificial intelligence in one form or another. Whether it is ChatGPT, Microsoft Copilot, Gemini or Claude, these tools have quietly become part of everyday working life. Employees use them to draft emails, summarise meetings, translate documents, improve presentations or simply save time. In many organisations this happens openly. In many others it happens without anyone really asking the question of whether it should.
What surprises me is not the use of artificial intelligence itself. Technology has always changed the way we work, and businesses naturally adapt. What surprises me is that companies which have detailed internal policies on subjects far less significant often have no rules whatsoever on the use of AI. I have drafted policies governing company vehicles, mobile phones, remote work, expense claims and, yes, even electric scooters. Yet when it comes to technology capable of processing confidential information, generating client communications or analysing commercial documents, many organisations still rely entirely on common sense.
From a compliance perspective, that feels increasingly difficult to justify.
The discussion is often framed around whether employees should be allowed to use ChatGPT. I suspect that question is already outdated. The more realistic question is how employees should use AI, because in many companies they already do. Ignoring that reality does not reduce the legal risks; it simply means those risks remain unmanaged.
An internal AI policy does not need to be particularly long or complicated. It simply needs to answer practical questions. May confidential information be entered into AI systems? Can employees upload draft contracts? Who reviews AI-generated content before it reaches a client? Which AI tools are approved by the company? Who remains responsible if AI produces inaccurate information? None of these questions are purely technical. They concern confidentiality, data protection, intellectual property, cybersecurity and ultimately corporate governance.
Perhaps that is why I find it curious that AI policies remain relatively rare. Businesses are already investing significant time and resources in compliance. They understand the value of clear internal rules in almost every other area of their operations. Artificial intelligence should not be the exception. If anything, it is rapidly becoming one of the areas where practical guidance is needed most.
In my experience, the best internal policies are rarely the ones that attract attention. Their value lies precisely in the fact that they quietly prevent problems from arising. I have a feeling that, within a few years, an internal AI policy will be regarded in much the same way as a data protection policy or an information security policy is today: not as an optional extra, but as an ordinary part of responsible business management.
If your organisation is reviewing its internal governance, compliance framework or AI-related policies, this is exactly the kind of discussion that should take place before legal problems arise—not after. Good compliance is rarely about reacting. More often, it is about preparing before the questions become urgent.