OĞUZ EROLADS & AI

Building an AI Usage Policy

2 min read29 July 2026

At most companies, AI use has already started — employees are pasting customer data into ChatGPT, consulting AI whenever they’re unsure, having it draft their emails. The problem is that it’s happening without rules: nobody knows what data can be shared, or which outputs can’t be used without review.

I build a written policy that fills this gap: which tools are allowed, what information should never leave the company, when outputs need human sign-off — realistic rules built for your company.

Why Guide Instead of Ban

A policy that says “AI use is banned” usually doesn’t work, because employees are already using it — just invisibly. A more realistic approach is to draw a clear line between what’s freely allowed, what needs permission, and what’s fully off-limits. This protects security while still letting your team get real value from AI.

When I write the policy, I first find out how your team is actually using it today — I don’t want to write something that looks good on paper but doesn’t reflect real usage.

How This Differs From Data Security

My AI data security service focuses on the technical side (what data lives in which system, under what access permissions). The usage policy focuses on the behavioral side: how employees should and shouldn’t use AI. The two complement each other but produce different deliverables; it’s usually healthiest to handle them together.

We set these up separately or together depending on your company’s needs.

How the Policy Gets Put Into Practice

A written document alone isn’t enough — it needs to be briefly explained to the team, signed off, or added to onboarding. We can make it more lasting by folding it into an orientation package or employee handbook.

How do we start? First, we have a free 20-30 minute preliminary call. We talk about what you want and what’s realistic. If it’s a fit, I send the scope and price in writing, then we begin. You can reach me via the contact page.

Frequently Asked Questions

Is this policy legally binding?

It can be binding as an internal rules document, but it’s not a legal contract. If you want serious legal enforceability, I recommend having a lawyer review the final text.

Does this relate to GDPR/data protection law?

Yes, especially the question of whether customer data can be entered into AI tools relates directly to data protection law. I keep general principles in mind when drafting this section, but I don’t provide formal compliance consulting.

Is this necessary for a small team too?

Even with a small team, if you work with customer data, a few clear rules reduce risk. We scale the scope to the team’s size.

How often should the policy be updated?

Since AI tools change fast, I recommend reviewing it at least once a year — more often if a new risk or tool emerges.