CozyHR
Menu
Products
Docs
Resources
Compliance
Company
Support
Blog
AI in HRHR PoliciesData PrivacyHR Tech

Generative AI Usage Policy for Employees: India HR Guide

How to write a practical generative AI usage policy for employees in India: data tiers, HR use cases, DPDP alignment, rollout and FAQs.

CozyHR editorial team 09 October 2026 20 min read
CozyHR Blog
Generative AI Usage Policy for Employees: India HR Guide

Sometime in the last year, someone in your company almost certainly pasted a salary sheet, a performance review or a candidate's CV into a public AI chatbot. They probably did it to save time, with good intentions and no malice. But if your company has no written generative AI usage policy, nobody told them whether that was allowed, what was safe to paste, or who was accountable for the result. That gap is exactly why a generative AI usage policy for employees is quickly becoming one of the most important HR documents an Indian company can write.

This guide shows HR managers, founders and compliance leads how to draft a practical, readable AI policy for the workplace. We cover why you need one, what to include, how to classify data, how to treat AI in hiring and performance decisions, how to align with India's data protection law, how to roll the policy out, and how to keep it alive as tools change. You will also find a ready-to-adapt policy outline, an approved-use matrix and answers to common questions. This is general guidance and not legal advice, so have your counsel review the final document.

Why Every Company Needs an AI Usage Policy

Generative AI tools can draft emails, summarise documents, write code, analyse spreadsheets and produce policy drafts in seconds. Employees adopt them quickly, often without asking. Banning them completely is rarely effective, because people simply use them on personal devices. Allowing them without guardrails creates risk. A clear policy replaces guesswork with guidance.

The risks a policy addresses

Confidentiality leaks. Information typed into a public tool may be stored, reviewed or used to improve the service, depending on the vendor's terms and the account type. Employees may not know which applies. Trade secrets, client data, source code and employee records can leave your control this way.

Personal data exposure. HR data is among the most sensitive data a company holds: identity documents, bank details, salary, health information, performance notes and disciplinary records. Pasting such data into an unapproved tool can create privacy and legal exposure. We explain the legal background in our guide to the DPDP Act and employee data privacy.

Inaccurate output. Generative models can produce confident but wrong content: invented facts, incorrect calculations or fictional citations. If a payroll formula, legal clause or compliance date goes into a document unchecked, the error becomes the company's error.

Bias and unfair decisions. Used in screening, ranking or evaluating people, AI can reflect and amplify bias in its training data or in how it is configured. Decisions about hiring, pay, promotion and termination affect livelihoods and require human judgment and fairness.

Intellectual property concerns. Questions can arise about who owns AI-generated output, whether it resembles existing protected content, and whether employees are inputting material they do not have the right to share.

Security risks. Unvetted browser extensions, plugins and free tools can introduce malware, data scraping or unsafe integrations.

Regulatory and contractual obligations. Client contracts may restrict how their data is processed. Sector regulations may impose extra requirements. A policy helps you meet those obligations consistently.

Inconsistent practice. Without a policy, one team uses AI heavily and carefully while another uses it carelessly. The company has no idea what is happening.

The benefits of a good policy

A thoughtful policy does more than reduce risk. It tells employees that using AI is welcome when done safely, which encourages productivity gains. It sets expectations for managers, clarifies accountability and gives HR a framework to handle violations fairly. It also makes audits and client due diligence easier, since you can show a documented control.

Principles to Anchor Your Policy

Before drafting rules, agree on a few principles. They keep the document coherent and make it easier to handle situations the policy did not anticipate.

  1. Humans stay accountable. AI assists; people decide. Whoever uses AI output owns it.
  2. Protect people's data. Treat personal and confidential information with care, and share only what is necessary through approved channels.
  3. Be transparent. Disclose AI use where it matters, particularly to candidates, clients and in regulated work.
  4. Be fair. Do not use AI in ways that unfairly disadvantage individuals or groups.
  5. Verify before relying. Check facts, numbers and legal references against authoritative sources.
  6. Use approved tools. Prefer vetted tools with appropriate contractual and security protections.
  7. Keep learning. Review the policy regularly as technology and regulation evolve.

Step 1: Take Inventory of Current AI Use

You cannot govern what you cannot see. Begin with a lightweight discovery exercise.

  • Send a short anonymous survey: which AI tools do you use, for what tasks, and how often?
  • Ask department heads which use cases they would like to enable.
  • Check with IT which tools are accessed from company networks and devices, within legal and privacy limits.
  • Review any vendor tools already in use, such as HR software, ATS or helpdesk platforms that now include AI features. Your HRMS or ATS may already use AI in ways you have not documented.

The aim is not to catch people out. It is to understand real behaviour so that the policy fits it. Make clear that the survey is for building guidance, not for punishment.

Step 2: Classify Your Data

The heart of any AI policy is a simple data classification that employees can apply in seconds. Four tiers usually suffice.

TierDescriptionExamplesAI use rule
PublicInformation already meant for the publicPublished blog posts, job advertisements, public product pagesMay be used with any tool
InternalGeneral business information not meant to be public but low sensitivityMeeting agendas, generic process notes, non-sensitive templatesApproved tools only
ConfidentialSensitive business informationClient lists, pricing, contracts, source code, strategy, financialsOnly approved enterprise tools with contractual protection, and only when necessary
RestrictedPersonal or highly sensitive dataEmployee identity and bank details, salary data, health information, performance and disciplinary records, candidate personal dataNot to be entered into any AI tool unless explicitly approved by HR and IT after a privacy review; anonymise wherever possible

Provide examples relevant to each department. For HR, spell out that salary sheets, payslips, appraisal ratings, grievance details, background verification reports and medical certificates fall into the restricted tier.

Anonymisation basics

Where AI can help without needing identity, teach employees to strip identifying details: names, employee IDs, contact details, bank information and unique descriptors. Replace them with placeholders such as "Employee A". Warn that anonymisation is harder than it looks. A combination of designation, location and salary can identify a person even without a name. When in doubt, do not paste it.

Step 3: Define Approved Tools and Accounts

Decide which tools are permitted and under what conditions. A short, clear tiered approach works well.

  • Approved tools: Vendor-reviewed tools with enterprise terms, security controls and data handling commitments that your IT and legal teams have checked. Employees should use company accounts, not personal ones.
  • Permitted with restrictions: Public tools allowed only for public or low-sensitivity internal content, such as drafting generic text or brainstorming.
  • Prohibited: Tools that fail your security review, unvetted extensions and apps, and any tool that requires uploading restricted data without an approved agreement.

Create a simple intake process so employees can request a new tool. Ask a few standard questions: what data will it touch, where is the data stored, does the vendor use inputs for training, what security certifications exist, can the data be deleted, and what are the contract terms? Keep a register of approved tools, owners and review dates.

When assessing vendors, apply the same discipline you would to any HR technology purchase. Our ATS buying checklist offers a useful template of questions you can adapt, including data hosting, access control and exit terms.

Step 4: Write the Acceptable Use Rules

Employees need to know what they may and may not do. Use plain language and concrete examples.

Generally acceptable uses

  • Drafting and editing general communications, such as emails, announcements and internal documents, which the employee then reviews.
  • Summarising non-confidential public documents.
  • Brainstorming ideas, outlines and options.
  • Generating first drafts of policy templates, job descriptions or training outlines using no personal data. Always review for accuracy and fit.
  • Helping with spreadsheets and formulas using dummy or anonymised data.
  • Learning and upskilling.

Uses that require approval

  • Using AI with confidential business data.
  • Integrating AI into business processes or customer-facing systems.
  • Building or customising AI agents that take actions on company systems.
  • Using AI to process any personal data.

Prohibited uses

  • Entering restricted data into unapproved tools.
  • Using AI to make final decisions about hiring, firing, promotion, pay or discipline without meaningful human review.
  • Using AI to generate fake documents, credentials, reviews or messages impersonating others.
  • Using AI to bypass company controls or to produce content that harasses, discriminates or defames.
  • Uploading third-party confidential material in breach of a contract or non-disclosure agreement.
  • Using AI output as authoritative legal, tax or compliance advice without verification by a qualified person.

Step 5: Set Rules for HR-Specific Use Cases

HR is both a heavy potential user of AI and a function that handles the most sensitive information. Give it specific guidance.

Recruitment and screening

AI can help write job descriptions, summarise CVs and schedule interviews, but it can also embed bias and make opaque decisions. Your policy should require:

  • Human review of any AI-generated shortlist or ranking before a candidate is rejected.
  • Documented, job-relevant criteria for screening.
  • Periodic checks of outcomes across groups to spot unfair patterns.
  • Transparency with candidates about the use of automated tools where appropriate.
  • A clear process for candidates to ask for human review.
  • Vendor due diligence on bias testing, data retention and security.

For a deeper treatment, see our guide on AI resume screening for SMB recruiters, and use a structured interview scorecard so human judgment stays anchored to consistent criteria.

Performance management

AI can help managers draft review comments or summarise feedback, but ratings and consequences must remain human decisions. Do not let AI generate performance ratings from raw activity data without careful design and oversight. Prohibit pasting named performance records into public tools. Our article on AI performance reviews offers a more detailed approach, and our performance calibration guide explains how to keep ratings fair.

Payroll and compensation

AI can explain formulas or help draft communications, but payroll calculations must come from validated systems with controls, not from a chatbot's arithmetic. Never paste employee-level salary data into unapproved tools. Treat AI-suggested tax or statutory interpretations as drafts to be verified. Consider the control weaknesses that automated or unreviewed processes can create; see our guide to payroll fraud prevention.

Employee queries and chatbots

If you deploy an AI assistant to answer employee questions, restrict it to approved knowledge sources, make sure it does not expose other employees' data, enable escalation to a human and log interactions as appropriate. Our guide on AI chatbots for employee self-service covers the design.

Grievances, investigations and disciplinary matters

These are among the most sensitive records a company holds. Prohibit entering details of complaints, investigations or inquiries into AI tools unless they are approved, private and specifically authorised for that purpose. Maintain the confidentiality required by processes such as those under POSH and your grievance redressal policy.

Policy drafting

AI can produce a useful first draft of a leave policy or handbook section, but it may miss state-specific rules, outdated provisions or company context. Treat output as a starting point and have a knowledgeable person review it. See our guide on creating an employee handbook.

Step 6: Align With Data Protection Obligations

India's Digital Personal Data Protection Act sets out obligations for entities that process digital personal data, including purpose limitation, notice and consent or other lawful grounds, security safeguards and data subject rights. The details of rules and timelines continue to develop, so verify the current position with official sources and your legal advisor.

For an AI policy, translate those principles into practical rules:

  • Purpose limitation: Use personal data in AI tools only for the purpose it was collected for.
  • Minimisation: Share the minimum data needed.
  • Notice: Update employee and candidate privacy notices to mention automated tools where relevant.
  • Security: Use tools with adequate safeguards, access controls and encryption.
  • Vendor management: Ensure contracts with AI vendors define their role, restrict secondary use and require deletion on request.
  • Retention: Do not keep AI chat logs containing personal data longer than needed.
  • Incident response: Treat accidental exposure of restricted data into an unapproved tool as a potential data incident to be reported internally right away.
  • Cross-border transfers: Understand where the vendor processes and stores data.

Step 7: Establish Human Oversight and Accountability

Every AI-assisted work product needs a named owner. Spell this out.

  • The employee who uses AI output is responsible for its accuracy, appropriateness and compliance.
  • Managers are responsible for ensuring their teams understand and follow the policy.
  • A designated owner, such as HR, IT or a small AI governance group, maintains the policy, approves tools and handles exceptions.
  • For high-impact decisions, require documented human review, noting what the reviewer checked.

Establish a lightweight governance group with representatives from HR, IT or security, legal or compliance, and business teams. It does not need to be heavy; a monthly or quarterly check-in is enough for most small and mid-sized companies.

Step 8: Plan for Transparency and Disclosure

Decide when AI use should be disclosed.

  • To candidates: If automated tools materially influence screening, be open about it.
  • To employees: If AI is used in workplace monitoring, analytics or evaluation, inform them clearly.
  • To clients: Some clients require disclosure of AI use in deliverables. Check contracts.
  • In content: For published content, decide your stance on labelling AI-assisted material, and ensure human review for accuracy and originality.

Transparency builds trust and also reduces the chance of unpleasant surprises.

Step 9: Train Employees

A policy nobody reads is useless. Plan short, practical training.

  • A 30-minute session for all employees: what the policy says, examples of safe and unsafe use, how to anonymise data, and how to ask for tool approval.
  • A deeper session for HR, finance and recruiting teams who handle restricted data.
  • A manager briefing on oversight responsibilities.
  • A one-page quick reference card or intranet page.
  • Refreshers at least once a year or when the policy changes significantly.

Use real scenarios. For example: "A manager wants to paste last year's appraisal comments into a chatbot to write a summary. What should they do?" Let people discuss the answer.

Step 10: Monitor, Enforce and Improve

Monitoring

Be proportionate and transparent. Monitor the use of company-approved tools through logs where appropriate and legal, and be clear with employees about what is monitored. Avoid invasive surveillance that damages trust.

Enforcement

State that policy violations are handled under the company's disciplinary framework, with proportionate responses. Accidental misuse reported promptly should be treated as a learning opportunity, not a reason for harsh punishment, or people will hide mistakes. Deliberate or repeated violations, or those that cause serious harm, may attract formal action under your code of conduct. Follow due process as described in our guide on disciplinary action and domestic inquiry.

Incident reporting

Provide a simple way to report concerns or incidents: a dedicated email address, a form or a named contact. Consider linking it to your whistleblower mechanism for serious matters.

Review cycle

Review the policy at least annually and whenever there is a significant change in tools, regulation or incidents. Keep a version history and communicate changes clearly.

Sample Policy Outline

Use the structure below as a template and adapt it to your company. Keep the final document short, ideally two to four pages, with plain language.

  1. Purpose and scope. Why the policy exists and who it applies to (employees, contractors, interns).
  2. Definitions. Generative AI, approved tools, personal data, confidential information.
  3. Principles. The seven principles above, in your own words.
  4. Data classification. The four-tier table with examples.
  5. Approved and prohibited tools. Where to find the current list and how to request a tool.
  6. Acceptable use. Permitted, approval-required and prohibited uses.
  7. HR and people-decision rules. Hiring, performance, pay and discipline.
  8. Data protection requirements. Privacy, security and vendor expectations.
  9. Accuracy and review. Verify outputs; the user is accountable.
  10. Intellectual property. Do not input third-party protected material without rights; review output for originality.
  11. Transparency and disclosure. When to disclose AI use.
  12. Roles and responsibilities. Employees, managers, HR, IT, legal.
  13. Incident reporting. What to do if something goes wrong.
  14. Enforcement. Consequences of violations.
  15. Training and review. Frequency and owner.
  16. Version, effective date and contact.

Approved-Use Matrix for Common Tasks

This matrix makes the rules concrete. Adjust it to your risk appetite and tool setup.

TaskPublic toolApproved enterprise toolNotes
Draft a generic job advertisementYesYesReview for bias and accuracy
Summarise a candidate's CVNoOnly if approved and privacy-reviewedContains personal data
Rewrite a general announcement emailYes, if no confidential contentYesCheck tone and facts
Analyse payroll data with names and salariesNoOnly with specific approvalRestricted data
Create a dummy salary example for trainingYesYesUse fictional values
Summarise meeting notes with client namesNoYes, if contracts allowCheck client terms
Draft a policy templateYes, no company dataYesVerify against current law
Write performance review text from named notesNoOnly if approvedHuman must own the final review
Generate interview questions for a roleYesYesEnsure job-relevance
Answer a statutory compliance questionReference onlyReference onlyAlways verify with official sources

Common Mistakes When Writing an AI Policy

  • Copy-pasting a template without adapting it. A generic policy that does not mention your tools, data or processes will be ignored.
  • Banning everything. Overly strict policies drive use underground.
  • Allowing everything. No guardrails means no accountability.
  • Writing in legal jargon. If employees cannot understand it, they cannot follow it.
  • Ignoring vendor AI features. The AI inside your existing software also needs oversight.
  • No owner. A policy without an owner decays.
  • Forgetting contractors and interns. They often handle data too.
  • Skipping training. Awareness is the control that matters most.
  • Treating the policy as one-and-done. The technology changes quickly.
  • Relying on AI detection tools. Detectors are unreliable; focus on process and accountability instead.

A Simple Rollout Plan

Weeks 1 to 2: Discover. Run the survey, interview department heads, list current tools and use cases.

Weeks 3 to 4: Draft. Prepare the policy, data classification table and approved-tool register. Involve IT, legal and a few frontline users to test clarity.

Week 5: Approve. Get sign-off from leadership. Decide on the effective date and exceptions process.

Week 6: Launch. Communicate through an all-hands message, a short training session and an intranet page. Obtain acknowledgment from employees, ideally through your HR system.

Weeks 7 to 12: Support and learn. Hold office hours, collect questions, update the FAQ and review tool requests.

Quarterly: Review. Check incidents, tool register and emerging use cases. Update the policy as needed.

Collecting employee acknowledgments in a central system makes audits simple. A good HR platform can store signed policies, track who has read them and remind people to complete acknowledgments.

Tailoring for Small and Mid-Sized Companies

If you are a small team without legal or IT specialists, simplify.

  • Keep a one-page policy with five rules: use approved tools; never paste personal or confidential data; verify everything; humans decide on people matters; report mistakes quickly.
  • Pick one or two vetted tools with business terms and standardise on them.
  • Assign a single owner, often the founder, HR lead or operations head.
  • Review every six months.
  • Get a lawyer to look at the document once, particularly on data protection and employment aspects.

As you grow, add detail. It is better to have a short policy that people follow than a long one they ignore.

Frequently Asked Questions

Do we really need an AI policy if we are a small company?

Yes. Small companies often move fastest with AI and have the least formal control, so the risk of accidental data exposure is real. A short, clear policy takes a few hours to write and can prevent expensive mistakes.

Should we ban public AI tools completely?

Total bans are hard to enforce and may push usage to personal devices. A more effective approach is to allow public tools for non-sensitive tasks, provide approved alternatives for sensitive work, and clearly prohibit entering restricted or confidential data into unapproved tools.

Can HR use AI to shortlist candidates?

It can assist, but a person should review and own the decision. Define job-relevant criteria, check results for unfair patterns, be transparent where appropriate and make sure vendors meet your privacy and security standards. Do not let an automated ranking be the sole reason for rejecting someone.

Is it safe to paste payroll data into a chatbot?

Not into an unapproved or public tool. Payroll data includes personal and financial information that must be protected. If AI help is needed, use anonymised or dummy data, or an approved tool that has gone through a privacy and security review.

Who is responsible if AI produces a wrong answer that we act on?

The person who used and relied on the output, and the company as a whole. That is why the policy should require verification and human accountability. AI is a drafting assistant, not an authority.

How does the DPDP Act affect our AI use?

If you process digital personal data of employees or candidates with AI tools, the obligations around purpose, notice, security, vendor arrangements and data subject rights apply. The rules and timelines are developing, so check the latest official position and consult your legal advisor.

How often should we update the policy?

At least once a year, and sooner when you adopt new tools, when regulations change or when an incident reveals a gap. Keep a version log and communicate each change.

Should employees disclose when they use AI?

It depends on context. Disclosure may be necessary for clients, candidates and in regulated work. For internal drafts, many companies do not require disclosure but do require that the author verifies and takes responsibility. State your position clearly in the policy.

What should an employee do if they accidentally paste sensitive data into a public tool?

Report it immediately to the designated contact. Provide details of what was shared, when and which tool. Prompt reporting lets the company assess the risk, contact the vendor if appropriate and take corrective action. Treat honest reporting as positive behaviour.

Can we use AI-generated policies and templates as-is?

Use them as first drafts only. They may be inaccurate, outdated or unsuited to your state and company. Have a qualified person review them, especially anything with legal or statutory implications.

Conclusion

A generative AI usage policy is not about slowing people down or stamping out innovation. It is about giving employees the confidence to use powerful tools while protecting the people whose data you hold and the business you are building. The strongest policies are short, specific and written for humans. They classify data simply, name approved tools, keep people accountable for decisions, protect personal information and are refreshed as the technology changes.

Begin with a discovery survey, draft a one- to three-page policy using the outline above, test it with a few employees, train your teams and review it regularly. You will end up with a document that people actually use, and a company that benefits from AI without betting its reputation on it.

If you are looking for a place to keep policies, collect acknowledgments and manage employee records securely, CozyHR can help you centralise HR documents, track policy sign-offs and keep sensitive employee data in one controlled system. Explore CozyHR to see how it can support your move toward safe, well-governed use of technology in HR.

Disclaimer: This article is general information, not legal advice. Laws, rules and guidance on data protection and AI change; consult a qualified legal professional and verify current requirements before adopting a policy.