CozyHR
Menu
Products
Docs
Resources
Compliance
Company
Support
Blog
AI in HRHR PoliciesHR TemplatesData Privacy

Workplace AI Use Policy: A Template Guide for Indian HR Teams

How to write a workplace AI use policy that protects confidential and employee data, sets responsible-AI rules for HR, and gives employees clear guidance on generative AI at work.

CozyHR editorial team 02 September 2026 34 min read
CozyHR Blog
Workplace AI Use Policy: A Template Guide for Indian HR Teams

Somewhere in your company right now, someone is pasting text into a chatbot. It might be a sales executive polishing a proposal, a developer debugging a stubborn function, or a recruiter summarising a stack of resumes before lunch. Most of that activity is harmless, even helpful. Some of it is quietly moving client details, source code and employee personal data outside your control.

That is why a written AI use policy has stopped being a nice-to-have. A workplace AI policy is no longer a document reserved for large enterprises with compliance departments. Indian startups and SMBs, where teams adopt tools faster than anyone can review them, need one just as urgently, and in some ways more so.

This guide walks you through what a workplace AI use policy should cover, the risks it needs to address, the principles behind responsible AI in HR, a step-by-step drafting process, and a full section-by-section template with sample clause text you can adapt. It is written for HR managers, founders and people-ops leads writing their first policy, not for lawyers. Where a topic needs legal input, we say so plainly.

Why every company now needs a written AI use policy

Generative AI at work arrived without an onboarding process. Nobody rolled it out; people simply started using it. Free tiers, browser extensions, AI features bundled into email and spreadsheets, meeting note-takers that join calls uninvited. By the time leadership notices, usage is already widespread.

The absence of a policy does not mean the absence of AI use. It means AI use without guardrails. Consider what that looks like in a typical 80-person company:

  • A finance associate uploads a vendor contract to a summarisation tool to "get the key terms quickly."
  • A team lead pastes a colleague's appraisal notes into a chatbot to "make the language more professional."
  • An engineer shares a chunk of proprietary code with an assistant to fix a bug, and the tool's default settings retain the input for model training.
  • A recruiter asks an AI to rank twenty candidates, then forwards the ranking without reading the resumes.

None of these people intended harm. Each of them created a risk the company had no visibility into. A written policy converts good intentions into consistent behaviour. It tells people what is fine, what is not, and what to do when they are unsure.

There is also a cultural benefit that is easy to overlook. Employees who are unsure whether AI use is allowed tend to hide it. Hidden use is unmanageable use. A clear, reasonable policy brings AI into the open, where it can be supported, improved and governed.

Finally, a policy protects the company when things go wrong. If a client asks how you safeguard their data, or an employee questions how AI shaped a decision about them, "we have a written policy, training records and acknowledgements" is a very different answer from "we assumed people would use common sense."

What a workplace AI use policy covers

A good workplace AI policy has two distinct scopes, and many first drafts miss the second one entirely.

Scope 1: Employee use of generative AI tools

This is the obvious half. It governs how anyone in the company may use AI assistants, code generators, image tools, meeting transcription services, AI features inside SaaS products, and similar tools in the course of their work. It answers questions such as:

  • Which tools are approved, and under what account type?
  • What information may be entered into them?
  • When must AI assistance be disclosed?
  • Who reviews AI-generated output before it goes out the door?
  • What happens if something leaks?

Scope 2: HR's own use of AI in people decisions

The second scope covers the HR function as a user of AI. This is where the stakes are highest, because the outputs affect real people's livelihoods. It includes:

  • Hiring: resume screening, candidate ranking, interview question generation, interview note summarisation, offer letter drafting.
  • Performance management: drafting review summaries, analysing feedback themes, generating development plans.
  • Employee queries: chatbots answering leave, payroll and policy questions, drafting responses to grievances.
  • Payroll and compliance: using AI to interpret statutory rules, reconcile data, or draft communications about salary changes.

HR teams sometimes write a policy for "everyone else" and forget that they are the heaviest users of AI on sensitive personal data. Your policy should hold HR to a higher standard, not a lower one, and it should say so explicitly.

What the policy is not

An AI use policy is not a ban. Blanket prohibitions fail because they are unenforceable and because they push usage underground. It is also not a technical security standard; it should reference your IT and information security policies rather than duplicate them. And it is not a substitute for judgement. The best policies give people a framework for deciding, not a rulebook for every possible situation.

Risks the workplace AI policy must address

Before drafting clauses, be clear about what you are protecting against. Each of the risks below should map to at least one rule in your final policy.

Confidential company data leakage

The most immediate risk. When an employee enters information into a public AI tool, that information leaves the company's environment. Depending on the tool's terms and settings, it may be stored, reviewed by the vendor's staff, or used to train future models. Financial projections, product roadmaps, pricing strategies, board materials and internal communications can all leak this way.

The policy needs to define which categories of information may never go into unapproved tools, and which may go only into enterprise-grade tools with contractual data protections.

Client and partner data

If you handle client information under contract, you likely have confidentiality obligations that are stricter than your own internal standards. Many client agreements prohibit sharing their data with third-party processors without consent. An AI vendor is a third-party processor. Entering a client's data into a chatbot may breach that contract even if nothing "bad" happens afterwards.

Personal data of employees and candidates

Indian organisations now operate under the Digital Personal Data Protection Act (DPDP Act) framework, which sets out principles for how personal data should be collected, used and protected. The details of applicability, timelines and obligations are matters for your legal advisers, and this article does not attempt to interpret the law. But the underlying principles are useful design constraints for any AI policy:

  • Use personal data only for the purpose it was collected for.
  • Collect and process only what is necessary.
  • Keep it accurate and secure.
  • Be transparent with the individuals it concerns.

Feeding a candidate's resume, an employee's medical leave request or a salary record into an AI tool is processing of personal data. Your policy should treat such data as restricted by default, and you should consult counsel on notice, consent and processor arrangements for any AI tool that touches it.

Intellectual property and copyright of outputs

Two related issues. First, ownership: who owns text, code or images generated by an AI tool? Vendor terms vary, and the legal position on AI-generated works is still developing in most jurisdictions, including India. Second, infringement: AI outputs can reproduce or closely resemble copyrighted material from training data, and the employee who pastes that output into a product or a marketing campaign may expose the company to claims.

The policy should require human review of AI-generated content intended for external or commercial use, and should discourage treating AI output as original work without checking.

Hallucinations and accuracy

Generative tools produce fluent, confident text that may be wrong. They invent statistics, cite non-existent sources, misstate legal rules and fabricate details. In HR, a hallucinated interpretation of a leave rule or a gratuity calculation can become an actual payroll error. In client work, a fabricated reference in a report can damage trust.

The policy must establish that the human using the tool remains fully responsible for the accuracy of anything they produce with it.

Bias in people decisions

AI models learn from historical data, and historical data reflects historical bias. A screening tool trained on past hires may favour certain colleges, cities, name patterns or career paths in ways that disadvantage protected groups. The tool will not tell you it is doing this; it will simply produce rankings that look objective.

For HR specifically, the policy needs explicit rules on where AI may inform a decision and where it may never make one, along with a requirement to check for disparate outcomes.

Shadow AI

"Shadow AI" is the AI equivalent of shadow IT: tools adopted by individuals or teams without the company's knowledge. It includes personal chatbot accounts used for work, browser extensions that read page content, AI meeting bots invited by one attendee, and AI features silently switched on inside existing software.

The policy addresses shadow AI by defining an approval process that is fast and reasonable enough that people actually use it, and by making it clear that using unapproved tools with company data is a policy violation.

Principles of responsible AI in HR

A workplace AI policy works best when it rests on a short set of stated principles. Principles help people reason about situations the rules did not anticipate. The following six are widely recognised and translate well into an HR context.

Fairness

AI must not be used in ways that produce unjustified differences in treatment based on gender, religion, caste, region, language, age, disability or other characteristics protected by law or by company values. Fairness means both avoiding intentional discrimination and checking for unintentional patterns.

Transparency

People should know when AI is involved in a process that affects them. Candidates should be told if AI tools assist in screening. Employees should know if a chatbot is answering their query rather than a person. Transparency builds trust and also creates the conditions for people to challenge errors.

Human-in-the-loop

A person with appropriate authority and context must review and own any AI-assisted decision that materially affects an individual. AI can draft, summarise, suggest and flag. It should not decide who gets shortlisted, promoted, rated or let go.

Accountability

Every AI-assisted output has a named human owner who is responsible for it. "The tool said so" is never an acceptable explanation. Accountability also applies at the organisational level: someone in the company owns the policy, the tool inventory and the review process.

Data minimisation

Use the least personal data necessary. If a task can be done with anonymised or aggregated information, do it that way. If an AI tool does not need a candidate's name, address, date of birth or photograph to help you draft interview questions, strip those out before you start.

Explainability

If a decision was influenced by AI, the decision-maker should be able to explain, in plain language, what the AI contributed and why they agreed or disagreed with it. If you cannot explain a tool's output, you should not be relying on it for people decisions.

These principles belong in the opening section of your policy. They also make excellent training material, because they give employees a way to think rather than a list to memorise.

Step-by-step: how to draft your AI use policy

Drafting does not have to take months. A focused HR lead with support from IT and a legal reviewer can produce a workable first version in a few weeks. Here is a sequence that works.

Step 1: Inventory the tools already in use

Before writing a single rule, find out what people are actually using. Run a short, non-punitive survey. Ask team leads. Check with IT for browser extensions and SaaS integrations. Look at which AI features are enabled inside your existing tools, including your HRMS, email suite, CRM and productivity apps.

You will almost certainly discover more usage than you expected. That is fine. The goal is an honest picture, not a list of offenders.

Step 2: Classify your data into tiers

Most of the policy's practical rules hinge on data classification. Define three or four tiers and give concrete examples for each. A common structure:

  1. Public: information already published or intended for publication.
  2. Internal: everyday business information not meant for outsiders but not damaging if seen.
  3. Confidential: information whose disclosure would harm the company, a client or a partner.
  4. Restricted: personal data, financial records, credentials, source code, legal matters and anything under specific contractual or regulatory protection.

If you already have an information security classification, reuse it rather than inventing a parallel one.

Step 3: Define approved, conditional and prohibited uses

For each data tier, decide what AI use is allowed:

  • Approved: uses that need no further permission (for example, using an enterprise AI tool to rewrite a public blog post).
  • Conditional: uses that require an approved tool, a specific account type, or a manager's sign-off (for example, summarising internal meeting notes).
  • Prohibited: uses that are never allowed regardless of tool (for example, entering employee salary data into a consumer chatbot).

Keep the prohibited list short and absolute. Long prohibited lists get ignored.

Step 4: Set disclosure rules

Decide when AI assistance must be disclosed and to whom. Common thresholds:

  • Externally facing content that is substantially AI-generated.
  • Any document that will inform a decision about a person.
  • Any use of AI in recruiting that a candidate might reasonably want to know about.
  • Meeting recordings and transcriptions, which should be announced to all participants.

Step 5: Build an approval workflow for new tools

Shadow AI thrives when approval is slow or opaque. Design a lightweight process: a short request form, a named reviewer (usually IT security plus HR for people-facing tools), a target turnaround of a few working days, and a published list of approved tools that is updated as decisions are made.

Include a vendor review checklist covering data retention, training on customer inputs, storage location, access controls, and whether an enterprise agreement with data protection terms is available.

Step 6: Plan training and acknowledgement

A policy no one has read is not a policy. Plan a short mandatory training session, a written acknowledgement captured in your HRMS, and refresher content when the policy changes. New joiners should complete this during onboarding.

Step 7: Set a review cadence

AI tools change monthly. Your policy should be reviewed at least every six months in the first year, and annually after that, with an explicit trigger for interim review when a major new tool is adopted, a significant incident occurs, or the legal landscape shifts.

Step 8: Get legal review before publishing

This is where "consult counsel" is not a disclaimer but a genuine step. Your lawyer should check the policy against your employment contracts, client agreements, data protection obligations and any sector-specific regulation. Ask them specifically about candidate and employee notices for AI-assisted processing.

Section-by-section AI policy template with sample clauses

The clauses below are original sample text designed for adaptation. They are written in plain language deliberately; a policy that reads like a statute will not be followed. Replace bracketed placeholders, delete what does not apply, and have counsel review the final version.

1. Purpose and scope

Purpose. This policy sets out how [Company] and its people may use artificial intelligence tools, including generative AI, in the course of work. Its aim is to let us benefit from these tools while protecting our company, our clients, our employees and our candidates from the risks that come with them. Scope. This policy applies to all employees, contractors, interns and consultants of [Company], on any device and any account, whenever company information or company work is involved. It applies to standalone AI tools, AI features built into other software, and AI services accessed through third parties. It applies with additional requirements to the Human Resources function, as set out in Section 9.

2. Definitions

AI tool means any software or service that generates, summarises, classifies, predicts, transcribes or recommends content or decisions using machine learning or similar techniques. This includes chat assistants, code assistants, image and video generators, meeting transcription services, and AI features embedded in productivity, HR, sales or engineering software. Generative AI means an AI tool that produces new text, code, images, audio or video in response to prompts. Approved tool means an AI tool listed on the company's Approved AI Tools Register, used through the account type specified there. Company information means any information created, received or held in connection with [Company]'s business, regardless of format or classification. Personal data means any information relating to an identifiable individual, including employees, candidates, clients' personnel and other third parties. People decision means any decision about hiring, compensation, promotion, performance rating, discipline, termination or other matters materially affecting an individual's employment or candidacy.

3. Approved tools

Employees may use AI tools listed on the Approved AI Tools Register, maintained by [IT/HR], through the account type specified for each tool. Where the register specifies an enterprise or business account, use of a personal or free account for company work is not permitted. Requests to add a tool to the register should be submitted through [form/channel]. [IT security] will review data handling, retention, training practices and access controls, and [HR] will review any tool intended for use with employee or candidate data. Decisions will normally be communicated within [five] working days. Until a tool is approved, it may be used only with public information as defined in Section 5.

4. Prohibited uses

Regardless of tool, the following are not permitted: 1. Entering restricted information, including personal data, salary and payroll data, credentials, source code, or client confidential material, into any AI tool that is not approved for that data tier. 2. Using AI to make a people decision without human review as described in Section 8. 3. Presenting AI-generated content as the employee's own original work where originality is expected, including in publications, legal submissions or certifications. 4. Using AI to generate content that is discriminatory, harassing, defamatory, misleading or unlawful. 5. Using AI to impersonate any real person, including generating voice, likeness or written communications purporting to be from a colleague, client or executive. 6. Disabling, bypassing or misrepresenting any security or data protection setting on an approved tool. 7. Recording or transcribing meetings with AI tools without informing all participants. 8. Using AI tools to access, scrape or analyse information the employee is not authorised to access.

5. Data classification and permitted AI use

All company information falls into one of the following tiers. When in doubt, treat information as belonging to the higher tier.
TierDescription and examplesPermitted AI use
PublicPublished website content, press releases, public job descriptions, marketing collateral already releasedAny approved tool; unapproved tools permitted for this tier only
InternalMeeting notes without personal data, internal process documents, draft marketing content, general project updatesApproved tools with business or enterprise accounts only
ConfidentialClient deliverables, pricing, financials, product roadmaps, unreleased features, vendor contracts, board materialsApproved tools specifically cleared for confidential data, with training on inputs disabled; manager awareness required
RestrictedEmployee and candidate personal data, payroll and compensation records, health information, credentials, source code, legal and disciplinary matters, any data under client contractual restrictionOnly tools explicitly approved for restricted data under a written agreement; anonymise where possible; HR or legal sign-off required for any new use
Anonymisation means removing or replacing names, contact details, identification numbers, dates of birth, photographs and any other detail that could identify a person, before entering information into an AI tool. Anonymised information may be treated one tier lower than its original classification, unless it remains re-identifiable.

6. Disclosure and attribution

Employees must disclose the use of AI tools where: - The output will be shared externally and is substantially AI-generated, in which case the receiving party should be told on request and the content must have been reviewed by the employee. - The output will inform a people decision, in which case the disclosure is recorded in the relevant document or system. - A meeting is being recorded or transcribed by an AI tool, in which case all participants are informed at the start. - A manager or client asks whether AI was used. AI assistance does not need to be disclosed for routine editing, formatting, translation of the employee's own drafts, or code completion within approved development environments, provided the employee has reviewed the result. Employees must not attribute AI-generated text to a real person as a quotation or cite sources generated by an AI tool without verifying that they exist and say what is claimed.

7. Accuracy and human review of AI-assisted work

The employee who uses an AI tool is responsible for the accuracy, quality and appropriateness of the output, exactly as if they had produced it without assistance. AI-generated figures, legal or regulatory statements, citations, calculations and factual claims must be independently verified before use. Any AI-generated output intended for publication, submission to a client or regulator, inclusion in a product, or reliance in a financial or legal matter must be reviewed by a person with the relevant expertise before release.

8. Human review of AI-assisted decisions

AI tools may support, but must not make, any people decision. Specifically: - A named individual with appropriate authority must review the underlying information, not only the AI summary, before the decision is made. - The reviewer must be able to explain the decision in their own words without reference to the AI output. - The reviewer must record, in the relevant system, that AI assistance was used and that the review took place. - Where an AI tool produces rankings, scores or recommendations about people, these are treated as one input among several and never as the sole basis for action. - Any individual affected by a people decision may ask whether AI assisted the process and receive an honest answer.

9. HR-specific rules

Because the Human Resources function processes the most sensitive personal data in the company, the following additional rules apply to HR staff and to managers performing HR tasks. Screening and shortlisting. AI tools may be used to organise, summarise or extract information from applications only through tools approved for restricted data. AI must not be used to automatically reject candidates. Every rejection at any stage must be confirmed by a person who has reviewed the candidate's application. Screening criteria applied by AI tools must be documented and checked at least [quarterly] for unequal impact across gender and other groups. Candidate notice. Where AI tools assist in screening or assessment, candidates must be informed through the job posting, application portal or application confirmation, in plain language, and given a contact for questions. Consult legal counsel on the wording and any consent requirements. Interview notes. AI transcription of interviews requires the candidate's informed agreement at the start of the interview. Transcripts and AI-generated summaries are restricted information, are stored only in the approved recruiting system, and are retained according to the recruitment records retention schedule. Interviewers must record their own assessment, not only an AI summary. Performance reviews. Managers may use approved tools to improve the clarity of their own drafted feedback. They must not enter another employee's personal data, prior reviews or peer feedback into any tool not approved for restricted data, and must not use AI to generate ratings, rankings or comparative assessments. Review content must reflect the manager's own observations. Employee queries and chatbots. Any AI assistant that answers employee questions about leave, payroll, benefits or policy must be clearly labelled as automated, must offer a route to a human, and must not provide binding interpretations of statutory entitlements, tax treatment or contractual terms. Payroll, tax and compliance questions with financial consequences must be confirmed by an authorised HR or finance team member. Disciplinary and grievance matters. AI tools may not be used to draft, summarise or analyse disciplinary or grievance material unless the tool is approved for restricted data and the HR head has authorised the specific use.

10. Security requirements

- Use approved tools only through company-managed accounts with single sign-on and multi-factor authentication where available. - Do not install AI browser extensions or desktop agents that can read screen or page content unless they appear on the register. - Disable data sharing for model training on any approved tool where the setting is available. - Do not enter passwords, API keys, access tokens or similar credentials into any AI tool. - Do not connect AI tools to company data sources, drives, email or messaging platforms without IT approval. - Treat AI-generated code as untrusted until reviewed; it must pass the same code review and security checks as any other code. - Report any suspected data exposure immediately under Section 11.

11. Incident reporting

If you believe that confidential or restricted information has been entered into an unapproved tool, that an AI tool has produced harmful or discriminatory output that was acted upon, or that any other breach of this policy has occurred, report it to [IT security contact] and [HR contact] as soon as possible and within [24 hours] of becoming aware. Early, honest reporting will be treated as a mitigating factor. The company's priority in any incident is to contain the risk, not to assign blame. Where personal data may have been exposed, the company will assess its notification obligations with legal counsel.

12. Consequences of non-compliance

Breaches of this policy will be handled under the company's disciplinary policy. The response will consider the sensitivity of the information involved, whether the breach was deliberate, whether it was reported promptly, and any prior breaches. Serious or repeated breaches, including deliberate exposure of restricted data or use of AI to make undisclosed people decisions, may result in termination of employment or engagement.

13. Policy ownership and review

This policy is owned by [Head of HR] with support from [IT security lead]. It will be reviewed at least every [six months] during its first year and annually thereafter, and additionally whenever a significant new AI tool is adopted, a material incident occurs, or relevant law or regulation changes. Employees will be notified of updates and asked to acknowledge the revised version through the HRMS.

Allowed vs not-allowed AI uses by role

Abstract rules become clearer with role-specific examples. The table below illustrates how the data tiers translate into daily decisions. Adapt the examples to your own business.

RoleAllowed (with approved tools)Allowed with conditionsNot allowed
HRDrafting job descriptions from a role brief; rewriting policy documents for clarity; generating interview question banks; summarising anonymised engagement survey themesSummarising interview notes in a tool approved for restricted data, with candidate agreement; drafting review language from the manager's own notes with names removedUploading resumes to a consumer chatbot; asking AI to rank or reject candidates; entering salary data, medical information or grievance records into unapproved tools; generating performance ratings
SalesDrafting cold outreach from public information; summarising public research on a prospect's industry; polishing proposal language that contains no pricingSummarising call notes in an approved CRM AI feature; drafting proposals containing pricing in a tool cleared for confidential dataPasting client contracts, client customer lists or negotiated pricing into unapproved tools; sending AI-generated claims about product capabilities without verification
EngineeringExplaining public documentation; generating boilerplate for open-source libraries; writing tests for non-sensitive code in an approved code assistantUsing an approved enterprise code assistant on proprietary code with training on inputs disabled; AI-assisted code review within the approved development environmentPasting proprietary code, architecture documents or credentials into consumer chatbots; merging AI-generated code without review; connecting unapproved AI agents to repositories or production systems
FinanceDrafting generic templates for expense policies; explaining public accounting concepts; formatting already-public financial summariesReconciling anonymised data in a tool cleared for confidential information; drafting board commentary from internal figures in an approved toolEntering payroll data, bank details, unreleased financials, tax filings or audit material into unapproved tools; relying on AI for statutory calculations without professional verification

Notice the pattern: the difference between "allowed" and "not allowed" is rarely the task. It is the combination of the data involved and the tool used.

Rolling out your workplace AI policy

Publication is the beginning, not the end. A policy that lands in an inbox and disappears has changed nothing. Rollout deserves as much thought as drafting.

Communication

Announce the policy from leadership, not only from HR, and frame it positively. The message is "we want you to use these tools well," not "we are watching you." Explain the reasoning behind the main rules, especially data classification, because people follow rules they understand.

Provide a one-page summary alongside the full policy. Most employees will only read the summary, so make it good: the tool register, the four data tiers, the short prohibited list, and where to ask questions.

Training

Keep the initial session to thirty or forty minutes. Cover the principles, walk through the data tiers with real examples from your own business, show how to check whether a tool is approved, and rehearse two or three realistic scenarios. Scenario-based training sticks far better than clause-by-clause reading.

Run a separate, deeper session for HR staff and people managers covering candidate notice, interview transcription, performance review rules and bias checks.

Manager FAQs

Managers will field most day-to-day questions. Equip them with a short FAQ covering the questions you expect, such as:

  • "Can my team use the free version of a chatbot for internal notes?" (Depends on the data tier and the register; usually no for anything beyond public information.)
  • "An employee used AI to write a client email and it contained an error. Who is responsible?" (The employee, as with any other work product.)
  • "Can I use AI to help write appraisals?" (For polishing your own drafted language with names removed, yes; for generating ratings or comparisons, no.)
  • "A vendor wants to demo an AI tool with our data. What do I do?" (Route through the approval process before any data is shared.)

Acknowledgement through the HRMS

Capture acknowledgement formally. Distribute the policy through your HRMS document management module, require employees to read and accept it, and keep a timestamped record. This matters for two reasons: it is evidence that the policy was communicated, and it lets you track who has not yet acknowledged and follow up. Platforms such as CozyHR let HR teams publish policies, collect e-acknowledgements and automate reminders, which removes the spreadsheet-chasing that usually kills this step.

Tie acknowledgement into onboarding so that every new joiner accepts the current version before receiving system access.

Monitoring without surveillance overreach

You need some visibility into AI use to know whether the policy is working. You do not need to read everyone's prompts. Reasonable monitoring looks like:

  • Reviewing which tools are accessed through company networks and accounts at an aggregate level.
  • Using enterprise AI tools' admin dashboards for usage volumes and settings compliance.
  • Periodic spot checks of externally facing content for accuracy and attribution.
  • Incident reports and their trends.

Avoid keystroke logging, covert screen capture, or reading individual conversations without a specific, documented reason. Heavy surveillance undermines the trust that makes a policy work and may raise its own legal and privacy concerns. Be transparent about what monitoring you do perform; your policy or a companion IT acceptable use policy should describe it.

Special guidance for HR teams using AI

HR teams are both the authors of the policy and its most consequential users. This section goes deeper on three areas where AI and people decisions intersect.

AI in recruiting

Recruiting is the most common HR use case for AI, and the one with the clearest fairness risks.

Candidate notice. Tell candidates, in the job posting or application flow, that AI tools may assist in organising and reviewing applications, that a person makes every decision, and whom to contact with questions. Keep the wording honest and specific. Consult counsel on whether consent, in addition to notice, is required for your particular processing.

Tool selection. Prefer tools that extract and organise information (skills, experience, qualifications) over tools that score or rank. If you do use scoring, insist on understanding what the score is based on. Ask the vendor for documentation on how they test for bias and what data the model was trained on. If they cannot answer, that is your answer.

Bias checks. At a set cadence, compare the pass-through rates of AI-assisted screening stages across gender and any other characteristics you can lawfully and appropriately track. Look for unexplained gaps. Also check for proxy bias: the tool may not see gender, but it may penalise career breaks, certain institutions or particular locations in ways that correlate with it.

Human review. No candidate should be rejected solely because a tool did not shortlist them. A recruiter should at minimum review every application that the tool deprioritised before the role closes, even if briefly. This is more work. It is also the difference between assisted and automated decision-making.

Records. Keep a record of which tools were used, what criteria they applied, who reviewed the outputs, and when. If a candidate later questions the process, you want to be able to show it.

AI in performance management

Performance reviews are where managers most often reach for AI, usually to make their writing sound better. The risks are subtle.

The "polish" trap. When a manager pastes rough notes about a specific employee into a chatbot, they have entered restricted personal data into a tool. Even if the tool is approved, the result is often generic language that loses the specific observations that make feedback useful. Encourage managers to draft their own feedback and use AI only to improve clarity, with names and identifying details removed.

No AI ratings. Never let a tool produce a rating, a ranking or a comparative statement about employees. Ratings must come from human judgement applied to evidence.

Theme analysis. Using AI to identify themes across anonymised, aggregated feedback (for example, in engagement surveys) is generally lower-risk and can be genuinely useful. Make sure the aggregation really is anonymous; small teams can be re-identified easily.

Records. Note in the review system when AI assisted the drafting. If an employee challenges a review, transparency about process is protective.

AI in employee queries and payroll support

HR chatbots and AI assistants can dramatically reduce the volume of repetitive questions about leave balances, holiday lists, reimbursement processes and policy details. They also carry a specific risk: confident wrong answers about money.

Label it. Employees must know they are talking to an automated assistant.

Bound it. Restrict the assistant to answering from your approved policy documents and HRMS data, not from general model knowledge. A question about gratuity eligibility should be answered from your policy or escalated, not improvised.

Escalate financial questions. Any query that could change what someone is paid, deducted or taxed should be routed to a human for confirmation. The assistant can gather information and draft a response; a person signs off.

Keep logs. Retain chatbot interaction logs according to your retention schedule so that disputes can be reviewed. Treat these logs as restricted data.

Watch for drift. Periodically sample chatbot responses for accuracy, especially after policy updates. An assistant that answers from an outdated leave policy is worse than no assistant at all.

Common mistakes when writing an AI use policy

Having a policy is better than not having one, but certain patterns reliably produce policies that fail.

Banning everything. A blanket prohibition is easy to write and impossible to enforce. People will use AI anyway, and you will have lost the chance to guide them.

Approving everything. The opposite failure. "Use your judgement" is not a policy. Without data tiers and a tool register, employees cannot tell where the lines are.

Writing it in legalese. If your policy needs a lawyer to interpret, it will not shape behaviour. Write plainly; let counsel review for accuracy rather than authoring the whole thing.

Forgetting HR's own use. Many policies govern "employees" and silently exempt the HR team processing the most sensitive data in the building.

Skipping the tool inventory. Writing rules without knowing what is in use produces rules that do not match reality.

Ignoring embedded AI. Your email client, spreadsheet, CRM and HRMS may all have AI features. If the policy only mentions chatbots, these fall through the gap.

Treating anonymisation as a magic word. Removing a name does not anonymise a record if the remaining details identify the person. Small companies are especially exposed to this.

No approval process. If there is no way to get a tool approved, employees will not ask. Shadow AI follows.

No review date. A policy written for the tools of one year will be wrong within the next. Build in review from day one.

Surveillance instead of trust. Monitoring that feels like spying kills the openness a policy depends on.

Publishing without acknowledgement. Without a record that people have read and accepted the policy, it is hard to rely on it when something goes wrong.

Workplace AI policy checklist

Use this list to check your draft before it goes for legal review.

  • [ ] Purpose and scope are stated in plain language and cover employees, contractors and HR's own use.
  • [ ] Key terms are defined, including AI tool, approved tool, personal data and people decision.
  • [ ] Six responsible-AI principles (fairness, transparency, human-in-the-loop, accountability, data minimisation, explainability) are stated.
  • [ ] A tool inventory has been completed and an Approved AI Tools Register exists.
  • [ ] A fast, documented approval process for new tools is in place with a named reviewer.
  • [ ] Data is classified into tiers with concrete examples and a permitted-use table.
  • [ ] The prohibited-uses list is short, absolute and clearly worded.
  • [ ] Disclosure rules cover external content, people decisions, meeting transcription and direct questions.
  • [ ] Accuracy responsibility sits explicitly with the human user.
  • [ ] Human review of AI-assisted people decisions is mandatory and documented.
  • [ ] HR-specific rules cover screening, candidate notice, interview transcription, performance reviews, employee chatbots and disciplinary matters.
  • [ ] Security requirements reference company-managed accounts, training opt-outs, credentials and code review.
  • [ ] Incident reporting has a contact, a timeline and a no-blame framing.
  • [ ] Consequences link to the existing disciplinary policy.
  • [ ] Ownership, review cadence and triggers for interim review are named.
  • [ ] Role-based examples have been prepared for training.
  • [ ] A one-page summary and manager FAQ exist.
  • [ ] Acknowledgement will be captured through the HRMS, including at onboarding.
  • [ ] Monitoring approach is proportionate and described transparently.
  • [ ] Legal counsel has reviewed the policy, including candidate and employee notices and processor arrangements.

FAQ

Do small companies really need a formal AI use policy?

Yes, and arguably more than large ones. Small companies adopt tools faster, have fewer technical controls, and often handle client data under contracts that assume enterprise-level care. A short, clear policy costs little to produce and prevents the kind of accidental leak that can end a client relationship.

Can we simply ban generative AI at work?

You can write that rule, but you cannot enforce it, and it will push use underground where it is invisible. A policy that approves specific tools and sets clear data rules gives you far more control than a ban does.

What counts as an "AI tool" under the policy?

Anything that generates, summarises, classifies, transcribes, predicts or recommends using machine learning. That includes chat assistants, code assistants, image generators, meeting note-takers, and AI features inside your existing email, spreadsheet, CRM and HRMS products. Embedded features are the ones most often missed.

Is it acceptable for HR to use AI to screen resumes?

It can be, with safeguards. Use tools approved for restricted data, tell candidates that AI assists the process, never let the tool auto-reject, ensure a person reviews every application before a final decision, check the outcomes for unequal impact, and keep records. Consult counsel on notice and consent requirements for your situation.

How do the DPDP Act principles affect our AI policy?

The principles of purpose limitation, data minimisation, accuracy, security and transparency are directly relevant whenever AI tools process personal data of employees, candidates or others. Your policy should treat personal data as restricted by default and require anonymisation and approved tools. The specific legal obligations, timelines and exemptions applicable to your organisation are a matter for your legal advisers.

Who owns the content an employee creates with AI?

The answer depends on the vendor's terms, your employment contracts and the developing legal position on AI-generated works. As a practical matter, treat AI output as raw material that becomes company work product once a person has reviewed, edited and taken responsibility for it, and never use AI output commercially without review. Ask counsel to review vendor terms for any tool used to produce commercial content.

How often should we update the policy?

Every six months during the first year, annually after that, and whenever a major new tool is adopted, a significant incident occurs or the legal landscape changes. Each update should be redistributed for acknowledgement.

What is the single most important rule if we can only enforce one?

Never enter restricted information, especially personal data, into a tool that has not been approved for it. Most serious AI-related incidents in workplaces trace back to that one action.

Conclusion

A workplace AI use policy is not about slowing people down. It is about letting them use powerful tools with confidence, knowing where the lines are and why they exist. The companies that handle this well are not the ones with the longest rulebooks; they are the ones with clear data tiers, a short list of approved tools, honest disclosure habits, and a firm commitment that people, not models, make decisions about people.

Start with the template above, adapt it to your business, train your team, and capture acknowledgements so the policy has real standing. Then review it regularly, because the tools will keep changing.

If you want a simpler way to publish your policy, collect e-acknowledgements from every employee, and keep the current version at the centre of onboarding, CozyHR's document management and policy acknowledgement features are built for exactly that. It is a small operational detail, but it is the one that turns a good document into a working policy.