Write for the category, not one logo
Employees often use ChatGPT as shorthand for many generative assistants. A resilient policy governs the use case and data rather than one vendor name, so the rule remains useful as tools change.
Distinguish personal accounts from company-approved configurations. Contract terms, retention, settings and access can change what is acceptable even when the prompt looks identical.
Make data boundaries concrete
“Do not enter sensitive data” is not operational enough. Use company-relevant examples such as customer contracts, candidate CVs, payroll details, source code, strategy and internal documents.
- public information that may be used
- internal data allowed only in an approved account
- personal or confidential data requiring review
- secrets and credentials that never belong in a prompt
Match verification to consequence
An internal draft and a client recommendation do not carry the same impact. Define who checks facts, calculations, citations, rights and tone before an output affects a decision or external communication.
Give exceptions a route
People need a known place to request a new tool or use case and a different route to report accidental exposure. A rule without a route drives hidden use rather than control.
General educational material. It is not legal advice and does not replace legal, DPO, HR or security review appropriate to your organisation.
