In many companies, AI use didn't start with a management decision but on employees' own initiative. One person opened a chat tool to polish a proposal, another to find an Excel formula, another to translate a customer email into English. This use is often helpful, but it has no rules. An AI acceptable use policy for employees is the most practical way to keep those benefits while managing data, quality and accountability risks. In this post we propose the outline of a policy that employees will actually read and follow, not a long legal document.
Why a ban doesn't work
The first reflex is often to say "no AI on company computers." This usually leads to two outcomes: employees don't stop using it, they just move to their personal phones and accounts, and the company loses all visibility into which data goes where. On top of that, your team falls behind while competitors speed up with the same tools.
The healthier path is to provide approved tools and write down the limits clearly. A good policy says "yes, like this" as much as it says "no."
The main sections of the policy
A policy of no more than a few pages should cover these sections:
- Purpose and scope. Who does the policy cover (employees, interns, external contractors) and which tools (chat tools, writing assistants, coding assistants, image generators)?
- Approved tools list. Which tools may be used, in which versions and with which accounts? Is use outside company accounts allowed?
- Data rules. Which data may be entered into a tool, and which must never be?
- Responsibility for output. The person using AI output is responsible for its accuracy.
- Transparency. When AI use should be disclosed in customer-facing content or official documents.
- Requesting new tools. The process for someone who wants to use a tool not on the list.
- Violations and reporting. What to do, and whom to notify, when sensitive data is entered by mistake.
- Review. How often the policy will be updated.
Explain the data rules with a table
The most-read part of the policy is the data rules, and the clearest format is a simple table:
| Allowed | With care, only in approved business tools | Not allowed |
|---|---|---|
| Published website and catalog text | Internal correspondence with personal data removed | Customer and employee personal data |
| General industry and technical information | Anonymized report summaries | Health, salary, special category data |
| Draft text without personal data | Proposal templates without prices | Passwords, access keys, source code |
| General Excel formula questions | Internal process documents | Contracts, special pricing, cost structure |
We explain the reasoning behind this classification and its KVKK (Türkiye's Personal Data Protection Law) dimension in more detail in our post on giving company data to AI tools. Wherever personal data is processed, KVKK topics such as the duty to inform and cross-border transfer rules should also be reflected in the policy.
Responsibility for output and review
The second critical part of the policy is output. What needs to be stated clearly:
- AI output is checked as if it were the user's own work; "the AI wrote it that way" is not an excuse.
- Output containing figures, dates, names, legal references or technical values is verified against the source.
- Every text that is sent to a customer, published or signed passes through a person's approval.
- Text, images or brands belonging to others are not used without permission.
For practical verification methods, see our post on hallucinations and accuracy checks.
Keeping the policy alive: training and updates
A policy that is written and filed away doesn't get followed. To put it into practice:
- Hold a short introductory meeting and explain the policy with examples.
- Prepare a one-page summary and keep it somewhere easy to reach.
- Name one person in each department as the go-to contact for questions.
- Update the approved tools list and the rules at least once a year, and immediately when a major tool change happens.
- Share good examples of use within the team, so the policy doesn't look like a list of bans.
Checklist
- Approved tools and their versions are listed.
- Tool accounts are managed by the company.
- The data table (allowed, with care, not allowed) is ready.
- Responsibility for output and the approval rule are in writing.
- The reporting path for sensitive data entry is clear.
- The introduction is done and the one-page summary is shared.
- A review date is set.
How we do it at Globya
We prepare the use policy by looking at your company's real workflows: which team uses which tool and why, and which data passes through where. We set up business accounts and access management for the approved tools, and write the policy so it speaks the same language as your KVKK compliance work. For the final review of legal texts, we recommend working together with your legal counsel. To get started, reach us via the contact page or by phone at +90 850 432 55 13.
Frequently asked questions
Does a small company need a written policy too?
Yes, but it can be short. Even in a team of five, having in writing which tools to use and which data not to enter noticeably reduces mistakes.
Should we allow employees to use their personal AI accounts?
If they will work with company data, we recommend accounts managed by the company. With personal accounts, data terms and access control are not in the company's hands.
What should we do if the policy is violated?
Limiting the damage comes first: identify which data was entered into which tool and, if needed, request deletion from the provider. If personal data is involved, an assessment under KVKK should be made.
How often should the policy be updated?
Because AI tools change quickly, it should be reviewed at least once a year, and immediately whenever there is a significant change to the approved tools list.
The Globya assistant is online 24/7; it answers right away and passes your question to the team if needed.