What Rules Should Staff and Freelancers Follow When Using AI?
IT Club provides practical technology guidance, not legal advice. Laws, contractual obligations and regulatory requirements vary according to the organisation, sector, data, location and use case. Obtain appropriate legal, data-protection, employment or regulatory advice where required.
A business has no meaningful AI policy when staff do not know which tools are permitted or what information must stay out of them. This guide sets out the practical, operational rules a small team actually needs — it is not a legal employment policy, and formal contractual wording should receive legal review.
The rules that matter day to day
- 1Use approved tools only — and know where the approved list lives. Anything else needs a quick request, not a quiet workaround.
- 2Use business accounts, not personal ones. Account ownership determines who controls the data, the settings and the history when someone leaves.
- 3Know the prohibited information: customer data, employee matters, passwords and secrets, financial details, contracts and anything covered by the confidential-information guide. When in doubt, use placeholders.
- 4Check output before it is used. Every AI answer is a draft; anything factual, customer-facing or consequential gets verified against real sources.
- 5Watch for bias — especially in anything touching people: recruitment shortlists, performance wording, customer segmentation.
- 6Customer communication drafted with AI is read in full by a human before sending. No exceptions for busy days — that is when the errors ship.
- 7Verify sources: if the AI cites something, open it. If it cannot be opened, it does not exist for business purposes.
- 8Human approval is named: work that leaves the business has an accountable person, and it is never “the tool”.
- 9Keep light records for significant uses — which tool, roughly what went in, who checked the output.
- 10Report mistakes the same day, without blame. A wrongly pasted document or an error sent to a customer gets smaller when reported early and bigger when hidden.
Shadow AI
Shadow AI — tools in use that the business does not know about — is the most common governance gap. It thrives where the approved route is slow or where asking feels risky. The fix is cultural as much as procedural: make requesting a tool fast, say yes where you reasonably can, and treat discovery of an unapproved tool as a prompt to assess it rather than solely as a disciplinary matter. An amnesty (“tell us what you're using, no consequences, this month”) often surfaces more truth than any audit.
Consequences, fairly framed
Staff should understand that these rules connect to existing obligations — confidentiality clauses, data-protection duties and customer contracts — and that serious or repeated breaches can have disciplinary or contractual implications. Framing matters: the aim is protecting customers, colleagues and the business, not catching people out. Any formal disciplinary wording belongs in employment documentation reviewed by a professional, not in an operational rules page.
Freelancers and contractors
- Apply the same information rules: your confidential and customer data does not change character because a contractor is handling it.
- Say so in the engagement: whether AI use is acceptable on your work, with which tools, and whether it must be disclosed.
- Ask how deliverables were produced where provenance matters — copyright and originality questions flow through to you.
- Do not accept 'my own AI stack' as an answer for confidential work without knowing what that stack does with data.
Offboarding
When staff or freelancers leave: remove their access to business AI accounts, transfer ownership of any chats, projects or custom assistants that the business needs, and check that no business data sits in personal accounts. AI tools belong on the leaver checklist alongside email and file access.
This page is practical operational guidance. Formal employment or contractor wording — policies, contract clauses, disciplinary procedures — should receive legal review before adoption.
Plain-English Takeaway
Ten clear operational rules — approved tools, business accounts, prohibited information, checking, and same-day mistake reporting — do more than any long policy nobody reads. Make the approved route fast, include freelancers, and add AI accounts to the leaver checklist.
Sources and further reading
- ICO — Employment practices and data protection
- NCSC — AI and cyber security: what you need to know
- GOV.UK — Using AI at work: guidance collection
External guidance changes. Check the source itself for the current position before acting on it.