Home / Guides / employee-ai-policy-chatgpt

Employee AI use policy template for ChatGPT, Claude, and Gemini

Draft an enforceable AI acceptable-use policy: approved tools, PII rules, incident response, and technical controls (Shield + MDM) security teams can actually deploy.

Published 2026-08-28 · NoeticGuard engineering notes

Policy sections to include

  1. Scope — all staff, contractors, and managed devices using AI assistants.
  2. Approved tools — enterprise ChatGPT, M365 Copilot, or internal gateways only.
  3. Prohibited data — customer PII, payment cards, health records, live API keys, unreleased financials, M&A codenames.
  4. Technical controls Browser Shield on managed Chrome, MDM force-install, SDK masking for product features.
  5. Incident response — report suspected paste/leak to security within 24 hours; preserve timestamps, do not re-paste into another LLM.

Enforcement walkthrough: stop employees pasting PII into ChatGPT. Evaluating alternatives? See our comparison hub.