17Teams and operations · Template، Guide، Checklist

Practical Team Guidelines for Using AI

Editable starter guidelines: allowed data, review, responsibility, source checking, disclosure and escalation, with a filled example for a small team.

Who it's for
For team leads, small-business owners and associations who want short, clear rules for everyday AI use at work.
Level
Intermediate
Time
50 min
Version
1.0 · 21 September 2026
Important: this is a practical starting draft for organising work inside your team. It is not legal advice and not a compliance certification for any law or standard. Laws differ between countries and sectors, and they change. If you work in a regulated sector (health, finance, legal, education) or process personal data at scale, review the guidelines with a legal professional before adopting them.

Why written guidelines?

In most teams AI is already in use, whether management knows it or not. No rules does not mean no use; it means everyone sets their own rules. One person pastes a full customer file, another avoids the tools entirely for fear of doing something wrong. Written guidelines protect both sides: they protect data and reputation, and they give staff clear permission to use the tools for what is allowed, without hesitation.

Good guidelines are short enough to be read and specific enough to be applied. Two pages beat twenty pages nobody opens. The template below is built to be edited: delete what does not fit, add what your sector needs.

The six principles behind the template

  1. A person is responsible. The tool suggests; whoever uses the output owns it as if they had written it themselves.
  2. Data before tool. The first question is always: what am I about to paste, and does its classification allow it?
  3. No output without review. Anything that reaches a customer, partner or audience passes a human eye first.
  4. Every number, name and reference is checked. Language models can be confident and wrong at the same time.
  5. Honesty with the audience. We disclose AI use when the audience expects it or a body requires it, and we never generate a real person's face or voice without their written consent.
  6. Report without blame. A mistake reported early gets fixed; a hidden one grows.

Classifying data: the traffic light

The easiest way to make a data rule usable is three colours everyone knows:

ColourExamplesRule
GreenPublished information, marketing copy, product specifications, general ideas, drafts with no namesAllowed in approved tools.
AmberInternal minutes, price quotes, performance reports, work correspondence with names removedAllowed after anonymising (removing names, numbers and identifying details), and in approved tools only.
RedPersonal data about customers, staff or beneficiaries, health data, salaries, bank details, contracts, passwords, trade secretsNot allowed in public tools. Only in an approved enterprise tool under a contract that defines data processing, with prior approval from the named person.

Anonymising is more than removing the name. A phone number, address, file number, date of birth or a precise description of a rare case can all identify someone. The practical test: if someone from the same town read the text, could they tell who it is about?

The editable template

Copy the template, fill in the square brackets and delete what does not apply. Then discuss it with the team before adopting it; rules the team helped write are the ones that get followed.

AI use guidelines — [organisation name]
AI use guidelines at [organisation name]
Version: [1.0] | Adopted: [ ] | Next review: [in 6 months]
Owner of these guidelines: [name/role]

These are internal working guidelines, not legal advice or a compliance certificate.

1. Purpose and scope
They apply to everyone working with [organisation]: staff, contractors, volunteers.
They cover chat tools, image, video and voice generation, and assistants inside work apps.

2. Approved tools
Tools allowed for work: [tool, plan/account, for which use]
Using an unlisted tool for work needs approval from: [role]
Work accounts are kept separate from personal accounts wherever possible.

3. Allowed data
Green (allowed): [examples from your work]
Amber (after anonymising): [examples]
Red (not allowed in public tools): [examples]
When in doubt: treat it as red and ask [role].

4. Human review
Every output that reaches a customer, partner or audience is reviewed by a person first.
Extra review by [role] is required for: [contracts, medical/financial content, official
statements...]

5. Responsibility
Whoever uses an output is responsible for it as if they had written it.
A mistake in sent work is never blamed on the tool: review is part of the job.

6. Checking facts and sources
Every number, name, date and reference is checked against an original source before use.
Sensitive information needs two independent sources.
We never cite a reference we have not opened and read.

7. Disclosure
We disclose AI use when: [the audience expects it / the client asks / a platform or
authority requires it / an image or voice could be mistaken for reality]
Approved disclosure wording: [e.g. "Prepared with the help of AI tools and reviewed
by our team"]

8. Images, voices and ownership
We do not generate a real person's face or voice without their written consent.
We do not imitate others' logos or brands, or a named artist's style.
Generated product images must match the real product.

9. Where we do not use AI
[hiring or dismissal decisions, diagnosis, final legal advice,
replies to sensitive complaints without review, ...]

10. Reporting and escalation
If red data was pasted, a wrong output was published, or a customer complained:
tell [name/role] within [24 hours] via [channel].
Early reporting is never penalised. Hiding it is the problem.

11. Learning and review
A short briefing on these guidelines for every new member: [who gives it]
The guidelines are reviewed every [6 months] or after a tool change or incident.

I have read these guidelines: [name] [date]

How to adopt the guidelines in two weeks

  1. Day 1: ask before you write. A three-question survey for the team: Which tools do you use? For which tasks? What worries you? You will learn what is really happening, not what you assume.
  2. Days 2–4: fill in the template. Start with the data and approved-tools sections; they matter most. Use examples from your real work in every colour.
  3. Days 5–7: discuss the draft. One meeting with the team. Ask: Which rule is unclear? Which rule will not actually be followed? Revise.
  4. Days 8–10: get the review you need. If your sector is regulated or you handle a lot of personal data, show the draft to a legal professional.
  5. Day 11: adopt and announce. Sign version 1 and ask everyone to read it and sign that they have.
  6. After that: review regularly. After three months ask: Were there incidents? Which rule was broken most, and why?

A filled example: a small design studio

Illustrative example

"Cedar Design Studio" is a fictional six-person studio in Tripoli that designs visual identities and social media content for local clients. These are extracts from its guidelines once filled in:

  • Approved tools: one chat tool on a team account for text, and one image-generation tool. Any other tool needs the art director's approval.
  • Green: campaign ideas, post copy before approval, visual descriptions, summaries of published articles.
  • Amber: the client brief with the client's name and brand removed if not yet public, campaign performance reports with financial figures removed.
  • Red: client contracts, invoice data, logo files before launch, any personal data about the client's audience.
  • Review: every post goes through the copywriter and then the account manager. Any image showing a real product is compared with the original product photo before delivery.
  • Disclosure: the contract tells clients the studio uses AI tools in production with full human review. If a published image is generated and looks real (a person or place), a clear label is added when the platform or client requires it.
  • Not allowed: generating faces that resemble real people, imitating a named designer's or artist's style, putting a client's logo into a public tool before launch.
  • Escalation: any incident is reported to the art director within 24 hours by direct message and discussed at the weekly meeting without blame.

After three months, the studio noticed that the rule broken most often was pasting the full client brief. The fix was not a penalty but a ready-made anonymised brief template that saves the team time.

Questions teams usually ask

  • Can I use my personal account for work? Better not, because management cannot control its settings or what stays in it after you leave. State in the guidelines when, if ever, it is allowed.
  • Do I have to mention the tool in every email? No, not for everything. Disclosure is needed when the audience expects it, the client asks, a body requires it, or content could be mistaken for reality. Define your cases in section 7.
  • What if I paste something red by mistake? Report it at once. Many tools let you delete the conversation, and the owner decides what else is needed. Quick reporting limits the harm.
  • Do these rules stop us benefiting? The opposite: clear rules open up use for everything green and amber without hesitation.

Common mistakes

  • Mistake: copying a long policy from a large corporation. Fix: two pages with examples from your own work get followed more than twenty generic pages.
  • Mistake: banning everything "to be safe". Fix: blanket bans push people to hidden use; state clearly what is allowed.
  • Mistake: a vague data rule such as "do not paste sensitive information". Fix: specific examples for each colour from your real work.
  • Mistake: not saying who to report to and how. Fix: a name or role, a deadline and a channel.
  • Mistake: treating the draft as a compliance certificate. Fix: it is internal organisation; legal requirements are reviewed with a professional.
  • Mistake: writing it once and forgetting it. Fix: a review date written at the top of the document.

Completion checklist

  • I asked the team about their real use before writing.
  • Approved tools are named, and it is clear who approves others.
  • Each colour (green, amber, red) has examples from our real work.
  • The human review rule is clear and extra reviews are specified.
  • Disclosure cases and wording are written down.
  • The reporting path has a name or role, a deadline and a channel.
  • The text states plainly that it is not legal advice or a compliance certificate, and a professional reviewed it where needed.
  • Every member signed that they have read it, and the next review date is set.

Next step

Want a view on your own situation? AI Workflow & Automation — a 75-minute session.

Book a strategy session

Free to use in your work and organisation; credit the source if you republish.