Company rules for AI: what has to be written down first
A company AI policy has to say three things: what it may be used for, what must never be pasted into it, and who is accountable for the result. Without the first, people use it quietly; without the second, data leaves the company; without the third, nobody owns the mistake. A ban with no alternative gets worked around.
What is in and what is out
Split the uses by risk. Brainstorming and cleaning up an internal note are a different league from client-facing copy or input for a contract.
For each category, say whether a human review is required. Most disputes start where nobody said it out loud.
What never goes into a chat
Customer personal data, non-public figures, source code under contract, anything under NDA. The policy should name concrete data types rather than talk vaguely about sensitive information.
A list of approved tools belongs with it. Without one, people use whatever is at hand.
Who owns the output
Whoever sends the text owns it. A model is not a source and its output is not a verified fact.
For documents produced with AI, a short note helps. Not as an admission of guilt, but so the next reader knows what to double-check.
FAQ
Should internal AI use be checked with a detector?
For internal texts it usually makes no sense. Checking pays off where the text goes out under the company name, or where an outside supplier delivered it.
Should we ban AI outright?
A ban with no alternative gets worked around and the company then has no visibility at all. An approved tool and a clear line work better.
Who should write the policy?
Legal and security together with the people who work with text every day. A document written by one side alone is either ignored or blocks the work.
Try it on your own text
Paste a text or upload a file and look at the score and at the specific sentences that came out suspicious.
Run a detection