Your team is already using AI. The question is whether you know which tools, with which data and by what standard. This guide builds the internal policy that answers that in three pages: a copy-and-paste template block by block, a data classification matrix with examples, the technical controls you can turn on today according to the official documentation, and what Mexico's 2025 law and Paraguay's law —with its countdown to November 2027— require.
Short answer: An internal AI use policy defines approved tools, what data may go into them, which outputs require human review and who to ask when in doubt. It has to cover scope, tools, data classification, human review, intellectual property, confidentiality, use of outputs, training, a channel for questions, consequences and effective dates. It fits in three pages and gets reviewed every six months.
- What is an internal AI use policy, and why does your company need one now?
- What happens if you don't have one? The shadow AI problem
- What does the policy have to contain? The eleven mandatory sections
- Policy template, part 1: scope, tools, data and human review
- Policy template, part 2: intellectual property, confidentiality, training and consequences
- How do you classify information into four levels?
- Which technical controls actually exist, according to the official documentation?
- How do you define human review without slowing the work down?
- What changes in Mexico under the 2025 LFPDPPP?
- And in Paraguay? Ley 7593/2025 and the clock running to November 2027
- How do you communicate the policy without slowing adoption?
- How often is it reviewed, and who is answerable for what?
- Tricks that are not in the manual
- What should you do this week?
What is an internal AI use policy, and why does your company need one now?
An internal AI use policy is a short document that defines which tools are approved, what data may go into them, which outputs require human review before they leave the building, and who to ask when there is doubt. It is not a rulebook to slow the team down: it is what lets you say "yes" with confidence instead of saying "no" out of fear. It fits in three pages and gets reviewed every six months.
The question is not whether your team is already using AI. They are. The question is whether you know which tools, with which data and by what standard. With no written policy, everyone improvises their own standard, and improvised standards tend to get generous at three in the afternoon on a closing day.
The document does three concrete things. First, it removes the doubt: someone who knows what they can paste into a chat works faster than someone who does not. Second, it protects people: if something goes wrong and there was a clear rule, the conversation is about the process and not about individual blame. Third, it lets you answer when a client, an auditor or a partner asks how you govern AI use —which by 2026 is already a routine question in tenders.
Notice. This article is educational and informational material. It does not constitute legal advice. Before adopting a policy with employment or data protection effects, review it with a qualified lawyer in the country where you operate.
What happens if you don't have one? The shadow AI problem
What happens is that AI comes in anyway, just through the back door and with no record of it. That is called shadow AI, and it has a very recognizable shape: the most productive person on the team has spent months using a free personal account, pasting in contracts, customer lists or payroll figures, and nobody knows because nobody asked.
The three typical harms are not hypothetical:
- Personal data under terms you do not control. The difference between a consumer plan and a commercial one is not only features: it is the default data policy. Anthropic states that for its commercial products «by default, we will not use your inputs or outputs from our commercial products to train our models», while on consumer plans training depends on a setting the user controls (commercial products · consumer plans, consulted on 19 September 2026).
- Knowledge that walks out with the person. Everything that account learned about your business sits in a personal account. The day someone leaves, it leaves with them.
- Unreviewed output reaching the customer. A quote with an invented number, or an email with another client's data pasted in by mistake.
None of the three is fixed by banning. Banning moves the usage to personal phones and destroys the one useful thing you had: visibility. And the risk is not theoretical in areas like sales, where contact lists and customer data are handled every day; we cover it in practice in B2B lead generation with AI.
What does the policy have to contain? The eleven mandatory sections
Eleven sections, not one more. Nobody reads a thirty-page policy and it protects you from nothing; a three-page one everybody has read does. This is the minimum structure, with what each part resolves.
| Section | What it resolves |
|---|---|
| 1. Scope and who it applies to | Whether it covers staff, interns, contractors and vendors |
| 2. Approved tools | What may be used and how to request something new |
| 3. Data classification | What information may go into each tool |
| 4. Human review | Which outputs do not go out without someone signing off |
| 5. Intellectual property | Who owns what gets generated and what may not be reused |
| 6. Confidentiality and third parties | Customer, vendor and candidate data |
| 7. Use of outputs | Transparency, fact-checking and prohibited uses |
| 8. Mandatory training | What someone must have completed before getting access |
| 9. Questions and incident channel | Who to ask and how to report a mistake |
| 10. Consequences | What happens in case of breach, proportionately |
| 11. Effective date and review | When it applies from and when it gets looked at again |
Note the order: tools come before prohibitions, and training before penalties. A policy that opens with punishment reads like a threat and gets complied with like a threat —that is, badly.
Want a hand applying this?
Free 30-minute working session. Uniamos is a remote AI automation agency (Austin and Mexico City) working over video calls and WhatsApp.
Policy template, part 1: scope, tools, data and human review
Copy these blocks as they are and replace what is in brackets. They are written so that a manager can adapt them in an afternoon with no outside help.
1. Scope. This policy applies to everyone who works for [Legal entity], including employees, interns, contractors and vendors with access to company systems or information. It covers any generative artificial intelligence tool, whether or not the company pays for it, when used for work tasks. It takes effect on [date] and supersedes any previous verbal instruction.
2. Approved tools. Only the tools on this list may be used for work, and only with the corporate account provided by the company: [tool 1], [tool 2], [tool 3]. Personal accounts are not permitted, nor are free versions of these or other tools, for work tasks, because the default handling of data is different.
To propose a new tool, write to [channel] stating: what problem it solves, what data it would need, which plan would be purchased and who the internal owner would be. [Owner] replies within a maximum of [10] business days. Until there is a written reply, the tool is not used with company information.
3. Data that may be used. The company classifies its information into four levels (see appendix). The rule is simple:
Level 1 (public) and Level 2 (internal): may be used in the approved tools.
Level 3 (confidential): only in the approved tools, with a corporate account, and only when the task genuinely requires it. Prohibited in any personal account.
Level 4 (restricted): does not go into any AI tool, under any circumstances, with no exceptions for urgency. If you believe your task requires Level 4 data, do not do it: write to [channel].
When in doubt about the level of a piece of data, treat it as the higher level and ask.
4. Human review. No AI-generated output leaves the company without a named person having reviewed it and taken ownership of it. Specifically, the following require review and sign-off by [role] before being sent: customer communications, quotes and pricing proposals, content published in the company's name, documents with contractual effect, reports containing figures, and any decision that affects a person (hiring, performance, credit, collections).
Reviewing means checking the facts and the numbers against the original source, not skimming. Whoever signs off is answerable for the content exactly as if they had written it by hand.
Policy template, part 2: intellectual property, confidentiality, training and consequences
5. Intellectual property. Everything produced with AI tools in the course of work belongs to [Legal entity] on the same terms as any other work product. It is not permitted to enter third-party copyrighted material into AI tools without authorization, or to publish as our own any content that reproduces someone else's material. Before any generated text, image or code is used in a product that is sold, [role] verifies that it does not incorporate identifiable third-party material.
6. Confidentiality and third-party data. Personal data belonging to customers, vendors, candidates and colleagues is only processed where there is a basis that permits it, and always under the principle of the minimum necessary: you enter the data indispensable for the task and nothing more. Wherever possible, work with anonymized data or fictitious examples. Confidentiality agreements signed with customers apply inside an AI tool exactly as they do outside it.
7. Use of outputs. (a) No figure, quotation, regulation or statistic is presented as verified unless it has been checked against the original source. (b) Nothing is attributed to a person or organization that they did not say. (c) When a customer asks whether AI was used on a deliverable, the answer is the truth. (d) It is prohibited to use AI to impersonate anyone, generate deceptive content, monitor colleagues, or make automated decisions about people without human intervention.
8. Mandatory training. Before receiving access to a corporate AI account, the person completes [name of internal module, 90 minutes] and reads this policy, and signs the acknowledgment. Every six months there is a [45]-minute refresher session. Anyone who does not complete the training on time loses access until they do. The company covers the time spent, during working hours.
9. Questions and incident channel. For any question about this policy: [channel and owner]. There is no such thing as a stupid question, and asking never has negative consequences.
If you believe you have entered Level 4 information, that an output containing an error reached a customer, or that an account has been compromised, report it within the first 24 hours to [channel]. Reporting promptly and in good faith will not be penalized; concealing it will.
10. Consequences. Breaches are handled proportionately. A good-faith mistake reported in time is treated as an opportunity to improve and may involve additional training. Repeated breaches, use of personal accounts with confidential data despite a prior warning, or deliberately entering Level 4 information may lead to the disciplinary measures set out in [internal rules] and in applicable employment law.
11. Effective date and review. In force since [date]. Reviewed every [6] months and whenever the applicable law changes, a new tool is adopted or a significant incident occurs. Review owner: [role]. Version [1.0].
Eleven blocks, three pages. If it runs longer when you print it, something is surplus.
How do you classify information into four levels?
With a four-level matrix and concrete examples from the real business, not abstract categories. The proof that a matrix works is that anyone on the team can classify a new document in ten seconds without asking. If it needs interpretation, the matrix is badly written.
| Level | What it is | Examples | Rule with AI |
|---|---|---|---|
| 1. Public | Information already published or intended for publication | Catalog, list prices, website, press releases, spec sheets, trade-show material | Free use in approved tools |
| 2. Internal | Everyday use; its disclosure causes no serious harm | Procedures, templates, meeting minutes with no personal data, org chart, sales calendar | Free use in approved tools, with a corporate account |
| 3. Confidential | Its disclosure would cause commercial, legal or reputational harm | Customer lists, proposals and negotiated prices, margins, contracts, personal data of customers and employees, product plans | Approved tools with a corporate account only, and only if the task requires it. Minimum necessary and, where possible, anonymized |
| 4. Restricted | Sensitive data, credentials or information under heightened legal obligations | Health, biometric, ethnic origin, union or political affiliation data; passwords and API keys; information under a confidentiality agreement that expressly prohibits it; disciplinary files; data about minors | Never, in any AI tool |
Two details make the difference. First: use examples from your own company, with the names your team actually uses, not generic ones. A price list has a specific name in your shop, and that is how it should be written. Second: the higher-level rule when in doubt. If someone does not know whether a document is Level 2 or Level 3, it is Level 3. That one sentence prevents most incidents.
It is also worth naming explicitly the edge cases people ask about under their breath: a résumé you receive is Level 3; a vendor invoice is Level 3; the minutes of a meeting where someone's health was discussed are Level 4, even if the rest of the minutes are Level 2.
Which technical controls actually exist, according to the official documentation?
More than most companies turn on, and nearly all of them are described in the public documentation. A policy without technical controls is a statement of intent; controls without a policy are a configuration nobody remembers the reason for. You need both.
Taking Claude as the example, because its documentation is public and verifiable, this is what exists as consulted on 19 September 2026:
| Control | Where it lives | Why it matters |
|---|---|---|
| No training on your content by default | Team and Enterprise | It is the main reason not to work on consumer plans |
| Turn off chat rating ("Rate chats") | Organization settings, Team and Enterprise | Sending feedback stores the full conversation for up to 5 years; turning it off removes that path |
| SAML SSO and domain verification | Team and Enterprise | Okta, Entra ID, Google, OneLogin, JumpCloud or Duo; can be enforced |
| JIT or SCIM provisioning | Team and Enterprise | Deactivation in the directory cuts access the same day |
| Roles and permissions | Team and Enterprise; custom roles on Enterprise only | There is only one Primary Owner per organization: decide who, by name |
| Audit logs | Enterprise only | They cover the last 180 days; it is a rolling window, so export periodically |
| Custom retention | Enterprise only | By default data is retained indefinitely; the configurable minimum is 30 days |
| Central connector authorization | Team and Enterprise | Governs which internal systems the tool can reach |
| Provisioned and reviewed Skills | All plans; automatic review on Enterprise | Lets you distribute internal procedures instead of everyone improvising |
Two more facts worth knowing before you sign anything. The data processing addendum is accepted automatically when you accept the commercial terms, with no separate signature (DPA text). And on certifications, Anthropic states SOC 2 Type I and II, ISO/IEC 27001:2022 and ISO/IEC 42001:2023, plus a configuration ready for HIPAA under a specific agreement, with scope covering the commercial products and not the consumer ones (certifications · trust portal).
On data residency, it is best not to overpromise: the platform documentation indicates that today the storage region supports only us, and inference only us or global (data residency). If your contract with a customer requires another region, that has to be solved another way —and said so in the policy.
As for the cost of operating with controls in place: team plans start at 20 dollars per seat per month with annual billing, and self-serve Enterprise starts at 20 dollars per seat plus usage, with a 20-seat minimum, according to the official pricing page; that is as of September 2026, so confirm on their site, because prices change and vary by region.
How do you define human review without slowing the work down?
By setting the bar according to potential harm, not the prestige of the document. If everything requires review, nobody reviews anything: things get signed off in bulk and review becomes a formality. The practical approach is a three-level scale anyone can apply without asking.
- No review. Internal work and drafts: summarizing a meeting for yourself, organizing ideas, translating a public text, writing a formula. Here AI is just another tool and asking permission would be absurd.
- Self-review. Anything that leaves your area but stays inside the company: internal emails, process documentation, analysis for your manager. Whoever writes it reviews it, and is answerable for it.
- Second-pair-of-eyes review. Anything that goes outside or affects a person: quotes, published content, reports with figures, hiring or credit decisions. Here someone other than the person who generated it signs off.
One distinction that saves arguments: review is about facts, not style. Numbers against the source, quotes against the original, names against the file. Style gets fixed if there is time left over; facts always.
And one rule of thumb that works very well in small and midsize companies: the more you like the output, the more slowly you should review it. Text that reads well lowers the reader's guard, and expensive mistakes tend to arrive wrapped in an elegant paragraph.
What changes in Mexico under the 2025 LFPDPPP?
The law changed and so did the authority, and plenty of internal policies still cite both incorrectly. The Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP, the federal law on protection of personal data held by private parties) now in force was published in the Diario Oficial de la Federación —the official federal gazette— on 20 March 2025, with an amendment of 14 November 2025. INAI was dissolved and its functions in this area passed to the Secretaría Anticorrupción y Buen Gobierno (the ministry of anti-corruption and good governance).
What bears directly on an AI use policy:
- A mandatory privacy notice with the identity of the controller, the data processed, the purposes, options for limiting use and mechanisms for exercising rights (articles 14 to 16). If you are going to process personal data with AI tools, that purpose has to be covered.
- Sensitive data —health, racial or ethnic origin, beliefs, political opinions, sexual preference, genetic information— requires express consent in writing (article 8). That is why it goes straight to Level 4 in the classification matrix.
- ARCO rights (access, rectification, cancellation and objection) with 20 days to communicate the decision and 15 days more to act on it (article 31). Your policy has to say who answers and from where.
- Principles of lawfulness, consent, notice, quality, purpose, good faith, proportionality and accountability (article 5). Proportionality is the one that underpins the minimum-necessary rule.
- Penalties expressed in UMA units, in bands reaching hundreds of thousands of units, with the possibility of increases where sensitive data is involved (articles 58 to 60).
A practical five-minute check: open your current privacy notice. If it names INAI, if it does not cover processing using third-party vendor tools, or if it does not say who to contact to exercise rights, you already have three tasks.
And in Paraguay? Ley 7593/2025 and the clock running to November 2027
Paraguay went from having no general data protection law to having one, with two years to adapt. Ley N.º 7593/2025 de Protección de Datos Personales (the personal data protection law) was enacted on 27 November 2025 with a twenty-four-month vacatio legis: it will be fully enforceable from around 27 November 2027. It creates the national personal data protection agency, under MITIC.
The points worth reflecting in your internal policy right now:
- Lawful bases. All processing needs one: consent, performance of a contract, legal obligation, legitimate interest or the others provided for. The policy should say which one your company invokes for each routine use.
- Record of processing activities. The law rests on proactive accountability: you have to be able to show what you process, for what purpose and with whom it is shared. An inventory in a spreadsheet is a perfectly valid start.
- Security breaches within 72 hours. That deadline forces you to have an incident channel that genuinely works, and it is the reason section 9 of the template sets 24 hours internally: to make the external 72 in time.
- Impact assessment where processing presents significant risks, with prior consultation of the agency if a high risk cannot be mitigated.
- Data subject rights, including human review of automated decisions. If you use AI to screen candidates or assess credit, this point applies to you squarely.
- Penalties expressed in minimum daily wages, with caps that escalate where sensitive data is involved and further still where minors are.
Two years sounds like a lot of time and is not: the real work is the inventory, and inventories take a while. If your company processes Paraguayan customers' data in automated processes, the operational detail is in using AI with customer data in Paraguay under Ley 7593.
Want a hand applying this?
Free 30-minute working session. Uniamos is a remote AI automation agency (Austin and Mexico City) working over video calls and WhatsApp.
How do you communicate the policy without slowing adoption?
By presenting it as a permission, not a prohibition. The same policy can be communicated two ways and produce opposite results. "As of today, using AI is prohibited without authorization" kills adoption in a week. "As of today you have a corporate account, here is what you can do and what you cannot, and here is where you ask" multiplies it.
The script that works has four parts, in this order:
- What you get. Start with the corporate accounts, the available tools and concrete use cases for that team. People listen to the rules part far better once they know what they are receiving.
- The three rules to remember. Do not recite eleven sections in the meeting: give three sentences. "Use the company account." "Level 4 data never goes in." "Anything that goes to a customer gets reviewed by a person." The full document gets read afterwards.
- Where to ask. With a specific name and channel, and an explicit commitment that asking costs nothing.
- What happens if you get it wrong. Say it before anyone asks: a mistake reported in time is treated as learning. That one sentence determines whether you will hear about incidents or not.
Three supports worth more than the meeting itself: a one-page summary posted next to the data matrix; a chat channel where the team shares what works for them, because adoption spreads peer to peer and not from management down; and a thirty-day review to collect real questions and adjust. It helps a great deal to pair the policy with concrete examples by team, like those in use cases by team in small and midsize companies.
Training is the other half of the job. Anthropic publishes free courses at Claude Academy, such as the AI fluency fundamentals course with its framework of delegation, description, discernment and diligence; they are a good complement, though it is worth knowing they do not grant any official certification. The internal program, week by week, is laid out in the eight-week training program.
How often is it reviewed, and who is answerable for what?
Every six months at minimum, and whenever the law changes, a new tool comes in or an incident occurs. What turns a policy into actual governance is not the document: it is the calendar and the names.
| When | What gets done | Who |
|---|---|---|
| Monthly | Review account additions and removals, and confirm that directory deactivation cut off access | IT owner |
| Quarterly | Compare tools actually in use against the approved list; collect pending requests | Policy owner |
| Quarterly | Export the available audit logs, if the plan offers them | IT owner |
| Twice a year | Review the full text, the data matrix and the examples; publish a new version | Management + policy owner |
| Twice a year | Refresher session with the team and a new read acknowledgment | Training owner |
| On incident | Analyze the case, fix the rule that failed and communicate what changed | Policy owner |
Two warnings from the official documentation that affect this calendar. Audit logs cover 180 days on a rolling window: if you need longer traceability, you have to export before the period lapses. And default retention is indefinite unless a different period is configured, with a 30-day minimum, available on the Enterprise plan. Deciding retention is deciding how long an old project can keep showing up in an internal search.
To connect this with real adoption —who uses what, how much and with what result— use the scorecard in measuring the return on AI training.
Tricks that are not in the manual
Twelve tricks from watching policies work and fail. None of them costs money.
1. Write the data matrix before the policy
It is the part people actually consult. If you only have time for one thing, build the four-level matrix with examples from your own company and stick it up next to the coffee machine.
2. Use examples with the names your team uses
Not "sensitive commercial information", but "the margins-by-customer file". A matrix with real names gets applied; one with abstract categories gets interpreted, and it gets interpreted in favor of whoever is in a hurry.
3. Higher-level rule when in doubt
A single sentence —"if you are torn between two levels, it is the higher one"— prevents most incidents and saves the policy owner dozens of questions.
4. Turn off chat rating on day one
In the organization settings of a team plan, turning off "Rate chats" closes the path by which a full conversation could be stored for up to five years. It is one click and almost nobody makes it.
5. Name a single person as primary owner
There can only be one Primary Owner per organization. Decide who that is, write it in the policy and define what happens when that person goes on vacation or leaves the company.
6. Export the audit logs every quarter
They cover 180 days on a rolling window. Anyone who discovers they need a log from eight months ago also discovers it no longer exists.
7. Add the no-penalty reporting sentence —and honor it the first time
"Reporting promptly and in good faith will not be penalized." A policy lives or dies at the first incident: if the first person to raise their hand gets burned, there will not be a second.
8. Prohibit Level 4 with no urgency exceptions
Every "just this once, the customer needs it by tomorrow" exception becomes a precedent. An absolute prohibition is easier to hold than a nuanced one.
9. Make the policy fit in three pages plus one single-sided page
The long version for whoever needs it; the one-pager for everyone else. If your team cannot recite the three main rules, you do not have a policy: you have a file.
10. Load the policy into the tool itself as a knowledge base
Putting it in a shared project lets anyone ask "can I paste this?" and get the answer from the policy itself. How to build that base is in Projects as your company's brain.
11. Version and date every revision
"Version 1.3, in force since 4 March 2027." Without a version you do not know what each person signed, and the read acknowledgment loses all its value.
12. Review the policy the day a new tool comes in
Not at the next half-year mark. The approved tools list is the section that ages fastest, and an out-of-date list is the best excuse for ignoring it.
What should you do this week?
Five days. At the end you will have a policy in force, communicated and signed, which is more than most companies your size have.
- Monday — The matrix. Get one person from each team together for an hour and classify twenty real documents into the four levels. The disagreements that come up are exactly the content of your matrix.
- Tuesday — The template. Copy the eleven blocks, replace the brackets and delete everything that does not apply to your company. Make it fit in three pages.
- Wednesday — The controls. Check the actual configuration: who the primary owner is, whether access comes through the corporate directory, whether chat rating is turned off and which connectors are authorized.
- Thursday — The legal review. Send the draft to whoever handles employment and data protection at your company. Have them confirm sections 6 and 10 and the personal data parts.
- Friday — The rollout. Thirty minutes with the team, using the four-part script. Hand out the one-pager, open the questions channel and collect the acknowledgments.
Thirty days later, half an hour to collect real questions and adjust. If you would rather do it with support and train the team at the same time, AI training with Claude is that option; and for the full phased rollout, see the implementation plan.
Frequently asked questions
How long should an internal AI use policy be?
Three pages, plus a one-page appendix with the data classification matrix. Long policies get signed without being read and protect you from nothing, because their value is not in the document but in the team remembering the three or four rules that genuinely matter: use the corporate account, never enter restricted-level data, and have a person review anything that goes outside. If you need more length, put the detail in separate appendices and keep the body short.
Do I have to ban the AI tools my team is already using on their own?
Banning without offering an alternative moves the usage to personal phones and leaves you with no visibility, which is the worst of both worlds. The order that works is the reverse: first you give corporate accounts on an approved tool, then you explain why a personal account is not suitable for company data, and only then do you close the door. If there is a tool the team uses heavily and it works, evaluate it seriously before ruling it out: it probably solves a real problem.
What data should never go into an AI tool?
Anything at the restricted level of the matrix: sensitive data such as health, biometrics, ethnic origin, union or political affiliation and sexual orientation; passwords and API keys; information covered by a confidentiality agreement that expressly prohibits it; disciplinary files and data about minors. In Mexico, sensitive data requires express consent in writing under article 8 of the LFPDPPP, and penalties can be increased where such data is involved, which on its own justifies the absolute prohibition.
Is a free or personal plan good enough for working with customer data?
No, and the reason is not features but the default data policy. Anthropic states that for its commercial products it does not by default use inputs or outputs to train models, while on consumer plans that depends on a setting each user controls. On top of that, the administrative controls —single sign-on, directory provisioning, audit logs, configurable retention— exist only on the team and enterprise plans. A personal account leaves no trail you can audit.
What happens if someone pastes confidential information by mistake?
They have to report it within the first 24 hours through the channel the policy specifies, and the policy has to state in writing that reporting promptly and in good faith carries no penalty. That internal deadline is not arbitrary: in Paraguay, Ley 7593/2025 sets a maximum of 72 hours to notify security breaches, and to make that you have to find out sooner. From the report onward you assess the scope, fix the rule that failed and tell the team what changed.
Who should own the policy?
Someone with the authority to decide and the time to field questions, which in a small or midsize company is usually the head of operations or of administration, not necessarily IT. What matters is that it is a named person, not a committee, and that there is a defined backup. Inside the tool, it is worth aligning that role with the organization's primary owner, which is also a single role per organization according to the roles and permissions documentation.
How often does the policy need to be reviewed?
Every six months at minimum, and whenever the applicable law changes, a new tool comes in or a significant incident occurs. The section that ages fastest is the approved tools list, so it is worth reviewing it the same day you buy something new rather than waiting for the cycle. Version and date every revision: without a version you do not know which text each person signed.
Can I use the policy to answer a customer or a tender?
Yes, and it is asked for more and more. A customer who asks how you govern AI use usually wants four things: the written, dated policy; the data classification matrix; the list of approved tools with the plan you pay for; and evidence that the team has been trained. It also helps to have the vendor's public documentation on certifications and data handling to hand, so you are not answering from memory.
Do I need a lawyer to review the policy?
Yes, at least the confidentiality, consequences and personal data processing sections, because they have employment and regulatory effects. This article is educational material and does not replace that review. The good news is that arriving at the lawyer's office with a complete draft turns a long consulting engagement into a short review, which costs considerably less.
Related articles
- How to roll out Claude in your company, phase by phase
- An eight-week AI training program for teams
- Projects: your company's knowledge base
- Measuring AI adoption and return in your company
- Using AI with customer data in Paraguay: Ley 7593
- AI use cases by team in small and midsize companies
- B2B lead generation with AI in Mexico and Paraguay
- More from the blog