Addaly is in open beta. Things will change, and AI answers can be wrong — check anything that matters.

AI at Work

The tasks it genuinely helps with, the ones it quietly ruins, and the line you must never cross.

Lesson 55 of 739 min

When your workplace has no policy

The most common situation in the world

Most organisations do not have an AI policy. Many that do have one sentence in a staff handbook, written quickly, meaning "be careful". Meanwhile a large share of staff are already using these tools, most of them on personal accounts, and few of them have told anyone.

If that is your workplace, the useful response is not to wait and not to hide. It is to make the informal thing explicit — and you can do that from any position, including a junior one.

Step one: ask in writing

One email. Two sentences.

I would find an AI assistant useful for drafting routine correspondence and summarising documents. Is there an approved tool, and are there restrictions I should know about?

This is a small act with disproportionate effect. If there is an approved tool, you now have it. If there is not, you have told the person whose job it is that a decision is needed, and you have a record of having asked. Every organisation that later has an incident divides its staff into those who asked and those who did not, and those are two very different conversations.

The reply may be nothing at all. Silence is not permission, but it is information: it tells you the organisation has no view, which means the duties fall on you personally and you should behave accordingly.

Step two: write the one page yourself

Do not wait for a committee. A page that fits on a page, in plain language, that a new colleague could follow on their first day. It should say five things.

1. Which tools are approved, and for what. Naming one approved tool solves more than any amount of principle, because most misuse is people improvising in the absence of an option.

2. What must never be entered. The specific list for your organisation, not a generic one: client files, patient identifiers, staff records, unpublished financials, credentials, anything under an NDA. Six concrete lines beat a paragraph about "sensitive information".

3. What must always be checked before it leaves. Numbers, names, dates, citations, quotations, legal thresholds. The pass from earlier in this course, written down.

4. Where a human must decide. Anything about a person — hiring, discipline, grading, benefits — and anything with legal or safety consequence.

5. Who to tell when something goes wrong, and that telling early is safe. This is the line that determines whether the policy works. If the honest report of a mistake is punished, you will not hear about the next one until a client does.

Then add the sentence that keeps it alive: This page will be reviewed on [date]. An unreviewed policy about a moving subject becomes wrong quietly.

What good looks like in practice

  • One approved tool, provided quickly. The gap between what people need and what they have is precisely the size of your shadow-AI problem. Nothing closes it faster than a licence and a login.
  • Training that is task-based, not fear-based. Show the two things that work and the two that go wrong. Fear-based training produces concealment, and concealment produces the incident.
  • A place to share what worked. A shared document of good prompts is a cheap, high-return artefact and it makes the whole team's floor higher.
  • A named person. Not a committee. Someone to ask.
  • A short register of what is being used for what. Three columns and twenty rows. When a regulator, auditor or insurer asks — and they now do — this document is the answer, and it cannot be reconstructed after the fact.

If you are junior and nobody is listening

Write the page anyway and follow it yourself. Keep your own record: tool, task, what you checked. Use the approved tool if one exists, a local model if the material is confidential and nothing is approved, and nothing at all if neither is available.

You may not be able to make your organisation careful. You can be individually defensible, and when the policy is eventually written, the person who has been keeping a sensible record for six months is usually the person asked to write it.

The one thing to keep

In the absence of a policy the safe default is not abstinence but a written question and a one-page rule you propose yourself, because unwritten practice is what an incident is judged against.

Before you move on

An office has no AI policy. Two staff use a chatbot daily for client correspondence and say nothing, believing that no policy means no restriction. Where is the reasoning wrong?

Pick the one you would defend. Nobody sees your answer.

No ads. No data sale. No public scores on people. Ever.

© 2026 Addaly