October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

How to Set Team Guidelines for Using AI at Work

A practical approach to workplace AI rules: inventory uses, define approved tools and data boundaries, verify outputs, protect affected people, and assign owners for training and review.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set AI-at-work guidelines by documenting which tools and tasks are approved, what information employees may enter, how outputs must be checked, and who is accountable for decisions. Start with an inventory of actual uses, apply stronger review to uses that can affect people, and assign owners to train staff, handle reports, and keep the rules current.

Start with a use-case inventory

Before writing rules, find out what AI systems employees already use or want to use. Record the tool, the task, the information entered, and who may rely on the result. Include both organization-approved systems and unapproved or informal use disclosed by teams.

As an Amazon Associate I earn from qualifying purchases.

Distinguish low-impact assistance, such as brainstorming or drafting internal text, from uses that affect customers, employees, candidates, or other people. The same tool may present different risks depending on the task, the data, and how much weight people give its output.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Organize the policy around risk

NIST’s voluntary AI Risk Management Framework (AI RMF) offers a useful structure: Govern, Map, Measure, and Manage. Its Playbook provides suggestions for applying those functions, but it is not a mandatory checklist; NIST says it is “neither a checklist nor set of steps to be followed in its entirety.” Select controls that fit the team’s context and the proposed use.

Assess each use against relevant dimensions, rather than treating “AI” as one uniform risk. NIST identifies validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy, and fairness with harmful bias managed. These qualities may involve tradeoffs, and their importance depends on the context.

  • Govern: Assign decision-makers, approvers, operators, and oversight responsibilities.
  • Map: Describe the task, users, affected people, data, and likely consequences.
  • Measure: Decide how to test quality and identify relevant privacy, security, fairness, or safety concerns.
  • Manage: Set controls, monitor results, respond to problems, and revise or stop the use when needed.

NIST released AI RMF 1.0 on January 26, 2023, and says it is being revised. Its Generative AI Profile was released July 26, 2024. Check NIST’s AI Risk Management Framework page and AI RMF Playbook for current material when creating or refreshing internal rules.

Define approved tools and tasks

Maintain an internal list that identifies approved systems and the tasks they may be used for. Approval should be tied to a specific use, not treated as blanket permission to use a tool for any purpose. Establish a route for requesting review of a new system or a higher-risk task; the appropriate reviewers and level of scrutiny will depend on the organization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When comparing tools or proposed uses, consider the following together:

  • Suitability for the task and the quality of results.
  • What information the service collects, retains, or uses, and what configuration and terms apply.
  • Security controls, access management, and the ability to audit activity.
  • Whether outputs can be verified and, where needed, explained.
  • Potential effects on workers, customers, and other affected people.
  • Whether a human can review, override, or stop the system’s output from being used.
  • Applicable obligations for the organization’s jurisdiction and sector.
  • Cost and operational burden.

There is no universal scoring formula for these factors. Set a documented review method proportionate to the use and its consequences.

Set rules for information employees enter

Have the appropriate security, privacy, and legal owners determine what information may be entered into each approved system, taking account of its actual configuration and terms. Address confidential business information, personal information, regulated data, client material, and unreleased information as relevant to the organization. Avoid a policy that assumes every tool handles data in the same way.

Make the rule easy to follow: staff should know where to find the approved-use list, which data categories are restricted for each system, and whom to contact when a task involves information not covered by the policy. Privacy and security are recognized risk dimensions, but the exact categories and permitted handling depend on the organization, tool, and applicable requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Require verification and name the accountable person

AI output should not become final work merely because it looks confident or polished. Specify checks appropriate to the task: verify factual claims against reliable sources, recalculate important figures, test code, inspect citations, and review customer-facing text before it is sent. A team may need different checks for a brainstorming draft than for material used in a consequential decision.

Name the person or role responsible for accepting the final work, and define when a qualified human must make or review a decision. NIST’s Playbook recommends explicit human roles and responsibilities, risk tracking, proficiency standards, risk-management training, oversight procedures, and transparency policies. Build those into workflows rather than relying on a general instruction to “use judgment.”

Apply extra scrutiny when people may be affected

Employment-related uses, worker monitoring, candidate evaluation, and other consequential decisions deserve careful review before deployment and while in use. Consider privacy, discrimination and fairness, labour rights, job quality, transparency, explainability, and accountability. OECD’s workplace analysis identifies these as important concerns; its guidance does not replace applicable law.

Rules differ by jurisdiction, sector, data type, and use. Have qualified local advisers assess the relevant requirements where necessary, especially before using AI in employment decisions or monitoring. This article offers general organizational guidance, not a legal determination for a particular workplace.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Train staff and provide a reporting route

Training should cover the approved tools and tasks, information-handling rules, output checks, and the human responsibilities attached to each workflow. Tell employees how to raise a question before using AI in an unlisted way and where to report an inaccurate output, data exposure, suspected misuse, or other incident.

Assign someone to receive and route reports, and define who evaluates them and what action may follow. Clear reporting and oversight procedures help the organization identify recurring problems and decide whether a use needs tighter controls, a pause, or a policy change.

Assign an owner and review triggers

Give a named role or team responsibility for maintaining the guidelines, the approved-use list, and associated training. Set review triggers so the policy is revisited when a tool or vendor data practice changes, a new use case is proposed, a material incident occurs, or relevant law or guidance changes.

NIST describes the AI RMF as a living framework. Because its materials evolve and the framework is being revised, check official NIST guidance during policy reviews rather than assuming an older internal document remains current. The OECD’s Employment Outlook 2023, Chapter 6 also discusses workplace impacts and trustworthy AI, including respect for the rule of law, human rights, and democratic values throughout the AI system lifecycle.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.