As AI tools spread through an organization, the privacy questions arrive quickly. Where is our data going? What happens to the information employees type into these tools? Are we exposing anything we shouldn't? These are reasonable questions, and the good news is that answering them doesn't require a legal department — it requires documenting a few decisions clearly.
Here's the short list of things worth writing down.
1. What data is off-limits
Be explicit about the categories of information that should never go into AI tools without specific approval: personal data about customers or employees, confidential business information, anything covered by privacy regulation or contractual obligation. A clear, named list is far more useful than a vague instruction to "be careful."
2. Which tools are approved
Maintain a short list of AI tools that are approved for work, and note what each is approved for. This prevents the common situation where sensitive information ends up in a free consumer tool simply because no one said which tools to use.
3. Where data goes
For each approved tool, document — at a basic level — what happens to the data entered into it. Does the provider use it for training? Is it retained, and for how long? You don't need deep technical detail, but you should be able to answer these questions for the tools your people rely on.
4. When consent or disclosure is needed
Some uses of AI touch other people — customers, students, job applicants. Document when you need to disclose that AI is being used, and when consent is required. This is both a legal consideration and a matter of trust.
5. Who is accountable
Name the person or role responsible for keeping these decisions current and answering questions as they come up. Privacy practices that have no owner tend to drift out of date the moment tools change — which they do, frequently.
Keep it readable
The point of documenting these decisions isn't to produce a binder. It's to give your people clear, quick answers to the questions they're already asking. The most effective AI privacy guidance is short, specific, and written in plain language.
A foundation, not a finish line
Privacy and policy work is never truly finished, because the tools keep evolving. But documenting these five areas gives you a foundation you can build on — and the confidence to adopt AI without quietly accumulating risk. It's a small effort that pays off every time someone wonders, "wait, are we allowed to do that?"
Reviewing these decisions on a regular cadence keeps them useful. Treat them as living guidance, and revisit them whenever you add a significant new tool.