Your Staff Already Use ChatGPT: Write the Policy Now

·6 min read·Ervandra Halim

Key answer

Yes, write a company AI usage policy now: your staff are already using ChatGPT and similar tools whether or not you have rules, and banning them only pushes usage underground where you lose visibility. Ervandra Halim's fix, used with Indonesian SME clients, is a single page with three buckets: what is allowed without asking, what is forbidden with no exceptions, and a gray area that requires asking a named manager first. Add quarterly review and the policy stays current.

  • Banning AI tools at work does not stop usage, it pushes it to personal phones and private accounts where the company has zero visibility.
  • A workable AI policy fits on one page with three buckets: allowed without asking, forbidden with no exceptions, and gray-area cases that require asking a named manager first.
  • The policy needs a quarterly review, since the tools change fast enough that a policy written today looks dated by year end.

Right now, someone on your team is pasting a customer contract into ChatGPT to summarize it. Someone else is asking it to rewrite a sales email that contains your pricing structure. They are not being reckless. They are being productive, and the tool is genuinely useful. The problem is that you do not have a company ai usage policy, so nobody knows where the line is.

I have watched this play out inside several Indonesian SMEs over the past few months. The instinct from management is usually to ban the tools outright. That is the worst option. A ban does not stop usage, it just moves it to personal phones and private accounts where you have zero visibility. The Samsung engineers who leaked internal source code into ChatGPT earlier this year did not do it because there was no ban. They did it because the tool solved their immediate problem faster than any internal process.

So the real job is not prevention. It is drawing a clear, boring, one-page line that people can actually follow. Let me give you the skeleton I hand to clients.

Why does banning AI tools backfire?

Banning AI tools backfires because a prohibition does not stop the behavior, it only hides it. When you forbid a useful tool, three things happen: usage goes underground and you lose the ability to guide it, your best people, the ones who experiment, feel treated like children, and you fall behind competitors learning to use the same tools well.

A company ai usage policy is not about control for its own sake. It is about making the safe path the easy path. If staff know exactly what is fine and what is forbidden, they stop guessing, and guessing is where leaks happen.

The framing I use with owners is simple. You are not policing intelligence, you are protecting data. Those are different jobs. Nobody argues that a warehouse should have no rules about what leaves the building. An AI policy is the same idea applied to information.

You are not policing intelligence, you are protecting data.

Ervandra Halim, advisor on AI adoption for SMEs

What should a one-page AI policy include?

A one-page AI policy should include three buckets: what is allowed without asking, what is forbidden with no exceptions, and gray-area cases that need a quick check first. You do not need a legal document, you need one page that a new hire can read in three minutes.

Allowed without asking. These are low-risk, high-value uses. Drafting and editing general text. Brainstorming ideas. Summarizing public documents. Writing code that touches no proprietary logic. Explaining concepts. Translating marketing copy. Anything where the input contains no confidential data and the output gets reviewed by a human before it ships.

Forbidden, no exceptions. This is the bucket that prevents the Samsung situation. Never paste in the following:

  • Customer personal data (names, ID numbers, phone numbers, addresses)
  • Financial records, pricing sheets, or internal margins
  • Source code from private repositories
  • Contracts, legal documents, or anything under an NDA
  • Employee records and payroll
  • Passwords, API keys, or access credentials

Gray area, ask first. Some cases sit between the two. A marketing draft that mentions an unreleased product. A process document that reveals how your operations work. For these, the rule is one sentence: when in doubt, ask your manager before pasting. Name a specific person who owns the decision, so "ask first" does not become "ask nobody."

Make the safe path the easy path

A policy on paper changes nothing. What changes behavior is giving people a sanctioned way to do the thing they want to do.

If your team needs to summarize customer contracts, that is a signal, not a violation. It means there is real value there. The right response is to find a tool with proper data handling, or to teach people how to anonymize the input first. Strip the names, replace the numbers with placeholders, then paste. The AI still does its job and nothing sensitive leaves the building.

This is also where a little training pays off fast. A thirty-minute session showing your team how to get better results, and how to spot when they are about to paste something they should not, does more than any signed document. People follow rules they understand and ignore rules that feel arbitrary.

The same discipline that protects your data also builds your capability. Treating information carefully is the foundation of using it well, which is exactly the mindset behind Your Business Data Is an Asset. Start Collecting It Now.

How often should you review the AI policy?

The AI policy should be reviewed once a quarter for most SMEs, since the tools themselves change every month and a policy written today will look dated by year end. Build in a recurring review and ask three questions each time:

  1. What new tools has the team started using since last quarter?
  2. Has anyone hit a gray-area case we should now make explicit?
  3. Are there approved tools that handle data safely enough to move a forbidden use into the allowed bucket?

Keep the policy in a place people actually see it, not buried in a shared drive nobody opens. Pin it in your team chat. Make it part of onboarding. Review it out loud in a meeting once in a while so it stays alive.

If you want the AI to genuinely help your business rather than just individual staff, the next step is giving it your own information to work from safely, which I cover in RAG Explained: AI That Actually Knows Your Business.

The practical takeaway

Your staff are already using these tools. That decision has been made for you. The only open question is whether they do it inside a clear boundary or in the dark.

Write the one page this week. Three buckets: allowed, forbidden, ask first. Name the person who owns the gray-area calls. Do a thirty-minute training so people understand the why. Review it every quarter. That is a company ai usage policy that actually protects you, and it took an afternoon, not a law firm.

If you would rather have someone map your data risks and set this up alongside your broader tech decisions, that is the kind of work I take on with selected partners. Start with the one page regardless. Underground usage is the risk you cannot see, and it is already happening.

ai policygovernancechatgpt at workdata protectionhr

Frequently asked questions

What should happen when staff genuinely need to process sensitive data, like summarizing a customer contract?

Treat that need as a signal, not a violation: it means there is real value in the request. The right response is finding a tool with proper data handling, or teaching staff to anonymize the input first, stripping names and replacing numbers with placeholders before pasting. The AI still gets to help and nothing sensitive leaves the building.

Would banning ChatGPT outright have prevented the Samsung source-code leak?

Not on its own. Those Samsung engineers pasted code into ChatGPT because it solved their problem faster than any internal process, not because a ban was missing. A rule cannot outcompete a tool that is genuinely faster, so the real fix is a sanctioned way to get the same speed safely, which is the logic behind allowing low-risk uses instead of blocking every use case.

Who should decide gray-area cases that fall between allowed and forbidden uses?

One named person should own that decision, not a vague 'ask first' instruction. The policy should specify a manager by name so gray-area questions, like a marketing draft mentioning an unreleased product, get answered instead of falling through the cracks of 'ask nobody.'

Does writing the policy replace training staff on how to use AI tools?

No, the two work together. A signed one-page policy changes little on its own; a thirty-minute session showing staff how to get better results and how to spot risky pastes does more than the document alone, because people follow rules they understand and ignore ones that feel arbitrary.

Ervandra Halim

Ervandra Halim

CPTO & Principal Architect

Ervandra Halim helps owners and leaders modernize operations and put AI to work daily. He partners with a few businesses at a time, mostly by referral.

Keep reading

AI & Automation

When Not to Use AI: A Framework for Saying No

Knowing when not to use AI in business saves more money than adopting it. Four situations where AI adds risk, cost, or liability instead of leverage.

·5 min read

© 2011–2026 Ervandra Halim