Company Rules and Why They Exist
A one-page document appears in everyone's inbox at Waymark, titled "Using AI tools at work". The office splits within the hour. Half the staff say "finally, someone wrote it down". The other half say management is banning the one thing that has made the season survivable.
Tessa reads it and finds neither. What she finds is the previous two pages, written down by someone who had the same thoughts a month earlier: a short list of approved tools, a shorter list of things that never go into them, and the name of a person to ask when a task falls outside both. This page is about why that document exists, how to work with one, and what to do when it says no to something genuinely useful.
What Is a Policy Actually Protecting?
Three things, and none of them is the IT department's dignity.
Client trust and legal duty come first. A travel agency holds material its guests handed over for one purpose, and privacy law in most places reaches data about identifiable people wherever it ends up — including pasted into a chat box by a well-meaning employee at half past four. The obligation follows the data, not the tool.
Commercial secrets come second: the supplier terms that took two years to negotiate, the pricing model, the partnership nobody has announced yet. These are not dramatic secrets. They are the ordinary material that makes one company different from its competitors, and their value is entirely in who has them.
The third one gets left out of the conversation, which is a shame, because it is the one that benefits Tessa directly. A policy protects the employee. "I followed the policy" is a sentence with an institution standing behind it. "I judged it was fine" is a sentence with one person standing behind it, alone, explaining a decision made under deadline six weeks ago. Written rules are how an organization takes that weight off individuals — which is the opposite of how a policy usually feels when it lands in your inbox.
What Is Actually on the Page
Policies about AI tools are usually short, and the short version is usually these three parts.
Approved tools. A list of which products may be used for work, and on which accounts. That list is not arbitrary: someone asked the three questions from earlier in this chapter on the company's behalf, read the answers, and checked which plan Waymark is actually on. Using an unlisted tool is not naughtiness — it is asking nobody's favourite question, "what happens to our text in there?", and hoping.
Categories that never go in. The previous page's list, made official: credentials, personal data, confidential material. The difference between the two versions matters. Tessa's version is a habit she maintains. Waymark's version is a decision the company made once, so that forty people do not each have to make it forty times a day at varying levels of tiredness.
Somewhere to ask. A named person or an address for the cases the list does not cover, which is most of the interesting ones. A policy without this third part is where the trouble starts: it can only ever say no, so people stop reading it.
When a Rule Feels Too Strict
Sooner or later a rule blocks something that would obviously help. That is a conversation, not an obstacle to be routed around, and the ask-first channel exists precisely for it: here is the task, here is what I would send, here is the redacted version — may I?
Which brings up the move this page is really about. The quiet workaround: doing the task on a personal account, or on a phone, or on the home laptop at the weekend, and saying nothing. It feels like a small act of sensible pragmatism, and it is the thing AI policies ban most explicitly, for reasons worth spelling out.
The data still travelled. Nothing was avoided except the protections. It went to a tool nobody vetted, on the weakest tier of promises — a free personal account, with the retention and training answers that come with one — and no record exists that it went anywhere at all, so if something surfaces later, nobody can even establish what was sent. And because the work happened outside the sanctioned route, the person who did it now owns it personally. The workaround transfers the whole risk from the organization onto the employee, which is exactly backwards from what it feels like at the time.
Professional kitchens run on food-safety rules that cooks find tedious: label everything, log the fridge temperature, throw out what is past its time even when it smells perfectly fine. They are occasionally annoying and always cheaper than one outbreak. And when an inspector does turn up, the cook who can say "I followed the procedure, here is the log" is the protected one. The cook who improvised is not.
What If There Is No Policy?
Most workplaces have not written one yet. Silence is not permission, and it is not prohibition either — it means nobody has done the thinking, so the thinking falls to whoever is at the keyboard.
In that gap, the previous two pages are the interim standard. Ask the three questions about the tool you are using. Keep the three categories out of it. Redact before you paste. That is a defensible position, and it is very close to what the official policy will say when it eventually arrives.
And there is an opportunity sitting in the gap, which Tessa takes. She offers to help draft the real one — not as an enthusiast for rules, but as the person in the building who has actually thought about where the text goes, with her redaction habit as Exhibit A. It is a small, unglamorous piece of work. It also puts a marketing coordinator in the room where a decision about the company's tools gets made, which is not nothing, and it is a conversation coming to every workplace this decade.
- "A policy is just IT covering itself." It is the organization making the previous page's judgement calls once, in daylight, so that no individual has to improvise them under deadline — and so that nobody stands alone afterwards explaining what they decided.
- "Using my personal account sidesteps the policy." It sidesteps the protections, not the exposure. The material still travelled, now to an unvetted tool with no record that it went — and the risk lands on the person who did it.
- "No policy means anything goes." No policy means nobody has done the thinking yet. Until they do, this chapter's defaults are the standard, and offering to help write the real version is a genuinely good move.
- "Policies age out, so there is no point learning one." The tool list ages, and should be revisited. The categories underneath it — credentials, personal data, confidential material — have not moved in decades and are not about to.
- The AI-policy conversation is arriving at every workplace this decade. Arriving as the person who understands why each line exists puts you on the writing side of it rather than the complaining side.
- Ask-first culture is what lets an organization say yes safely. The alternative to it is not freedom — it is a blanket ban issued the week after the first incident.
Knowledge Check
Which protection does this page say usually gets left out of the conversation about AI policies?
- That it protects the employee who followed it
- That it protects client data and legal duty
- That it protects the company's commercial secrets
- That it protects the budget from tool spending
What three parts does a typical short AI policy contain, according to this page?
- Approved prompting techniques, a house style guide, and a list of good tasks
- Approved tools, the categories that never go in, and somewhere to ask about the rest
- A budget for each team, a monitoring system, and a quarterly report on how much AI was used
- A ranking of the AI products, their prices, and a recommendation on which to buy
The policy blocks a task that would clearly save Tessa a day. She does it on her personal account instead. What actually happened?
- Nothing improper — the policy governs company accounts, and this was her own account
- The company's exposure was reduced, since the material never touched a work system
- The protections were skipped, not the exposure — and the risk moved onto her
- She raised the question implicitly, and the company can review the decision later
Waymark has no written AI policy at all. What does this page recommend?
- Treat the absence as permission, since no rule has been broken until one exists
- Avoid AI tools entirely for work material until management publishes something official
- Adopt another company's published policy word for word and treat it as Waymark's own
- Apply this chapter's defaults as the interim standard, and offer to help write the real one
You got correct