Rules for using AI at work, written so people follow them.
People in your business are already using AI. This kit is the rules, plus the working documents that make rules stick: a data classification, an approved tools register, an eight-section policy you can adopt with about ten edits, a register of the decisions AI touches, a 30-day rollout and a self-score.
Free. A PDF of 24 pages (Canada edition) or 22 pages (International edition), Canada being Ontario first, plus a Word file with the policy and the two registers for editing.
Who it is for
The person who ends up owning this.
Owners, managing partners, operations and office leads at firms of 5 to 200 people, without a compliance department to hand it to. Anyone who has been asked "can we use this?" and wants a better answer than "probably". Professional services, agencies, accounting and law firms, and operations teams inside larger companies.
What's inside
Ten sections, in the order you use them.
- 01 Why a two-page policy is not enough The three things you are actually governing: tools, company data and decisions.
- 02 What applies to you Canada edition: what the published rules say as of the print date, each line dated and sourced. International edition: the questions to put to your adviser.
- 03 The AI data classification Green, amber and red, ten worked examples, and one rule per tier for each class of tool.
- 04 The approved tools register Three tool classes, six questions to ask any vendor, and the register to record the answers.
- 05 The AI use policy Eight sections, editable, written so a 40-person firm can adopt it with about ten edits.
- 06 Decisions that need a human Ten decisions where AI may draft and suggest, and a named person decides.
- 07 The AI decision register One row per tool per decision it touches, so "was AI involved, and who decided?" has an answer.
- 08 The 30-day rollout Find out what is happening, classify, approve three tools, publish, train in 45 minutes, review on day 30.
- 09 Self-score Twelve yes or no questions and three bands, each with a next step.
- 10 Sources and dates Every source the kit relies on, with the date it was checked.
What this is not
Not legal advice, not a guarantee.
It tells you what the published rules say and when we checked them, so you can ask the right questions of the right people. It does not replace a lawyer's view of your situation, and adopting it certifies nothing. Where a product is named, it's because staff already use it, not because we're suggesting it.
From the kit
Two sections of the kit, published in full so this page is useful before you download anything.
The AI data classification
This is the page people will use most. It sorts the information in your firm into three tiers and gives one rule per tier for each class of tool. Once staff know the tier, they know the rule.
The idea behind it comes from Canada's privacy commissioners' joint principles on generative AI: enter personal information into a prompt only where authorised, and use de-identified information instead wherever you can. We've extended that to confidential business information, because the same leak happens either way.
The three tiers
Green: public or harmless. Information that is already public, or that would cause no harm to anyone if it appeared on the internet tomorrow with your name on it. Published marketing copy, your website text, public product descriptions, general how-to questions, generic drafting ("write a polite reminder about an overdue invoice" with no names or amounts).
Amber: internal or client-confidential, but not personal or regulated. Information you would not publish but that identifies no individual and carries no legal or contractual duty beyond ordinary confidentiality. Internal process documents, draft proposals with the client's name removed, pricing models, project plans, code you own, meeting notes with people's names taken out.
Red: personal, regulated, or under a duty you can't delegate. Anything that identifies a person combined with something about them. Anything covered by a privacy law, a professional duty, a court order, or a non-disclosure agreement. Government identifiers. Health, financial and legal details about a person. Credentials and keys. Anything you'd have to report if it leaked.
When you're not sure, treat it as one tier higher. Red beats amber; amber beats green.
Worked examples
Scroll sideways to see the whole table
| Information | Tier | Why |
|---|---|---|
| A client's file: correspondence, their situation, their instructions | Red | Identifies a person and their affairs; owed a duty of confidentiality; in Canada, personal information handled in commercial activity |
| A Social Insurance Number, passport number or any national ID | Red | A government identifier. There is no business reason to put one into an AI tool, at any tier |
| Employee performance notes, a warning letter, an interview scorecard | Red | Personal information about a named employee, and it feeds a decision with legal effect |
| Your pricing model, margins, rate card | Amber | Commercially sensitive but identifies no person. Business or enterprise tier only |
| A contract under NDA, or a draft agreement with the counterparty named | Red | The NDA usually forbids disclosure to any third party; a tool provider is a third party. Ask before you summarise it anywhere |
| The same contract with names, amounts and identifying terms removed, for a clause-wording question | Amber | De-identified. The question is now about drafting, not about the deal |
| Public marketing copy, blog drafts, your services page | Green | Meant for the world. Any tool is fine |
| An email from a customer complaining about a delay | Red as received; Amber once the name, account and any identifiers are removed | The complaint is personal information. The wording problem isn't |
| A spreadsheet of monthly sales totals by region | Amber | Internal numbers, no individuals |
| The same spreadsheet with a customer name per row | Red | Now it's a list of people and what they bought |
The rule per tier per tool class
Tool classes are defined in the kit. In short: consumer means a free or personal account; business means a paid plan where the provider commits not to train on your data; enterprise means a signed agreement with your firm's name on it, admin controls, and a data-processing agreement.
Scroll sideways to see the whole table
| Tier | Consumer account | Business tier | Enterprise tier |
|---|---|---|---|
| Green | Allowed | Allowed | Allowed |
| Amber | Not allowed | Allowed, on an approved tool from the register | Allowed |
| Red | Never | Not allowed, except de-identified first (see below) | Allowed only for the specific uses the owner has approved and logged in the decision register, and only where your contract with the client or your privacy obligations permit it |
Two lines to remember:
Red never goes into a consumer account. Not once, not "just to check the grammar".
Amber goes only into approved tools. If a tool isn't in the register, it's a consumer account for the purpose of this table, whatever it costs.
De-identifying, so more work can happen at amber
Most red information becomes amber when you remove what identifies the person or the deal. Names, initials that are unique in context, addresses, phone numbers, email addresses, account and file numbers, dates of birth, government identifiers, exact amounts where the amount itself is identifying, and the counterparty in a contract. Replace them with placeholders: Client A, [address], [amount]. Put the real details back into the output afterwards, by hand.
This is not a loophole. It is the recommended way to get value from AI on real work without moving personal information out of your control. Train people on it in the 45-minute session (in the kit); it's the single most useful skill in the kit.
What the classification doesn't cover
It doesn't cover output. An AI tool's answer can be wrong, biased or invented, whatever tier the input was. The review rules in the policy and the decision table (both in the kit) handle that.
From the kit
Decisions that need a human
AI can do three things with a decision: draft the material around it, suggest an answer, or make it. The first two are useful almost everywhere. The third is where the risk lives, because a decision made by a tool has no one who can explain it, and in some cases (hiring, automated decisions with significant effect) the law or a regulator expects a person to be able to.
The rule in the policy is simple: for the decisions in this table, AI may draft and may suggest, and a named person decides. "Decides" means they could give the reasons in their own words if asked, without pointing at the tool.
Scroll sideways to see the whole table
| Decision | AI may draft | AI may suggest | AI may not decide | Who decides |
|---|---|---|---|---|
| Hiring: who is interviewed, shortlisted, offered a job | The posting, the interview guide, a summary of a candidate's own submitted material | A list of candidates whose applications mention the stated requirements, as a starting point that a person reads in full | Which candidates advance, are rejected, or are offered a role. Ranking or scoring applicants counts as deciding | Hiring manager |
| Credit and payment terms for a client | The terms letter, the reminder sequence | A payment-history summary, a note that a client's pattern has changed | Whether to extend credit, on what terms, or to stop supply | Finance lead or owner |
| Pricing for a specific client or deal | The quote document, a first-pass estimate from your own rate card | Comparable past jobs, a range | The price offered, discounts, exceptions | Whoever owns the account |
| Advice to a client on what to do | Background research, a summary of options, a first draft the adviser rewrites | Points the adviser may have missed, questions to ask | The advice itself. The adviser owns every word that reaches the client | The professional on the matter |
| Termination, discipline, demotion | A chronology from documents a person has already reviewed | Nothing. Keep AI out of the recommendation | Any part of the decision, and any assessment of a person that feeds it | The manager, with HR or counsel |
| Performance assessment | A draft of the review from the manager's own notes | Nothing that scores or ranks people | Ratings, pay outcomes, promotion | The manager |
| Anything with legal effect: filings, notices, claims, contracts, sworn statements | A first draft, a checklist, a plain-language summary | Clauses to consider, inconsistencies spotted | What is filed, sent or signed. A person checks every citation and every fact against the source | The person who signs |
| Client communications that commit the firm | A reply for a person to edit | Tone, missing points | Sending it. Nothing goes to a client without a person reading it | The sender |
| Monitoring or investigating staff | Nothing without a written monitoring policy that describes it | Nothing | Conclusions about a person's conduct | Management, under the policy |
| Actions in company systems: sending, paying, publishing, editing records | The content of the action for a person to confirm | The next action | Taking the action, unless it's trivial, reversible and specifically approved in the register | The person confirming |
Get the kit