Business IT projects · Across Québec Request a quoteFrançais

AI usage policy

An AI usage policy is a short document, approved by management, that tells employees which artificial intelligence tools they may use, for which tasks, with which data, and how to check the results before relying on them.

Updated on

It is the centrepiece of AI governance. In its publication on generative AI (ITSAP.00.041), the Canadian Centre for Cyber Security says an organization's policies should include the oversight and review processes required to ensure the technology is used appropriately. This page is about the document itself: its content, approval, rollout and review.

Short answer

You describe your teams and the AI tools already in use: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The mandate can range from drafting alone to rollout and training.

What an AI usage policy mandate can cover

  • A picture of current use, through interviews or a short questionnaire
  • Drafting the policy, in French and in your team's other languages as needed
  • A simple data classification: allowed, allowed with care, prohibited
  • The list of approved tools and the procedure to request a new one
  • A one-page quick reference for employees
  • Support for approval, announcement and training
  • A review schedule and review triggers

The sections of an AI usage policy

  • Purpose and scope: who it applies to (employees, contractors, interns) and on which devices and accounts, including personal ones.
  • Approved tools: the list of allowed tools, the version or type of account required, for example a business account rather than a personal one, and how to request a new tool.
  • Permitted and prohibited uses: concrete examples by role, such as summarizing a public document, writing a first draft or reviewing code, and what remains off limits.
  • Data never to enter: the Centre advises avoiding personally identifiable information or sensitive corporate data in queries or prompts. The policy turns that principle into examples specific to the business: client or employee files, contracts, pricing, passwords, source code.
  • Human review: the Centre notes that outputs can be incorrect, might not make sense, might not take certain factors into account and can be biased, and recommends fact-checking against credible sources. The policy specifies who reviews what before use.
  • Transparency: when to indicate that content was produced with AI, for example in a document delivered to a client.
  • Decisions about a person: if AI is used to render a decision based exclusively on automated processing of personal information, section 12.1 imposes information and review obligations, detailed on our AI governance and oversight page.
  • Account security: multi-factor authentication, prompt history retention settings where the tool allows them, and no shared accounts.
  • Reporting: what to do if information was entered by mistake or an output causes a problem, and who to contact.
  • Roles and review: who owns the policy, who answers questions and when it will be reviewed.

Approval: who should sign off

Management should approve the policy, since it commits the business and applies to everyone. We recommend involving whoever manages IT, human resources and the person in charge of the protection of personal information.

That last point matters: Québec's private-sector privacy act requires governance policies and practices regarding personal information to be approved by the person in charge of the protection of personal information (s. 3.2). The rules in your AI policy that involve such information should therefore be consistent with those policies and go through that person.

Also have a few employees who use AI daily read the draft: they quickly spot rules that cannot be followed.

Communication: making the policy known

  1. An announcement by management explaining why the policy exists and what it allows
  2. A short session with examples from each role
  3. A one-page quick reference, posted or available on the intranet
  4. A read acknowledgement, so you know who received the policy
  5. Inclusion in onboarding for new employees
  6. An address or designated person for questions and tool requests

The Centre's publication ITSAP.10.093 also lists awareness training on artificial intelligence technologies among the topics an organization may want to offer.

Review: keeping the policy current

The Centre recommends keeping up to date on the latest threats and vulnerabilities associated with generative AI. We suggest setting a review date in the policy and also reviewing it at each of these triggers:

  • A new tool, or a new AI feature in software you already use
  • A change in a vendor's terms of use or data retention
  • An AI-related incident or error
  • A new project that uses personal information
  • Recurring questions from employees

Keep a version history and the date of each approval.

Questions to ask yourself before requesting a quote

  • Which AI tools do your employees already use, with personal or business accounts?
  • What sensitive data flows through the business: health, financial, client files?
  • Is there already a privacy policy, an IT acceptable use policy or a code of conduct to align with?
  • Who will approve the policy and who will own it?
  • Do you want only the document, or also the announcement, training and follow-up?

Pitfalls to avoid

  • Banning everything: employees may use tools anyway, just without guidance
  • A long, legalistic text nobody reads; the quick reference matters as much as the policy
  • Copying a foreign template that cites laws that do not apply to your business
  • Forgetting AI features built into software already in use, such as the office suite or management software
  • A policy with no owner and no review date
  • Rules that contradict your published privacy policy

What to specify in your request

  • The approximate number of employees and the main roles
  • AI tools known or suspected to be in use
  • The types of sensitive data you handle
  • Existing policies to align with
  • Languages for the policy and the quick reference
  • Desired deliverables: policy, quick reference, training session, review

Frequently asked questions

Should we ban ChatGPT and other public tools?

Not necessarily. In its publication on generative AI, the Canadian Centre for Cyber Security suggests considering whether AI is a necessary tool for the task, weighing the risks and costs. A common approach is to approve certain tools with business accounts, specify the data allowed and prohibit the rest.

What data should never be entered into an AI tool?

The Centre advises avoiding personally identifiable information and sensitive corporate data in queries or prompts. In the policy, name concrete examples: client or employee information, contracts, non-public financial data, passwords and source code. Also set out what to do if something is entered by mistake.

Who should approve the AI usage policy?

Management, together with the person in charge of the protection of personal information. Section 3.2 requires governance policies and practices regarding personal information to be approved by that person. The rules in the AI policy that involve such information should therefore go through them.

Do we have to tell clients we use AI?

It depends on the use. When a decision based exclusively on automated processing of personal information is rendered, section 12.1 requires informing the person concerned. For other uses, the policy can set a transparency rule, for example for documents delivered as is to a client. The Centre notes that content not clearly identified as AI-generated can result in confusion.

How often should the policy be reviewed?

Set a review date in the policy, and also review it when a new tool arrives, a vendor changes its terms or an incident occurs. AI tools change quickly, and a frozen policy loses credibility with employees.

AI usage policy

Usage policy, tool inventory and Law 25

Request a quote