Guide Objectives
- Understand the key elements of policies for Gen AI
- Know how to collaborate with stakeholders in identifying organizational Gen AI needs & risks
- Use and understand Gen AI use policy language
Given Gen AI’s growing prevalence in the workplace, leaders need to manage its use, risks, and potential for value creation.
It is important to develop policies for Gen AI use that are relevant to the organization and that address the potential use cases and concerns it may have. These policies are the backbone to which organizations can manage, define scope for, and develop consistency incorporating Gen AI in its work streams.
They also emphasize the need to move the organization forward in dealing transparently with modern technologies. This guide has been created to support the development of these policies.
Guide Specific Disclaimer
Gen AI technology and use cases are rapidly evolving. Likewise, updates to best practices are also a regularity. When using Gen AI, you should remain attentive to recent updates and news about the platforms you are using, along with their inherent risks. Similarly governments around the world have new AI policies in development, making the regulatory landscape quite active. While this guide is based on common principles, you should stay attuned to the specific nature of the AI tools that you use and the regulatory environment you operate in to customize appropriately.
Additionally, this guide is focused on Gen AI use, rather than the development of Gen AI tools. As such, the policy scope suggested is framed as such.
Review key elements of Gen AI use policies
When creating policy for Gen AI use, you should first understand a few key elements that should be included, such as:
- Data Management – Compliance: What regulations and guidelines exist within your region that may create compliance requirements? Policies should ensure all Gen AI use is aligned with the regulatory environment you are operating in. Reviewing relevant legislation on AI use is both a critical and complicated task as regulations are shifting on a nearly daily basis to account for new uses, technologies, and associated
- Data Management – Privacy – Are there use cases where employees may input sensitive information as prompts for Gen AI content creation? Given Gen AI algorithms (and responses) are developed based on both training data and (usually) user interactions, prompting with sensitive information would lead to that information being stored in the model as training data. It may then lead to that information being available for content creation for others using the tool. This is particularly concerning if the tool is publicly available.
- Ethics – Are there ethical concerns related to Gen AI that can influence how it is used by your organization? Many ethical concerns may be addressed by complying with local legislation. However, a policy should also ensure Gen AI use is aligned to your organization’s mission and values. Key ethical concerns to consider when using Gen AI tools, particularly for business or commercial gains include: using generated content that is based on biased data, creating content without sourcing, and mimicking the content of artists and their originality. Others include the use of Gen AI in existing applications, such as in minute taking or recording of confidential meetings without permission.
- Human-AI Collaboration – How does your organization utilize human decision making to curate use of Gen AI content? Policies should create scope and boundaries about AI usage, and particularly how and when it may be used to complement, rather than replace, human thought and creativity. In general, a human review of all Gen AI-developed content should be included .
- Sustainability – How can Gen AI be used in a way that minimizes negative environmental impact? Policies should strive to limit the inefficient use of Gen AI in order to reduce the significant energy and water consumption needed to run the models.
Evolving AI Legislation
AI legislation is in development in many countries and jurisdictions around the world at this time. For example, in the US, a summary of emerging AI legislation across various states exists here. In Europe, the European Union has adopted the Artificial Intelligence Act, providing guidelines and regulations across the board on AI development and use. In the UK, the government has released an AI Regulatory Framework.
Develop & implement a Gen AI use Workshop(s)
The next step involves understanding organizational needs and priorities prior to developing a fit-for-purpose Gen AI use policy. To do this, and to emphasize the importance of the process, holding a workshop with key interdisciplinary members of your team, or if you have a smaller organization, perhaps the whole team is important.
Key objectives include:
- Developing an understanding of how Gen AI is used in the workplace and for what purposes
- Understanding current opinions and apprehensions in using AI at work
- Defining key opportunities in using Gen AI to improve productivity and organizational impact
- Building consensus around key ethical, mission-related, and organizational risks entailed with current and likely future uses of Gen AI
- Begin brainstorming processes for mitigating risks
- Bringing staff into the policy development process, in order to build buy-in upon enactment
Due to the ubiquity and accessibility of Gen AI tools, leaders may not completely understand exactly how staff across the organization are currently utilizing them. Hence, it is imperative to bring together stakeholders to elucidate further on Gen AI usage. This will help define the scope of the policy and risk mitigation strategies.
A few questions to ask staff at the workshop include:
- How are you using ChatGPT and other Gen AI tools to serve your work? How has it best been effective? How are you checking the accuracy of the information?
- How do you see these tools improving your efforts? Are there tools you would like to experiment with further?
- Are there tool training sessions you feel would better your efforts?
- Are there opportunities you see where Gen AI can help grow the organization and its mission?
- What concerns do you have in using AI in your work? Do you have ethical concerns? Any thoughts on how to address them?
Write your policy for Gen AI use
After defining the needs and priorities for a Gen AI use policy customized to your organization, it is now time to create the policy. Feel free to use our template to kick start policy development.
A few key points to consider when writing the policy:
- Keep the policy focused – While there are many uses and risks related to Gen AI, starting out with a clear focus on the purpose and the target audience will create the clarity needed to create actionable policy items.
- Keep it simple (at least to start) – It is important to understand your staff’s limited attention span and bandwidth for reading (and understanding) policies. Rather than developing a detailed, comprehensive policy at the start, considering all current and potential future uses of Gen AI within the organization, it is better to start with critical policy elements that are immediately actionable and relevant.
- Create a common language – Gen AI terminology may not be familiar to or universally understood by all staff. Technical terms or words that could be open to multiple interpretations should be included in a glossary section of the policy, or removed altogether.
As your write your policies, look at this example and template to help you along the way.
During this process, it is also important to:
- Define who owns and is responsible for updating the policy; and
- Bring in key stakeholders to weigh in and provide feedback on iterations of the policy.
‘So what’ and next steps
After developing a policy, it is important to recognize the policy is a “living document”. This is always the case for policies, but is even more relevant for ones focused on Gen AI use, given the rapidly evolving nature of the tools, technologies, and practices.
It would also be important to kickoff policy implementation with a staff meeting to discuss the policy, hear any feedback, and move forward accordingly. Raising the importance of the policy and its value through the collaborative process is nearly as important as having the policy itself.
If you want to go further in using Gen AI in your organization, you can explore the guide on developing an organizational understanding of Gen AI for improved productivity.
Was this guide helpful? Please rate this guide and share any additional feedback on how we might improve it.