Staff AI use policy prompt: free ChatGPT template
Updated · By Robert Breen
Use this when staff already use ChatGPT or similar tools and nobody has said what's allowed. A first draft from AI saves the blank page, but it can't know your clients, contracts or local rules. So this prompt builds the draft only from decisions you've made, and lists the questions you still need to answer instead of answering them for you.
Have a professional review it. This prompt helps you draft, not decide. Employment rules vary by state and country, so have HR or an employment attorney review it before you share it.
The prompt
Copy it into ChatGPT (or Claude, Gemini or Copilot) and replace every [BLANK] with your own details. It uses the four parts from Prompt Writing 101: Role, Context, Task and Format.
Role: You are helping the owner of [BUSINESS] draft a short, plain-language policy on using AI tools at work. Context: Our staff do [WORK]. Tools we allow: [APPROVED TOOLS]. Information that must never go into an AI tool: [NEVER SHARE]. Work a person must check before it goes out: [HUMAN CHECK]. Questions go to [CONTACT]. Only write rules I've given you. Where a policy would usually cover something I haven't decided, list it as a question. Task: Write a one-page policy covering: purpose in two sentences, approved tools, what never goes in, how to mask client details, what needs a human check, how to report a mistake, and who to ask. Then list my open questions. Format: Short headed sections with bullets, under 450 words, written to the employee as "you". Then "Questions for the owner" as a numbered list. No legal language I didn't supply.
Fill in the blanks
[BUSINESS]- Your business name and what you do.
[WORK]- The kinds of work staff might use AI for.
[APPROVED TOOLS]- Which tools and which accounts: the business account, not personal ones.
[NEVER SHARE]- The data that never goes in: ID numbers, account numbers, health details, passwords, client documents.
[HUMAN CHECK]- What a person must read before it leaves the building.
[CONTACT]- Who answers questions and takes reports of mistakes.
Example, filled in
A made-up example from the free lesson Turn a Client Meeting into Action Items and a Follow-Up Email (Accounting Firms). Millbrook Accounting is the made-up firm in the client meeting lesson. Staff have started pasting meeting transcripts into ChatGPT to pull out action items, and the owner wants the rules written down.
Role: You are helping the owner of Millbrook Accounting, a small accounting and bookkeeping firm, draft a short, plain-language policy on using AI tools at work. Context: Our staff do bookkeeping, payroll and tax preparation for small businesses, including client meetings and client emails. Tools we allow: ChatGPT on the firm's account only, signed in with your work email; no personal accounts. Information that must never go into an AI tool: Social Security numbers, tax IDs, bank and card numbers, passwords, and client tax returns or source documents. Work a person must check before it goes out: every client email, anything with a date, amount or tax figure, and any summary saved to a client file. Questions go to Maya Brooks. Only write rules I've given you. Where a policy would usually cover something I haven't decided, list it as a question. Task: Write a one-page policy covering: purpose in two sentences, approved tools, what never goes in, how to mask client details, what needs a human check, how to report a mistake, and who to ask. Then list my open questions. Format: Short headed sections with bullets, under 450 words, written to the employee as "you". Then "Questions for the owner" as a numbered list. No legal language I didn't supply.
What a good answer looks like
- A never-share list in plain words, plus a how-to line: replace names with "the client" and drop account numbers before pasting.
- A human-check rule tied to real work: every client email and every date, amount or tax figure.
- Open questions such as: May staff use AI for tax research? What happens if client data is pasted by mistake? Do clients need to be told?
- No rules you didn't give it, like a ban on all AI or a disciplinary process.
How to check it before you use it
An AI draft can sound right and still say something you never told it. Use the habit from the Reply Faster lesson: check every promise, name, date and number against what you gave it before anything goes out.
- Have HR or an employment attorney review it. Firms with client confidentiality duties should also check their professional rules.
- Make sure your tool settings match the policy. Read your plan's data controls before saying what the provider does with your data.
- Answer every open question before rollout, or the gaps become the policy.
- Give staff an example of masked text, not just a rule to mask.
Why this prompt works
An AI acceptable use policy works when it's short enough to remember. Making the AI list open questions, instead of filling them in, keeps policy decisions with the owner.
Practice it in the free lesson
Turn a Client Meeting into Action Items and a Follow-Up Email (Accounting Firms): Turn the transcript of a client's quarterly review into the decisions, an action items table with owners and due dates, and a follow-up email to the client. You do every step yourself in a practice copy of ChatGPT, and nothing touches your real accounts.
Also useful: Prompt Writing 101: Role, Context, Task, Format
Terms used here
Related prompts
- Policy summary for staff prompt: Turn a long internal policy into a plain staff summary: who it applies to, what to do, limits and deadlines, with unclear lines…
- Staff AI training plan prompt: Plan short AI training for your staff around tasks they already do each week: who learns what, practice on masked examples, and…
- Employee handbook section prompt: Turn your own rules into one plain-English handbook section, with every gap and anything touching pay, discipline or privacy…