TheoryPractitioner30 min

Building an AI Use Policy

Why you need a written policy

Many organisations deploy Claude without a formal policy, reasoning that their general IT acceptable-use policy is sufficient. This is a mistake. A general IT policy was written for email, file sharing and internet access. It does not address the specific capabilities and risks of generative AI.

Without a policy that addresses AI specifically, employees will:

  • Make their own judgements about what data is appropriate to enter into Claude (some will be too cautious; others will be reckless)
  • Attribute AI-generated content without understanding whether that is required
  • Be uncertain what to do when Claude produces a harmful or incorrect output
  • Have no framework for escalating concerns

A clear, specific AI use policy eliminates this ambiguity. It is also a legal requirement in some contexts: the EU AI Act and sector-specific AI governance regulations increasingly require documented policies for AI tools used in regulated activities.

What a good policy covers

A useful AI use policy is short enough to be read (2–4 pages maximum), specific enough to be actionable, and positive in framing (what you can do) before it is prohibitive (what you cannot do).

Section 1: Purpose and scope

This policy governs the use of [Company Name]'s Claude Enterprise deployment. It applies to all employees, contractors and third parties who access Claude through our Enterprise account.

The purpose of this policy is to enable productive, safe and compliant use of Claude, and to prevent misuse that could expose [Company Name] or its stakeholders to harm.

Section 2: Approved use cases

List the categories of tasks for which Claude may be used. Be specific — "general productivity" is not actionable; "drafting emails, summarising documents, analysing data, writing code, preparing presentations" is.

Claude may be used for:

  • Drafting and editing internal and external written communications
  • Summarising documents, reports and meeting notes
  • Analysing structured data and generating commentary
  • Writing, reviewing and documenting code
  • Researching topics and synthesising information from provided sources
  • Generating creative content for internal or external communications
  • Supporting decision-making by exploring scenarios, identifying risks and generating options

Section 3: Prohibited uses

Be specific about what is not allowed. Vague prohibitions like "do not misuse Claude" are unenforceable. The most important prohibitions for most organisations:

Data input restrictions:

Do not enter the following into Claude:

  • Full names, contact details or financial information of individual clients or customers, unless anonymised
  • Employee personal data (salary, performance data, disciplinary history, medical information)
  • Passwords, authentication credentials or encryption keys
  • Information marked as [Company Name] Confidential or higher, without explicit approval from your manager and the DPO
  • Non-public financial data that would constitute inside information
  • Information covered by legal professional privilege, unless specifically approved by the General Counsel

Output restrictions:

Do not:

  • Publish, submit or send any Claude-generated content without human review and verification
  • Represent AI-generated content as wholly your own original work when authorship disclosure is material (e.g., academic contexts, regulated advice contexts)
  • Use Claude to generate communications designed to deceive or mislead
  • Use Claude to automate decisions with significant consequences for individuals without appropriate human oversight and a lawful basis for automated processing

Tool restrictions:

Do not:

  • Access Anthropic's API or third-party Claude integrations using your personal API keys without IT approval
  • Use Claude through any interface other than [company's approved deployment] without IT security approval
  • Share your Claude login credentials with others

Section 4: Verification and accuracy

Address the hallucination risk explicitly:

Claude can produce plausible but incorrect information. All Claude-generated outputs must be verified before use, particularly:

  • Facts, statistics and data
  • Legal or regulatory requirements
  • Technical specifications
  • Financial figures

You remain responsible for the accuracy of any output you use, regardless of whether it was AI-assisted.

Section 5: Attribution

Clarify when AI assistance must be disclosed:

Disclose AI assistance when:

  • Submitting documents for external regulatory or legal purposes (check specific disclosure requirements with Legal)
  • Publishing content in contexts with explicit human-authorship requirements
  • Responding to direct questions from clients or partners about how work was produced

Internal use of Claude for drafting and analysis does not require disclosure in most contexts. When in doubt, ask your manager or the legal team.

Section 6: Incident reporting

Define what to do when something goes wrong:

Report the following to [contact/email]:

  • Claude produces an output that is harmful, offensive or that could expose [Company Name] to reputational or legal risk
  • You accidentally enter prohibited data into Claude
  • You discover that a colleague is using Claude in a way that appears to violate this policy
  • You encounter a technical error or security concern related to Claude

Reports are treated as standard IT incidents and will not result in disciplinary action for the person reporting in good faith.

Section 7: Policy maintenance

This policy is reviewed [annually/semi-annually] or whenever significant changes occur to Claude's capabilities, [Company Name]'s risk profile or applicable regulation. Queries and suggestions should be directed to [contact]. The current version is available at [intranet link]. Previous versions are archived at [location].

Common pitfalls in AI policies

Too long: a 15-page policy will not be read. Aim for 2–4 pages. Put technical details in an appendix.

Too vague: "Use Claude responsibly" is not a policy. Every clause should be specific enough that a reader can make a binary decision: does this action comply or not?

Too prohibitive: a policy that is mostly restrictions will not be read and will not be followed. Lead with what people can do. People read the permissions and skip to the restrictions; make the permissions explicit and concrete.

Treating it as a one-time document: a policy written in 2024 will be out of date by mid-2025 as Claude's capabilities evolve and regulation develops. Assign a named owner and a review date.

Not communicating it: a policy that lives on the intranet without active communication is effectively invisible. Include it in onboarding, reference it in training, and re-publish it when updated.

The policy communication plan

When you publish or update your AI use policy:

  1. Email all Claude users with the key points summarised in plain language (not just a link to the full document).
  2. Update your Claude onboarding materials to include a policy summary page.
  3. Brief managers so they can answer their team's questions.
  4. Add policy acknowledgement to your onboarding checklist — employees confirm they have read and understood the policy as part of gaining access.
  5. Post a summary in #claude-help so it is discoverable by new users joining the channel.

Scenario: a policy incident and its resolution

A paralegal at a law firm pastes a full client case summary (including client name, matter number and case details) into Claude while drafting a letter. The firm's AI policy prohibited entering client-identifying information, but the policy was unclear about what "identifying" meant in practice.

The incident is reported by the paralegal themselves (who realised the issue immediately and followed the reporting process). The DPO reviews the incident, confirms the data was not retained beyond the firm's 30-day retention setting, and determines no GDPR breach notification is required.

The policy is updated: a new section clarifies "identifying information" with examples (name, address, matter number, case details) and adds a sentence: "When in doubt, replace names with initials and remove matter numbers before pasting context into Claude."

The update is communicated to all legal staff with a 5-minute training clip. There are no recurrences.

Key takeaway

Your AI use policy is a living document, not a compliance checkbox. Write it to be read (short, specific, positive-first), communicate it actively, assign an owner and a review cadence, and treat incidents as improvement opportunities rather than enforcement moments. A policy that employees actually follow is infinitely more valuable than a comprehensive one that no one has read.


📖 Official Documentation See this in practice in Anthropic’s live support docs: