Writes a one-page AI usage policy for your HR team — plain language, numbered rules with a one-line "why" each, grounded in the law of your region. It's a usage policy, not a ban list: the goal is a team that uses AI daily and knows exactly where the lines are.
Write our HR team's AI usage policy
How it works
- Settles where the file will live — a connected folder — before writing anything.
- Asks one question first: where do your employees and candidates sit? US, EU/EEA, both, or elsewhere. Everything downstream depends on this — the "why" behind each rule cites the right laws (EEOC and state AI laws for the US; GDPR, the EU AI Act, and pay transparency rules for the EU; the stricter rule everywhere if both).
- Reads your existing policies. You upload whatever you have — handbook, privacy policy, InfoSec, NDAs — and it extracts what's relevant so the new policy aligns instead of conflicting. Where a conflict exists, it writes the stricter rule, names the conflict, and marks it [REVIEW].
- Interviews you — one question at a time, up to 9: who uses AI and for what, which accounts are approved, what data may never be entered, when real names are allowed, what needs human review, how you disclose AI use, and what happens when something goes wrong. It skips anything your uploaded policies already answer.
- Writes the policy, shows you the draft, and saves it only after you approve.
What you need to give it
- Where your employees and candidates are located.
- Existing company policies, if you have them (optional but improves alignment).
- Answers to the interview questions.
What you get back
A one-page policy file (ai-usage-policy.md) with a version header, an expectations block ("use AI for routine work, share what works, we outsource tasks — never responsibility"), and numbered rules covering at least: approved paid accounts only with model-training turned off; names out by default; a "never enter" data list (IDs, bank details, health records, open investigations); what may go in de-identified; AI never makes employment decisions; comp numbers come from a comp platform, never AI; human review for anything legal or going to an employee's file; how AI use is disclosed; and an incident procedure — stop, note it, report same day, no blame.
Every line that needs sign-off from legal, a DPO, or leadership is marked [REVIEW], and the document ends with a sign-off table.
How to run it
Copy the whole file from ai-usage-policy.md and paste it into a new AI conversation with a folder connected.
Good to know
The regional law references are why this beats a generic template — but the [REVIEW] marks exist because a policy like this still needs a human with legal responsibility to sign off before it ships.