Policy on Employee Use of Artificial Intelligence

Policy on Employee Use of Artificial Intelligence

Purpose:

To ensure that employees use AI applications responsibly while safeguarding confidential information and personally identifiable information (PII).


Warning
Absolutely nothing that, bundled with other information found elsewhere on the internet, has the remotest possibility of identifying a person or company should ever be entered into an AI app. 

Approved AI Apps

Chat GPT is approved for general use, provided the rules below are followed. Please contact Roberta to request approval for other AI apps. 

Scope:
This policy applies to all employees using AI applications (such as, but not exclusively, ChatGPT) in the course of their work, including any text-based AI tools, automation platforms, or other artificial intelligence services.

1. Confidentiality and Data Privacy

  • Do not share confidential information: Employees must not input confidential company data, trade secrets, or any information related to clients, partners, or vendors that could harm the company if disclosed. 
  • PII Removal: All PII (such as names (even first names should be changed) , addresses, phone numbers, email addresses, Social Security numbers, and financial details) must be removed from any data before it is entered into AI tools.
  • Internal Company Info: Any information stored in AutoTask or other cloud services we use, including configuration item names that use the customer's company name fully or partially, company locations, ticket numbers, etc. must be changed before being entered into AT tools. 
  • Sensitive Data: Information such as passwords, security credentials, or personal financial information must not be entered into AI applications under any circumstances.
  • Sensitive Links. Do not input links to SecureNotes data, SharePoint shares, or company or customer web site URLs
  • Do not upload files that may contain any of the above. 

2. Approved Use Cases

  • AI can be used for general tasks such as:
    • Drafting non-confidential emails, reports, or summaries.
    • Providing general information, analysis, or brainstorming ideas.
    • Automating routine tasks (e.g., data processing without sensitive content).
  • All use cases involving AI must comply with this policy and relevant legal and regulatory requirements.

3. Employee Responsibilities

  • Understand the tool: Employees should familiarize themselves with the capabilities and limitations of AI applications before using them for work purposes.
  • Anonymize Data: Employees must ensure that any data entered into AI tools is free of any identifying markers, or unrelated to specific individuals or clients.
  • Regular Review: Employees must periodically review the data they enter into AI systems to ensure compliance with this policy.

4. Data Handling Procedures

  • Secure Inputs: Always review information before inputting it into AI applications to ensure it does not contain sensitive or confidential details.
  • Data Retention: Employees must not store confidential data or PII within AI platforms that do not provide adequate security or encryption.
  • Compliance with Regulations: Ensure all AI use complies with data protection laws such as GDPR, HIPAA, and other industry-specific regulations.

5. Training and Support

  • Training: Employees will receive training via our Cyber Security Training platform on best practices for using AI tools. 
  • Support: Management will provide guidance on secure AI usage, and employees must consult Roberta before using any new AI applications not previously approved.

6. Consequences of Non-Compliance

  • Violations of this policy may lead to disciplinary actions, including but not limited to warnings or termination of employment, depending on the severity of the breach.

7. Policy Updates

  • This policy will be reviewed and updated as AI technologies evolve, or as required by legal and regulatory changes.

Approval & Effective Date
This policy is effective from 10/2/2024 and must be adhered to by all employees using AI tools.



    • Related Articles

    • Employment Forms

      W-4 Form Federal Income Tax Withholding  Employers aren’t required to report any information that employees claim on their Form W-4, Employee's Withholding Certificate to the IRS. However, Forms W-4 are still subject to review. Employers may be ...
    • Company (Staff) Directory

      See below for Staff List. Direct lines are also listed in IT Glue under each user's PINS. This staff directory is for internal use only. Customers should generally be emailing the support address for tech support or the office address for ...
    • Time-Off Policy and Instructions for Full-Time Employees

      Vacation Time Eligibility All full-time employees are entitled to the following paid vacation benefit. A full-time employee is defined as one who consistently works at least thirty-five hours per week. Accrual First two calendar years of sequential ...
    • Paid Sick Leave Policy - Expires 12/31/24

      This policy expires on Dec 31.2024. Please see the updated policy here. Paid Sick Leave Policy Both full-time and part-time employees get a certain amount of paid sick leave every year based on the number of hours worked. Each employee accrues earned ...
    • Paid Sick Leave Policy - Effective January 1, 2025

      Items in green are direct verbiage from the NJ sick leave law Paid Sick Leave Policy Both full-time and part-time employees get a certain amount of paid sick leave every year based on the number of hours worked. Each employee accrues earned sick ...