
By Chisom Obiudo
An AI usage policy is effective only when employees can apply it correctly in their everyday work. It should tell them which tools are authorised, what information they may enter, how to verify AI-generated output, when to disclose AI assistance, and when to stop and whom to contact.
The real test begins on Monday morning
At 8:30 on Monday morning, an account manager has twelve minutes to prepare for a client call. They want to use an approved AI assistant to summarise last week’s meeting notes.
The company’s policy states: ‘Do not enter confidential information into AI systems’ and ‘All AI output must be subject to human oversight.’
The account manager must now decide: Does the client’s name constitute confidential information? If the name is removed, could the project details still identify the client?
How should the summary be reviewed before use? The policy sets out broad rules but not the practical steps required to complete the task safely.
This is the gap between policy and practice. Closing it requires the company to translate each rule into clear instructions: which tools employees may use, what information they may enter, how to remove identifying details, how to verify the output, when to disclose AI assistance, and whom to contact when uncertain. The first issue is determining what information employees may enter.
Why ‘do not enter confidential information’ is not enough
‘Do not enter confidential information’ sounds clear until an employee has a document in front of them and must decide whether to upload it.
A client’s name may already be public, but the client’s planned restructuring, negotiated prices or legal position may be confidential. A draft contract may contain standard clauses, signatures, financial terms and legal comments.
Removing the company’s name is not enough if the project details, dates, transaction value or other information could still reveal the client or the matter.
Anonymisation means removing or altering all details that could reasonably identify a person, client or transaction, not simply deleting a name.
The policy must also specify who is authorised to approve an exception and what the employee should do while awaiting a decision.
A team lead should not override a restriction because a deadline is tight. If the authorised person cannot approve it, the task must stop.
Once employees understand what information they may enter, they need equally clear instructions on how to verify the output.
Human oversight without verification is not oversight
Human oversight means testing AI-generated output against reliable source material before using it. Consider a procurement officer who asks AI to compare three supplier proposals.
The ranking appears reasonable, so the officer reviews it and copies the summary into an evaluation note.
Nobody compares the ranking with the original proposals to confirm that the tool included every mandatory requirement, used the correct prices and distinguished evidence from marketing claims.
Now consider a company secretary using an approved AI assistant to prepare a briefing from a 120-page board pack.
The summary accurately states management’s recommendation but omits a condition in the legal paper and reverses a figure in the finance appendix.
A director who relies on the summary because it appears plausible has failed to exercise effective oversight.
The verification process should require checking each decision, material figure, risk, and proposed resolution against the relevant source paper. Flag any uncertainty, and the AI-generated briefing should support meeting preparation rather than replace the board pack.
The checking process must align with the task. For a grammar edit, the employee should confirm that the meaning and facts remain unchanged.
For a supplier comparison, the employee should verify eligibility requirements, prices and scores against the original proposals. For a board-paper summary, the employee should confirm the decisions, figures, risks and proposed resolutions against the relevant papers.
The policy should specify what must be checked, which source must be used and what evidence of the check must be retained. That evidence could include a completed checklist, references to the relevant source pages or approval from a named reviewer. An instruction to ‘review carefully’ places responsibility on the employee without explaining how the review must be carried out.
Five actions every employee must be able to take
A usable policy can be tested through five observable actions. Employees should be able to demonstrate each one in a real task, not merely confirm that they have read the document.
1. Use an authorised tool
The employee can access the current list of company-approved AI tools and select the appropriate one for the task. The list distinguishes between company-managed accounts and free public accounts and includes AI features built into everyday software. If staff cannot find it quickly, ‘use approved tools only’ is not workable.
2. Decide what information may be entered
Employees should be able to classify information into one of three categories: permitted as is, permitted only after approved anonymisation, or prohibited. The policy should provide role-specific examples for each category.
A published product description may be permitted. Meeting notes may be allowed only after names and identifying project details have been removed.
Payroll records, passwords and access credentials may be prohibited. Draft contracts should be assessed based on their content and the security conditions of the approved tool.
The policy should also explain whether an exception may be requested, who has authority to approve it, and what the employee must do while awaiting approval. Information should not be entered until the required approval has been obtained.
3. Check the output against the source
Employees must verify AI-generated output against the original source before using it. For a meeting summary, they should compare the decisions, deadlines and assigned responsibilities with the meeting notes.
For financial commentary, they should reconcile each figure with the approved spreadsheet. For a contract summary, they should check the stated obligations, dates, exclusions and penalties against the relevant clauses.
The policy should also explain how the check must be recorded, such as through source references, a completed checklist or approval from a named reviewer. Reading the output and finding it plausible is not verification.
4. Disclose AI assistance when required
The employee knows when to disclose that AI was used, who must be told and how. An internal grammar edit may not require disclosure, whereas an external report, professional advice or a recommendation that influences a decision may require it. The policy provides standard wording and specifies where the disclosure must be recorded.
5. Stop and contact the right team
The escalation pathway should cover two situations: a possible incident and a new use requiring approval.
If an employee enters confidential or prohibited information, they should stop using the tool immediately.
They should not delete the prompt or response, continue the conversation with the tool, or share the output with anyone else.
Report the incident through the channel specified in the policy, such as the information security helpdesk, an incident-reporting form, or a security hotline. The report should identify the tool used, the time of the incident, the information entered, the output received, and any action already taken.
If the proposed use is for a new task and no incident has occurred, the employee should not begin the task. They should send the proposed use, the intended tool and the type of information involved to the AI policy owner, the information security team or the Legal adviser, as directed by the policy. Work should begin only after the required approval has been recorded.
Turn policy awareness into role-based practice
Defining the five actions is only the beginning. An annual acknowledgement confirms that employees have received the policy.
It does not demonstrate that they can apply it correctly. Employees need short, role-specific exercises based on decisions they are likely to face, such as summarising sales notes, using AI in recruitment, checking financial commentary against approved figures, or deciding whether a draft agreement has been properly anonymised.
Each exercise should present a realistic task, the proposed AI tool, and the information the employee intends to enter.
The employee should then answer five questions: Is the tool authorised? May the information be entered? How must the output be checked? Must the use of AI be disclosed? Who should be contacted if the answer is unclear or if something goes wrong?
After explaining the correct response and the rationale, the trainer should provide a second scenario for the employee to complete independently. Managers should receive additional scenarios showing what they may approve themselves and what must be referred to the AI policy owner, the information security team, or the legal team.
The measure of an AI usage policy is not whether it has been approved, published or acknowledged. It is whether employees can apply it correctly to their work. Hesitation, inconsistent answers and unnecessary referrals show where the instructions or training remain incomplete.
Start this week. Select three common AI tasks for each role and ask employees to work through them under the current policy.
Record where they hesitate, disagree, or choose the wrong action. Turn those points into clearer examples, practical checklists, and short, role-specific exercises.
Then test the policy again. Continue until employees can make the correct decision confidently and consistently. That is when an AI usage policy becomes a reliable guide for the decisions employees make at work.
*Chisom Obiudo is an admitted legal practitioner of the High Court of Namibia specialising in corporate governance and AI governance. She facilitates AI governance training for boards and delivers professional AI skills training. She can be contacted at chisomokafor11@gmail.com






