Your staff is already using generative AI. Whether you approved it is a separate question.
Marketing is drafting external copy in public chatbots. Developers are pulling backend snippets from coding assistants. Someone in finance is pasting spreadsheet extracts into a language model to get a summary before a Tuesday meeting.
Absent a written policy, every one of those people is making an individual call about what corporate data is acceptable to upload to somebody else’s servers.
That’s the exposure. Accidental disclosure, weakened intellectual property claims, regulatory liability. Banning the technology rarely fixes it either, because people who need the productivity just move to personal devices where you have no visibility at all.
What works is a policy built around data classification, human accountability, and vendor control. Not technology forecasting. Rules about what goes where, and who answers for the output.
Regulatory detail below reflects the position as of early October 2026. This area moves quarterly, and none of it is legal advice.
Start With Data Classification
The most immediate risk is proprietary information leaving your perimeter.
Consumer-grade AI tools routinely use submitted text to refine their models. When an employee pastes a client’s financial portfolio, an internal strategy memo or proprietary source code into a public chatbot to tidy the wording, that content has left your control. It may surface in responses to entirely unrelated users.
Your policy needs rigid tiers, each mapped to specific permitted tools.
Public data. Marketing copy, published releases, general industry research. Already available externally, so public AI interaction carries little additional risk.
Internal data. Employee schedules, standard operating procedures, routine internal communications. These belong in enterprise-grade tools where the vendor contractually commits that your data won’t train their models.
Confidential and restricted data. Client PII, trade secrets, unreleased financials, healthcare records, proprietary source code. Prohibited from any external AI system without documented executive approval and verified encryption.
The National Institute of Standards and Technology addresses exactly this in the Artificial Intelligence Risk Management Framework (AI RMF 1.0), which emphasises mapping data flows and enforcing access controls to prevent exposure during machine interactions.
Translate that into one sentence your staff will remember: on a consumer platform, treat every prompt as though you’re publishing it.
Get the Copyright Position Right
There’s a lot of confused advice circulating here, and both extremes are wrong.
Human authorship is required for copyright protection. The Copyright Office has been consistent that purely machine-generated output, with no meaningful creative human contribution, cannot be registered.
What doesn’t follow is total forfeiture. Human-authored contributions to a work remain protectable, and the Office has registered works containing AI-generated material where the human authorship was disclosed and identifiable. You lose protection on the machine-generated elements specifically, not on the entire asset.
That distinction determines whether you ship. A logo generated wholesale from a prompt gives you weak standing against a competitor copying it. The same logo, substantially reworked by a designer whose contributions are documented, is a different legal object.
Your policy should include an authorship clause covering three things.
Generative tools are for brainstorming, outlining, and preliminary drafting. Employees must meaningfully modify machine output before commercial deployment, and should keep a record of what they changed. And anyone using AI to produce a core business asset discloses it, so counsel can assess ownership before the thing ships.
The documentation matters as much as the editing. A registration claim rests on being able to describe what the human contributed.
The Employment Law Position Changed Substantially
This is the section most AI policy guides currently get wrong, because the landscape moved three times in the past year.
Machine learning models inherit and amplify whatever bias sits in their training data. Letting software screen résumés, evaluate performance, or predict candidate success creates real discrimination exposure. That much hasn’t changed.
What changed is the regulatory map.
Colorado’s AI Act was repealed before taking effect.
Governor Polis signed SB 26-189 on 14 May 2026, replacing SB 24-205 with a considerably lighter version that drops the bias audit and risk assessment requirements. The replacement arrives 1 January 2027. Any guide citing the original Colorado AI Act as a live bias-audit obligation is describing a law that no longer exists.
The EEOC withdrew and reissued its guidance.
The Commission pulled its hiring guidance in 2025 and reissued a version in April 2026, then adopted a new National Enforcement Plan for FY 2025–2029 on 4 June 2026. The underlying ADA and Title VII obligations are unchanged. The specific technical assistance document many policies cite may not be current.
NYC Local Law 144 remains the strictest requirement in force.
Employers and employment agencies using an automated employment decision tool for NYC hiring or promotion must obtain an independent bias audit annually, publish the summary, and give candidates at least ten business days’ notice. It’s the only US law today mandating a formal annual independent audit.
Illinois HB 3773 took effect on 1 January 2026.
It amends the Illinois Human Rights Act rather than creating a separate AI statute, prohibits AI from producing discriminatory effects across recruitment through termination, bars zip codes as proxies for protected characteristics, and requires applicant notice. One complication: the Illinois Department of Human Rights withdrew its proposed implementing rules in June 2026 to coordinate with other agencies, with no revised timeline. The statute remains fully enforceable without final guidance on how to satisfy it.
Others in motion.
Texas TRAIGA and California’s FEHA automated-decision and CPPA ADMT regulations all took effect 1 January 2026, with California employer compliance due 1 January 2027. Connecticut’s CART Act begins phasing in from 1 October 2026. Companies with EU operations or EU-based staff also fall under the EU AI Act, whose high-risk obligations became fully enforceable on 2 August 2026.
The enforcement precedent worth knowing is older and concrete. In 2023, the EEOC settled its first AI hiring case when iTutorGroup paid $365,000 after recruiting software automatically rejected more than 200 applicants for being too old.
What your policy should say.
Prohibit autonomous software making final hiring, compensation, promotion, or termination decisions. Require human-in-the-loop for all HR functions: machines can aggregate and summarise, a manager verifies, interviews and documents the decision. If you operate in NYC, budget for the annual audit. If you operate in Illinois, build the notice into your application flow now rather than waiting for implementing rules that may not arrive.
Vendor Auditing Is the Load-Bearing Control
This section deserves more weight than most policies give it, for a reason the Illinois statute makes obvious.
HB 3773 applies to the use of AI. A Workday or Greenhouse module scoring candidates falls inside the statute even though you didn’t build it, didn’t configure the model and may not know it’s running. Vendor diligence isn’t a procurement formality. It’s the compliance step.
The broader point is that most AI in your business isn’t a chatbot anyone visits. It’s features shipping quietly into software you already pay for. Your CRM, your email platform, your accounting package, your project tooling. If a vendor trains on your data by default, you’re exposed regardless of what your staff does or doesn’t paste into public tools.
So: no department head activates a new application, or a new generative feature inside an existing one, without technical and legal review. IT evaluates data retention terms, model training opt-out mechanisms and security architecture before approval.
For mid-market organisations that need this operationalised without loading it onto internal staff, engaging specialised IT consulting services in Charlotte can audit third-party AI vendors, configure secure enterprise tenants and lock down data loss prevention across the network. The value is making the infrastructure match the document, blocking exfiltration attempts and surfacing unsanctioned deployments before they become incidents.
Discovery comes first, though. Run an inventory before writing rules about tools you haven’t found yet. Expense reports, SSO logs, and browser extension audits will surface most of what’s already in use, and endpoint security platforms increasingly report AI service usage across a fleet directly.
Enforcement Is What Makes It a Policy
A document sitting in the handbook protects nobody. Enforcement, monitoring, and consequences are what convert it from a suggestion.
Have every employee, contractor and vendor sign a separate acknowledgment, distinct from general onboarding paperwork. That removes the ignorance defence when someone feeds restricted financial data into a public system.
Mandate disclosure. Employees declare when generative tools contributed to client deliverables, financial forecasts, or production code. And state the accountability rule explicitly: if a model fabricates a figure or invents a citation, the person who submitted the work owns the error. Blaming the tool is never a defence.
Then set out consequences that match the severity. Treat a data classification breach the same way you’d treat any cybersecurity breach. Deliberately uploading confidential client PII to an unvetted model is an insider threat event, and the policy should say so in those terms.
Build in a Review Cycle
One structural recommendation, given everything above.
Three US frameworks changed within twelve months. Colorado repealed and replaced its law. The EEOC withdrew and reissued guidance. Illinois pulled its implementing rules after the statute went live. A policy written to a fixed regulatory snapshot is out of date within two quarters.
Date the document. Assign an owner. Schedule a quarterly review of the regulatory position and an annual review of the whole policy. Keep a change log, because demonstrating that you tracked obligations as they shifted is itself evidence of good faith if anyone ever asks.
Strong data governance, human accountability, and continuous vendor auditing let you use this technology without surrendering your intellectual property, your security posture, or your standing with a regulator. The policy is the mechanism. Keeping it current is the work.
Related: Who Owns Artificial Intelligence? Ownership vs Control
