Expertise · Using AI responsibly

Establishing principles for using internal AI.

A set of AI usage principles is not just formal paperwork: it is how you maintain consistent quality when the entire team uses AI for company tasks.

Quick summary

An internal AI usage framework needs to clearly answer four questions: who can use which tools, which data must never be included, when a review is mandatory, and who is responsible for implementation. Without this framework, the risk of data leaks and brand identity drift gradually increases without anyone noticing. Sinh Vũ recommends establishing the framework early, even when the team is small, and reviewing it periodically as tools and regulations change continuously.

Quick comparison
You should choose this direction when
  • Someone on the team has started using AI for company tasks.
  • Large scale with many departments requiring centralized control.
  • Industry subject to strict regulations requires a clear framework before scaling
Not needed when.
  • write policies once and then store them away without updates
  • only general prohibitions without specific data classification
  • skipped the review step for customer-facing content
Quick glance
Commonly used industries
Financehealthcarelegaltechnology

When a team member starts using AI for company tasks without any framework, that company is operating on implicit trust. Sometimes that’s fine. But as the team grows, as data becomes more sensitive, and as content moves out faster, implicit trust is no longer sufficient. An internal AI acceptable use policy is how you set clear boundaries before issues arise.

Four questions a set of guidelines must address

It doesn't need lengthy documents. It needs to adequately answer these four questions:

  • Who can use which tools. Not all tools are suitable for every position. The person handling customer data needs to know which tools are approved and which are not.
  • Data that must never be included. Customer information, contracts, personnel data, and unpublished strategies are the most common types that need to be explicitly listed. General prohibitions without classification leave employees unaware of the true boundaries.
  • When a review is mandatory. Content reaching clients, official announcements, decisions affecting individuals: these points require someone to check for accuracy, bias, and relevance before release.
  • Who is responsible for execution. If no specific person is named, policies will not be updated and no one will take action when issues arise.

Data classification: the part that many overlook.

This is the most common weakness: a general prohibition policy, but without specifying what is sensitive. The result is that each person makes their own judgments, leading to inconsistent conclusions.

The simplest way is to divide into two columns: data allowed to be fed into AI and data not allowed. The practical classification criterion is the consequences if that data leaks outside the organization. Publicly posted content is usually allowed. Customer names and contact information are often not. You do not need a complex security diagram to start: a clear list is enough for the team to know and practice.

Mandatory review point

AI generates content quickly, but that speed also poses risks if there is no pause. AI governance frameworks like NIST AI RMF and OECD guidelines emphasize that outputs used for significant decisions or external content must be reviewed for accuracy, bias, and interpretability.

In practice, you need to clearly define at least three types of stopping points:

  • Content reaching customers, whether it’s an email, document, or social media post.
  • Official announcements outside the organization.
  • Decisions affect individuals, whether they are customers or employees.

A stop point does not mean approval through multiple layers. Sometimes, a ten-minute review by one person is sufficient. What matters is that this stop point exists and someone is truly responsible for it.

Establishing a framework early and concisely. Small team: a half-page to one-page document, concluding four questions above, enough to get started. Large teams or industries under strict management: need a clear facilitator, a new tool approval process, and a regular quarterly review schedule. There’s no need to wait for the team to grow large before establishing a framework: the highest risks often occur during rapid growth, when people use new tools before anyone has a chance to ask questions.

Policies must live, not be set in stone once.

AI tools are changing rapidly. Regulations like the EU AI Act are tightening. A policy written last year may be outdated compared to today's reality. This is why the principles need a clearly defined review schedule in the documentation, rather than waiting for an incident to revisit.

A periodic review is also an opportunity to update the approved tool list, adjust data classification as the business changes, and remind the team about boundaries. The habit of regular reviews is more important than the perfection of the first draft.

The viewpoint of Sinh Vũ

Sinh Vũ operates under the philosophy that every task has an output steward. For us, the principle of using internal AI is not an administrative procedure but a way to maintain stable quality as scale increases. When working with clients, instead of imposing a pre-set policy template, Sinh Vũ facilitates a working session for your team to collectively finalize the principles they believe in and will implement. Classifying data, identifying mandatory reviewers, and assigning responsibilities: these decisions belong to you, not us. We ask the tough questions and remain neutral.

Accountability is the foundation of trustworthy AI: there must be clear mechanisms for responsibility and oversight, as well as corrective measures in case of errors.

OECD AI Principles, accountability principle, referenced from NIST AI RMF.
The tool brings back.

Decision checklist

Topic: Establishing internal AI usage principles for the business. Sinh Vũ Handbook, sinhvu.com

0 more than 6 items

Select each item you find appropriate, then print or save as PDF to take with you.

Sign indicating that you should take action
Questions to answer before deciding

If you have marked most of the signs above, this is the time to discuss in more detail. Sinh Vũ can help you review and propose a direction.

References

Datapath, AI Acceptable Use and Governance Policy for Businesses. AWS, Responsible AI Policy. OECD AI Principles (accountability principles). NIST AI Risk Management Framework (AI RMF 1.0).

Frequently asked questions

In a small company with just a few people, is it necessary to write principles for using AI?

Necessary, and the sooner the better. In a small team, each person has their own habits, and data boundaries are often not communicated. A short document, half a page to one page, clearly stating which data should not be input into AI and who reviews external content is enough to get started. Simple but essential, and it must be read by the team, not left in a drawer.

When classifying specific data, what criteria should be used?

The most practical criterion is the consequences if that data is leaked. Customer data, contracts, personnel information, and unpublished strategies are typically in the category that is strictly prohibited from being entered into external AI tools. Public data or released content is usually allowed. You do not need a complex diagram: a simple two-column list indicating what can and cannot be entered is sufficient for the team to understand the boundaries.

← Back to Brand AI