AI Use Policy for Employees: Written, Adopted, Trained
An AI use policy tells staff which AI tools they may use, what data may go into them, when output must be checked or disclosed, and who approves new uses. Remolda drafts it with you and trains staff on it.
In short
- A usable AI policy fits on a few pages: approved tools, data classes, review and disclosure rules, who owns what, and how to request a new use.
- It is written for your tools (Microsoft 365 Copilot, ChatGPT Enterprise, Claude, others) and your data, in English and French.
- Canadian anchors: PIPEDA and the privacy commissioners' 2023 principles for generative AI, Quebec Law 25 for automated decisions, and Ontario's rule on disclosing AI use in job postings (since January 1, 2026).
- Starts with the one-week AI Readiness Review ($490 CAD + HST), which maps current AI use; drafting and staff training are quoted on the call.
- The policy ships with a one-page staff summary and a short training session, so people know the rules on day one.
Your situation
An AI policy is often written after staff have already started using AI. Typical triggers:
- Staff use personal ChatGPT accounts for work. Client names, drafts and numbers go into tools the organization has no contract with.
- Copilot or ChatGPT Enterprise is being rolled out. Leadership wants rules in place before licences go live.
- A client, funder or insurer asked. A questionnaire wants to know how you control AI use.
- Hiring and HR use AI. Screening tools, job postings and interview notes raise disclosure and fairness questions.
What the policy covers
| Section | What it settles |
|---|---|
| Approved tools | Which tools and tiers staff may use, and for what |
| Data rules | What may go into which tool: public, internal, confidential, personal information |
| Output rules | Checking facts, figures and citations; when AI use must be disclosed |
| Special uses | Hiring (including the Ontario job-posting disclosure), client-facing content, decisions about individuals, code |
| Roles | Policy owner, approvers for new tools, privacy and security contacts |
| Incidents | What to report, to whom, how fast |
| Review | Review date and triggers for an earlier update |
A one-page staff summary goes with it, written in plain language.
What Remolda does
Maps current use. Which tools people use today, for which tasks, with which data. The AI Readiness Review session covers it.
Checks vendor terms. Business-tier data use, retention and region settings for your tools. See AI vendor selection.
Drafts the policy. In your format, English or French, with the Canadian rules that apply to you. The structure we start from is our AI use policy template. The regulatory map is covered in AI compliance in Canada.
Trains staff. A short session and the staff summary, or a full Copilot and ChatGPT training by role.
How long it takes
In our experience two to four weeks from the first session to an approved policy. It depends on the number of approvers, legal and privacy review, and whether a French version is required.
What it costs
The first step is the one-week AI Readiness Review at $490 CAD + HST, which maps current AI use and gaps. Policy drafting and training are quoted on the same call, based on tools, units and languages. See the pricing page for all packages.
Why Remolda for an AI policy
- Written for your tools. Rules match the licences and tiers you actually use.
- Canadian sources cited. Each regulatory point links to the official text.
- Staff learn it. Summary and training included in the plan.
- Bilingual. English and French versions.
- Kept current. Owner, review date and triggers built in.
How the work runs
Policy work sits in the Audit and Strategy steps of the Remolda Cycle and is revisited in Evolve.
- Readiness Review. Current use, data and gaps.
- Vendor terms check. Data use and region settings.
- Draft. Policy and staff summary.
- Approval. Review with leadership, legal and privacy.
- Launch. Staff session and a review date.
Frequently asked questions
What should an AI use policy for employees include?
Scope and definitions, the list of approved tools, what data may and may not be entered, rules for checking and disclosing AI output, special rules for hiring and client-facing use, roles and approvals for new uses, incident reporting, and a review date.
Is there a template we can use for an AI policy?
Yes. Remolda publishes an AI use policy template for Canadian organizations in Word and PDF, in English and French, at remolda.com/en/insights/tools/ai-policy-template. A template gives the structure; the adapted policy has to match your tools, vendor contracts and privacy obligations, which is the work we do with you.
Do Canadian organizations have to have an AI policy?
For most private companies a written AI policy is voluntary, and several rules make one practical: PIPEDA accountability for personal information, Quebec Law 25 notices for decisions made exclusively by automated processing, and Ontario's rule that employers with 25 or more employees disclose AI use to screen, assess or select applicants in public job postings.
How much does an AI policy cost?
The first step is the AI Readiness Review at $490 CAD + HST, which maps current AI use and the gaps. Drafting the policy and training staff are quoted on the call, based on the number of tools, units and languages.
How long does it take to put an AI policy in place?
In our experience two to four weeks from the first session to an approved policy. It depends on how many people must sign off, whether legal and privacy review it, and whether both language versions are needed.
Should the policy ban ChatGPT?
Bans are hard to enforce and push use onto personal accounts. A workable approach is to approve one or two business-tier tools, set data rules and require review of output. Where a tool is off-limits, the policy explains why and names the approved alternative.
How do we keep the policy current?
Name an owner, set a review date every six to twelve months, and log requests for new tools or uses. Tool changes and new regulations trigger an earlier review.
Sources
- Office of the Privacy Commissioner of Canada — Principles for responsible, trustworthy and privacy-protective generative AI technologies
- LégisQuébec — Act respecting the protection of personal information in the private sector (CQLR c P-39.1), s. 12.1
- Canadian Centre for Cyber Security — Generative artificial intelligence (ITSAP.00.041)
- Ontario — Your guide to the ESA: requirements related to publicly advertised job postings
Facts checked:
Related services
Approach phases
Related insights
LLM Integration into Existing CRM and ERP Software in Canada: Architecture, Data Residency and Cost
Mitacs AI Advantage: Ottawa Commits $162M to 10,000 AI Work Placements
AI for Canadian Municipalities: Where It Works in 2026
Talk to an AI transformation consultant
A 30-minute call: you describe the situation, we tell you what to do first and what it would cost.
Book a 30-min call30 minutes. English or French.