Skip to content
HomeThe Journal – Articles and InsightsAI at Work
,

No AI Policy at Work? That Is the Norm, and It Is Now Your Responsibility

You ask about your company’s AI policy and get a blank stare. That is the norm, not the exception. Here is how to protect yourself, and your reputation, when the rules do not exist yet.

Woman at a desk looking intently at a computer

Most organizations are using AI faster than they are governing it. Here is how to protect yourself in the gap.

You start a new job, you want to do the right thing, so you ask whether there is a policy on AI tools. You get a shrug, a vague answer, or a link to a document that says nothing. If that happens, you are not unlucky. You are in the majority. A 2026 study found that while 94 percent of higher-education employees had used AI tools for work, only 54 percent were aware of any policies governing that use, and more than half were using tools their institution had never vetted. Often the issue was not poor communication. The policies simply did not exist yet.

This is happening across industries, not just on campus. Business adoption of AI has kept climbing while the rules lag behind. The practical result for you is uncomfortable: you will be using AI in situations where no one has told you what is allowed. A missing policy does not remove the risk. It removes the guardrails and leaves the responsibility with you, which makes your own rule for what not to paste the thing that protects you.

Why the gap is risky for you specifically

When there is no policy, the consequences of a mistake do not disappear. They land on the person who made it. Paste a client’s confidential data into a consumer chatbot and you may have created a genuine privacy problem, regardless of whether anyone told you not to. AI chat tools have already had serious exposures, including a leak of roughly 300 million private messages from one popular app. “There was no rule against it” is not a defense that protects your reputation or your employer’s data. The safer assumption is that you are accountable for your own AI use whether or not a document says so. The same caution applies to your company’s own work product. Feeding an unreleased strategy, unpublished research, or proprietary material into an unvetted tool can compromise information your employer depends on, and you could be the one asked to explain how it got out.

A five-step playbook for the policy vacuum

You do not need the company to act first. You can build your own standard.

First, find the policies that already apply. Even with no AI-specific rule, your employer almost certainly has policies on data handling, client confidentiality, security, and acceptable use. Those already bind you, and most AI questions are really data questions in disguise. Start there.

Second, ask a specific question rather than a general one. “What is our AI policy?” invites a shrug. “Can I use an AI tool to draft this client summary, and is there an approved tool for it?” is concrete enough to get a real answer, and it puts your judgment on display in the process.

Third, build a personal data rule. Decide in advance what you will and will not put into an AI tool. A reasonable default: never paste client data, personal information, credentials, or anything confidential into a tool your company has not approved. When you need AI help with sensitive material, anonymize it or use a made-up example that has the same shape.

Fourth, keep a simple record. Note when you used AI on meaningful work, what you put in, and how you checked the output. This habit, sometimes called an AI work log, takes seconds and gives you a clear answer if anyone ever asks how a piece of work was produced.

Fifth, when unsure, choose the conservative option. If you cannot tell whether something is allowed, treat it as if it is not until you can ask. The cost of waiting an hour is small. The cost of a confidentiality breach is not.

A quick word on which tools to trust

When you do get an answer about approved tools, understand why it matters. Tools your employer provides through a business or enterprise agreement usually come with contractual protections about how your data is stored and whether it is used to train future models. The free, personal version of the same chatbot often does not carry those protections. This is one of the most useful distinctions to learn early: the same brand of AI can be safe to use through a company account and risky to use through a personal login. When in doubt, ask which account you should be using, not just which tool.

You can be the person who fixes it

Here is the opportunity hiding in the problem. Someone is eventually going to help shape how your team uses AI. It might as well be the person who raised it thoughtfully. You do not need authority to ask a manager whether the team should agree on some basic ground rules, or to share a short summary of how you handle it yourself. Early-career people who bring structure to a messy situation do not look junior. They look like leaders.

No policy is not permission

It is responsibility, handed to you by default. Treat the gap as a place to show judgment rather than a loophole to exploit, and keep in mind how easily AI conversations leak when you decide what is safe to share. Build a personal standard you can explain to anyone, and you turn the most common workplace AI situation into a quiet advantage.

Fred Faulkner Avatar

About the author

Keep reading

More from the journal

All articles