Do We Need an AI Policy If We Don't Use AI? - Gemstone Consulting Services Blog Post - https://gemstoneconsultingservices.com/post/do-we-need-an-ai-policy-if-we-dont-use-ai

Do We Need an AI Policy If We Don't Use AI?

October 01, 2026•9 min read

Many business owners assume an AI use policy is something you write after you buy AI software. If the company hasn't adopted any AI tools, it's easy for them to feel like they don’t need to waste time governing something that they don't use.

The trouble is that your company doesn't have to adopt AI for your team to use it. Staff can open ChatGPT, Claude, or Gemini on a work computer or a personal phone in seconds. And many of the tools you already pay for, such as email platforms, office software, meeting apps, and industry systems, have added AI features over the past two years.

So the question is “Do we need an AI Policy if our company doesn’t use AI?”

The short answer: Yes. If your team uses computers or phones for work, you need an AI use policy, even if leadership has never approved an AI tool. Without one, staff decide for themselves what information is safe to enter, which tools to trust, and when AI output is good enough to send. A policy replaces those individual guesses with clear company rules.

Key Takeaways

  • Not adopting AI is not the same as not using it. Staff may already use AI tools on their own to perform their jobs, and software you already own may include AI features.

  • No policy means every employee sets their own rules. That's how confidential information ends up in tools the company doesn't control. When confidential information gets leaked, your company is responsible for the data breach whether the issue stems from AI use you authorized or not.

  • A policy is a safeguard, not a commitment to adopt AI. It can say "no AI tools are approved yet" and still set clear expectations for how work can be performed..

  • In regulated industries, the stakes are higher. In healthcare and behavioral health, a single paste of client information into a personal AI account can be a reportable privacy issue.

  • A good policy is short and practical. Staff should be able to answer "can I use AI for this?" in under a minute.

Why "We Don't Use AI" Is Usually Not True

When leaders say their company doesn't use AI, they usually mean the company hasn't bought an AI product. That's a different statement.

Staff are using it on their own. Employees are using AI to perform their work regardless of whether the company has officially authorized a specific software. Most aren't hiding their AI use because no one is establishing what the rules are. If they have the option to use an AI tool that can produce in 15 minutes what used to take them 2 hours, they’re going to opt for convenience. Microsoft and LinkedIn's 2024 Work Trend Index found that 75% of office based workers were using generative AI at work, and 78% of those users brought their own tools rather than waiting for their employer to provide them. The term BYOAI which stands for “Bring Your Own AI” has become a common phrase in some workplace settings.

Your existing software has added AI. Office suites, email platforms, video meeting tools, CRMs, and industry specific software now include AI writing assistants, meeting summaries, and automated suggestions. Some of these features may already be switched on for your account by default. This means your team may already be using AI every day to perform their job.

AI arrives through vendors and contractors. Your bookkeeper, marketing agency, IT provider, or recruiting firm may be using AI on your data. You have no idea what software they’re using, what's being entered into the various platforms, and how that data is managed and stored by the unknown vendor.

What Can Go Wrong Without a Policy

Confidential information leaves the company. An employee pastes a client proposal, a financial spreadsheet, or a contract into a personal AI account to "clean it up." Depending on the tool and its settings, that information may be stored, reviewed, or used to improve the vendor's models. In 2023, Samsung restricted generative AI use on company devices after employees entered internal source code into ChatGPT.

Wrong information goes out under your name. AI can produce confident, well-written answers that are simply incorrect. Without a rule requiring human review, those errors reach clients, proposals, and the public.

Staff get mixed messages. One manager encourages AI use, another forbids it, and a third doesn't know it's happening. Employees stop asking and do what seems easiest.

AI makes decisions it shouldn't. Using AI to screen resumes, evaluate employees, or decide who gets a service raises legal and fairness questions. Some jurisdictions already regulate it. New York City, for example, requires bias audits and candidate notices when employers use automated tools to make hiring decisions.

You can't respond to a problem you didn't define. If an employee makes a mistake with AI, there's no standard to measure it against, no process for reporting it, and no fair basis for consequences.

What's Different in Behavioral Health and Treatment Programs

Everything above applies plus there are additional consequences.

  • Client information carries federal protections. Substance use disorder records are protected by 42 CFR Part 2 in addition to HIPAA. Since February 16, 2026, Part 2 has followed HIPAA's breach notification rules and penalties, and HHS's Office for Civil Rights is enforcing it.

  • Documentation pressure drives unapproved use. Clinicians and admissions staff behind on notes are among the most likely to try AI shortcuts. Without a policy, nothing tells them that a personal account, free or paid, is not an acceptable place for client information.

  • Accreditors are paying attention. In September 2025, the Joint Commission and the Coalition for Health AI released guidance calling for AI policies, governance, staff training, and monitoring. It's voluntary for now, but it signals what surveys, licensing, and other regulatory audits will look like in the future.

  • Your EHR may already include AI. Many EHR vendors have added AI documentation features. Your policy should say whether those features are approved, and under what conditions.

We cover this in depth in "Shadow AI and the HIPAA and 42 CFR Part 2 Violation Dilemma".

What an AI Use Policy Should Cover

A useful policy answers the questions staff actually have. At a minimum, it should cover:

  1. Scope. Who the policy applies to including employees, contractors, interns, and vendors handling company data.

  2. Approved tools. Which AI tools, if any, are approved, and whether AI features in existing software may be used. "None are approved yet" is a valid feeling, but just making that statement doesn’t stop employees from using AI, they will just use it in secret.

  3. Prohibited information. What must never be entered into an AI tool, such as client or patient information, financial records, personnel files, passwords, and confidential business documents.

  4. Account rules. Whether staff may use personal AI accounts for work. In most companies, especially regulated ones, the answer should be no.

  5. Human review. Which AI-assisted work must be checked by a human before it's final or sent outside the company.

  6. Decisions AI may not make. Hiring decisions, discipline, client eligibility, or clinical judgment should never be made solely based on an AI response.

  7. Disclosure. When clients or customers should be told that AI was used.

  8. Reporting mistakes. How staff report an AI-related error or a possible data exposure, and a commitment of whether reporting will result in disciplinary action.

  9. Training and acknowledgment. How staff learn the policy and confirm they've read it.

  10. Ownership and review. Who owns the policy and how often it's updated. We recommend at least twice a year while AI tools are changing this quickly. That is our recommendation, not a legal requirement.

How to Put a Policy in Place Without Slowing Your Team Down

  • Ask before you write. Find out what staff are already using, and make it safe to answer. A policy written without that information misses the real risks.

  • Start simple. A clear 2 to 3 page policy that people read beats a 20-page document nobody opens. That length is our estimate of what staff will actually read, not a rule.

  • Pair every "no" with a path. If staff can't use personal AI accounts, tell them what they can do instead, even if it's "bring the task to your manager while we evaluate approved tools."

  • Train with real examples. Show staff actual tasks from their jobs and whether AI is allowed for each one.

  • Revisit it. AI features change monthly. Put a review date on the policy.

Frequently Asked Questions

Do small businesses need an AI policy?
Yes. Small companies often have fewer IT controls, which makes informal AI use harder to see. A short policy covering prohibited information, account rules, and human review addresses the biggest risks without heavy administration.

Can our AI policy simply ban AI?
It can, but bans rarely work on their own. Staff who find AI useful often keep using it on personal devices, where the company has even less visibility. A policy that sets clear limits and offers an approved path is usually more effective.

Is an AI policy legally required?
In most industries, no specific law requires a standalone AI policy yet. However, existing obligations, including privacy laws, HIPAA, 42 CFR Part 2, employment laws, and client contracts, still apply when staff use AI. A policy is how you show you've taken reasonable steps to address the issue.

What's the difference between an AI policy and an acceptable use policy?
An acceptable use policy covers technology in general, such as email, internet, and devices. An AI policy addresses risks specific to AI, including what information can be entered, how outputs are reviewed, and which decisions AI may not make. Some companies add an AI section to their existing acceptable use policy. Either approach works if the AI rules are clear.

Who should own the AI policy?
One named person, usually in operations, compliance, or IT, should be responsible for keeping the AI policy current. In healthcare and behavioral health, the compliance or privacy officer should be involved.

Get Your AI Use Policy in Place

Your company needs an AI use policy even if you've never approved an AI tool, because your team may already be using it. In a 20-minute call, we'll talk through how AI is showing up in your company today and how our AI Use Technology Toolkit helps you put a clear AI use policy in place.

Schedule a call with us https://calendly.com/micheledavisnyc/20-minute-chat

Related Reading

Michele Davis

Michele Davis

Michele Davis is the Founder and CEO of Gemstone Consulting Services. She helps companies adopt AI in their operations with the governance, workflows, and staff training for sustainable team adoption. She brings 16 years of leadership experience in nonprofit, government, and human services settings, which includes programs subject to HIPAA and 42 CFR Part 2. She created the proprietary RISE Method and hosts the Bots in the Building podcast.

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog