One-Page AI Do / Don’t List
Purpose: Short social/freebie asset that can be used in posts, PDFs, employee handouts, or landing page previews.
Title
Before employees use AI at work, answer these 5 questions.
The 5 questions
1. Is this AI tool on the employee list for this use?
If the tool is not on the employee-facing list (standing Approved or Conditional), do not use it for any company work — including drafts and Internal content.
If the tool is Conditional, stay inside the listed limits (teams, data types, features, retention). Approved ≠ unrestricted — even standing Approved tools have permitted use cases.
Personal / free AI accounts are not a company path.
2. Am I entering sensitive data?
Be careful with:
- Customer/client data
- Personal information
- Employee/HR data
- Financial/payment/payroll data
- Contracts/legal documents
- Source code
- Logs/security/vulnerability details
- Credentials/API keys/secrets
- Confidential business plans or pricing
Even on a listed tool, enter only data types permitted for that tool.
3. Can I use a redacted or generic version instead?
Safer prompt:
Draft a polite response to a customer asking for a delayed project update.
Riskier prompt:
Paste a full customer email thread with names, account details, contract terms, and internal notes.
4. Have I reviewed the output before using it?
AI can be wrong, outdated, biased, misleading, or completely made up.
Human review is required before using AI output for:
- Customer-facing communication
- Public content
- Legal, HR, finance, security, or compliance work
- Code/configuration changes
- Business decisions with meaningful impact
5. Do I know who to ask if I’m unsure?
If the answer is unclear, stop and ask [Owner/Team].
Fast questions prevent expensive mistakes.
Do
- Use only tools on the employee list (Approved or Conditional) for permitted use cases — Conditional limits still apply.
- Use public/generic information when possible.
- Redact sensitive details.
- Review AI output before relying on it.
- Ask before uploading files or connecting integrations.
- Report mistakes quickly.
Don’t
- Do not paste credentials, API keys, tokens, or secrets into AI tools.
- Do not upload customer/client files to tools that are not on the employee list (or not permitted for that data type).
- Do not use personal / free AI accounts for any company work.
- Do not stretch Conditional tools beyond listed teams, data types, or features.
- Do not invite AI meeting bots to sensitive meetings without approval.
- Do not install AI browser extensions that can access work apps without approval.
- Do not treat AI output as automatically correct.
Bottom line
AI can help teams move faster, but shadow AI creates avoidable risk.
Use only listed tools within their limits. Protect sensitive data. Review the output. Ask when unsure.
Conditional limits note: Conditional tools are allowed with boundaries. Check the employee-facing list before you paste. Standing Approved still means permitted use cases only — not a free-for-all.
CTA version
Need a practical first step?
Get the free AI Tool Approval Checklist Lite.
Social post version
Employees are already using AI at work.
Before they paste data into ChatGPT, Copilot, Gemini, meeting bots, browser extensions, or AI writing tools, they should answer:
- Is this tool on the employee list for this use (Approved or Conditional — limits apply)?
- Am I entering sensitive data?
- Can I use a redacted/generic version?
- Have I reviewed the output?
- Do I know who to ask if I’m unsure?
The goal is not to block AI.
The goal is to stop shadow AI from turning into shadow risk.
This material is provided for general operational and informational purposes only. It is not legal, compliance, privacy, security, HR, or professional advice. Review and adapt for your organization before use.