AI policy for your company, with a template you can adapt
An AI policy tells your staff which AI tools they may use and what company information may go into each one. It also names who checks the result before anything leaves the building. Below are the topics a policy covers, what Canadian law already asks of it, and a complete template for a manufacturer or distributor. Download the template as a text file and have your lawyer review it before you adopt it, since this page is not legal advice.

What an AI policy is
An AI policy is a short written document that sets the rules for how your staff use AI tools at work. People also call it an AI use policy, an AI usage policy, an AI acceptable use policy or a generative AI policy. You can add it to your employee handbook or keep it as a separate policy that each person signs.
Generative AI means tools that write text, code or images from a request typed in plain language, such as ChatGPT, Claude, Microsoft Copilot and Gemini. The same features also show up inside the email, office and meeting software you already pay for.
How it differs from AI governance and AI security
The AI policy holds the rules your staff follow day to day. AI governance settles who decides and what records you keep when a new tool comes in. AI security covers the technical controls, such as sign-in, access rights and where data is stored, and is explained in AI security for your business.
Why a smaller manufacturer needs one
A written policy tells your staff which tool may receive a customer drawing or a cost sheet, so nobody has to guess. Quebec’s labour ministry published a guide on responsible AI at work on June 15, 2026. It warns that without clear rules, some staff may use outside tools or personal accounts without saying so. It suggests clear internal rules on AI tools, including the types of data staff should not use (Ministère du Travail guide, in French). The minister’s news release says the guide does not replace the legal framework that already applies.
The type of account decides what happens to your files. On personal ChatGPT and Claude plans, the person who owns the account decides whether chats train the vendor’s models (OpenAI and Anthropic, read September 27, 2026). On business plans, both vendors say they do not train on your content by default (OpenAI and Anthropic). Both also say a thumbs up or thumbs down on an answer can send that conversation into training: OpenAI says so for its personal plans even after an opt-out, and Anthropic says so for its commercial products. The detail by plan is in what a personal account does with your data and in the ChatGPT security settings to check.
When staff use AI tools the company has not approved, often on personal accounts, it is called shadow AI. The Canadian Centre for Cyber Security tells organizations to set policies on how AI should be used, with oversight and review (ITSAP.00.041, December 2025). It also tells users to keep personal information and sensitive corporate data out of prompts.
Need an approved tool before the policy goes out
Tell us which AI tools your team uses and which records they touch. We will tell you what an approved setup for those records would take.
Start a conversationWhat an AI policy for employees covers
An AI policy for employees covers ten topics. The table shows what each one decides, with an example from a plant.
| Section | What it decides | Example for a plant |
|---|---|---|
| Approved tools | Which AI tools staff may use, and with which account | Office staff use the company’s business plan, and nobody quotes from a personal account |
| Information classes | Which kinds of information may go into which tool | Customer drawings and cost sheets go only into tools approved for Confidential |
| Personal accounts, extensions and connectors | Whether staff may use their own accounts, browser add-ons or links to email and drives | A meeting note-taker needs written approval before it joins a customer call |
| Checking the output | Who checks AI output before it is sent, signed or approved | The estimator checks every price and tolerance against the ERP before a quote goes out |
| Decisions about people | Whether AI may screen applicants or rate staff | A person decides every hire, and an Ontario job posting discloses AI screening |
| AI that takes actions | What an AI tool may do without a person | The tool drafts a purchase order, and the buyer approves it before it goes |
| Impersonation and payment requests | How staff confirm a request that could be faked | A supplier’s new banking details are confirmed by calling the number on file |
| Reporting a mistake | What staff do when information goes into the wrong tool | Tell the policy owner within 24 hours, with no discipline for reporting |
| Training | What staff learn before they get an account | A session on the approved tool, using the plant’s own documents |
| Review and ownership | Who owns the policy and when it changes | The owner reviews it every 12 months and whenever a new tool arrives |
Two topics are easy to miss. One is AI features built into software you already pay for, such as meeting note-takers. The other is AI agents, which are tools that can send email or change records, so each of their actions needs a named person’s approval.
What Canadian law already asks of your policy
This section is not legal advice, and your lawyer decides how each rule applies to your company. In December 2023, Canada’s privacy commissioners said organizations using generative AI must comply with Canada’s privacy laws (Office of the Privacy Commissioner of Canada).
Federal (PIPEDA)
PIPEDA, the federal privacy law for businesses’ commercial activities, applies in Ontario and also applies in Quebec when personal information crosses provincial or national borders (PIPEDA in brief, Office of the Privacy Commissioner of Canada). Under PIPEDA, you stay responsible for personal information you send to an outside service. You must use a contract or other means to get comparable protection (Schedule 1, clause 4.1.3). You report to the Privacy Commissioner any breach that creates a real risk of significant harm. You also keep a record of every breach (sections 10.1 and 10.3). The commissioners also ask you, where possible and reasonable, to remove names and other details that identify a person before information goes into a prompt.
Canada’s proposed Artificial Intelligence and Data Act, part of Bill C-27, never received Royal Assent, and Bill C-36, a federal privacy bill, is at second reading in the House of Commons. The status of each bill is on AI governance for a smaller company.
Quebec
Quebec’s private sector privacy act, as amended by Law 25, applies to enterprises in Quebec. The rules from it that affect your AI policy are in the table at the end of this section, with the template section that covers each one.
Under section 41 of the Charter of the French language, an employer uses French in written communications with its staff. Documents on conditions of employment and training documents produced for staff must be in French. Where another version exists, the French one must be available on terms at least as favourable.
Ontario
From January 1, 2026, Ontario employers with 25 or more employees must disclose AI screening in public job postings. The rule covers AI that screens, assesses or selects applicants, including through a recruiting firm (Ontario ESA guide). An employer with 25 or more employees on January 1 also needs a written electronic monitoring policy (Ontario ESA guide). It must say whether staff are monitored electronically. If your AI tools log what staff type, make the two policies match. Ontario’s Bill 194 applies its AI rules to public sector entities only.
Controlled goods and export-controlled drawings
If you handle controlled goods or export-controlled technology, two federal documents cover that data in the cloud. The Controlled Goods Program’s cloud guidance says registrants are responsible for deciding whether a cloud solution is appropriate. It tells them to check data residency options so that controlled goods data is stored on servers located in Canada, and says Global Affairs Canada must be consulted about export licensing for data stored outside Canada. Global Affairs Canada’s Notice to Exporters No. 1159 explains when using a cloud service counts as a transfer of controlled technology, and says technology owners are responsible for making sure their cloud use does not cause one. Have your Designated Official (the person your company named to the Controlled Goods Program) or the person responsible for export controls decide before any such file goes into an AI tool.
The table sums up each rule in this section, what it asks and the template section that covers it.
| Rule | What it asks | Who it applies to | Template section |
|---|---|---|---|
| PIPEDA 4.1.3, outside services | You stay responsible for personal information you send to an outside service, and you use a contract or other means to give it comparable protection. | Businesses covered by PIPEDA | 6 and 8 |
| PIPEDA ss. 10.1 and 10.3, breaches | Report a breach that creates a real risk of significant harm, and keep a record of every breach. | Businesses covered by PIPEDA | 16 and 17 |
| Quebec, ss. 3.1 and 3.2 | The person with the highest authority is in charge of protecting personal information unless the role is delegated in writing, and that person approves the enterprise’s governance policies for personal information. | Enterprises in Quebec | 4 and 8 |
| Quebec, ss. 3.3 and 17 | A privacy impact assessment, a review of which personal information the system uses and how it is protected, before you acquire, develop or overhaul a system that handles personal information. An assessment and a written agreement before that information leaves Quebec. | Enterprises in Quebec | 6 |
| Quebec, s. 12.1 | Tell a person when a decision about them rests only on automated processing of their personal information. | Enterprises in Quebec | 12 |
| Quebec, ss. 3.5, 3.6 and 3.8 | Access, use or communication of personal information that the law does not authorize, or its loss or any other breach of its protection, is a confidentiality incident. Report an incident with a risk of serious injury to the Commission d’accès à l’information and the people concerned, and log every incident. | Enterprises in Quebec | 16 and 17 |
| Charter of the French language, s. 41 | Write to staff in French, and draw up documents on conditions of employment and training documents in French. | Employers in Quebec | 22 |
| AI disclosure in job postings | Say in a publicly advertised job posting when AI screens, assesses or selects applicants. | Ontario employers with 25 or more employees | 12 |
| Electronic monitoring policy | Keep a written policy that says whether staff are monitored electronically. | Ontario employers with 25 or more employees on January 1 | 18 |
| Controlled goods and export-controlled technology | Check data residency so controlled goods data is stored on servers in Canada, and make sure cloud use does not cause a transfer of controlled technology. | Registrants and holders of controlled technology | 7 |
AI policy template for a manufacturer or distributor
This template is written for a smaller manufacturer or distributor. Replace everything in [square brackets] and delete what does not apply. The text file holds the same clauses and numbering, so item 3 under section 7 here is clause 7.3 in the file. It is a starting point, so have your lawyer review it before you adopt it.
Download the AI policy template (plain text)
[Company name] AI use policy
Version [1.0]. Effective [date]. Approved by [name, title]. Next review [date].
This template is a starting point and not legal advice. Have your lawyer review it before you adopt it.
1. Purpose
- This policy lets you use AI tools for your work while protecting customer drawings, prices and personal information.
- It says which AI tools you may use, what information may go into each one, and who checks the result.
2. Who it applies to
- This policy applies to employees, contractors and temporary staff who do work for [Company name] or use its information.
- It applies on any device, including personal phones and home computers, whenever company information is involved.
3. Words used here
- An AI tool is software that writes, summarizes, translates, transcribes or analyzes content from a request. It includes AI features inside software we already use.
- An approved AI tool is a tool listed in section 5.
- A company account is an account that [Company name] pays for and that an administrator can add, remove and review.
- A personal account is any account you opened yourself, free or paid, including one opened with your work email address.
- A prompt is anything you type, paste, upload or say to an AI tool, including attached files.
- Output is anything an AI tool produces in response to a prompt.
4. Who owns this policy
- [Name, title] owns this policy and answers questions about it at [email or phone].
- Quebec only: the person in charge of the protection of personal information is [name, title].
- The owner keeps the list of approved tools in section 5 up to date.
5. Approved tools
- Use only the tools listed in the table below, signed in with your company account.
| Tool | Account type | Who may use it | Highest information class allowed |
|---|---|---|---|
| [Tool name] | [Company account on a business plan] | [All office staff] | [Internal] |
| [Tool name] | [Company account on an enterprise plan] | [Estimating and purchasing] | [Confidential] |
| [Tool name] | [Runs on our own server] | [Named users] | [Confidential] |
- Any new tool, AI feature, plug-in, browser extension, meeting note-taker or connection to email, shared drives or [ERP] needs written approval from [owner] first.
- When an AI feature appears in software we already use, do not use it with company information until [owner] adds it to this table.
- Do not use the thumbs up or thumbs down buttons in an AI tool unless [owner] has confirmed that feedback on that tool is not used for training.
6. What we check before approving a tool
[Owner] approves a tool only when clauses 6.1 to 6.6 are all true.
- A contract between the vendor and [Company name] covers our use of the tool.
- An administrator at [Company name] can add and remove users.
- Users sign in with a password and a second step, such as a code on their phone.
- The vendor states in writing that it does not train its models on our content by default.
- The vendor’s written terms say how long it keeps prompts and output, and whether we can delete them.
- The vendor states in writing where our data is stored and where it is processed.
- Quebec only: if the tool handles personal information, [owner] completes a privacy impact assessment first. If that information leaves Quebec, the assessment and a written agreement come before it does.
- [Owner] records each approval with its date and the highest information class allowed.
7. Information classes
- Public: information anyone can already see, such as our published catalogues and website. Any approved tool may use it.
- Internal: procedures, work instructions and routine email that hold no Confidential or Restricted information. Any approved tool may use it.
- Confidential: customer drawings and 3D models, quotes, cost sheets, routings, supplier prices, margins, customer and supplier lists, ERP exports and contracts. Use only tools marked for Confidential in section 5.
- Restricted: controlled goods technical data, export-controlled technology and anything a customer contract forbids sharing. Never put it into an AI tool unless [Designated Official (the person your company named to the Controlled Goods Program) or owner] approves in writing. Passwords, access keys and banking details never go into an AI tool, with or without approval.
- If a customer or supplier gave it to us, treat it as Confidential unless the contract says otherwise.
- If you are not sure of the class, treat it as the higher class and ask [owner].
8. Personal information
- Put personal information about employees, applicants or customer contacts only into [tool], and only where [owner] has authorised that use.
- Remove names and other details that identify a person when the task does not need them.
- Never put a person’s social insurance number, health information or banking details into an AI tool.
9. Personal accounts
- Never put company information into a personal AI account, free or paid.
- If an approved tool cannot do the job, ask [owner] which tool to use.
- Do not install a browser extension or phone app that reads your screen, email or files with AI unless [owner] has approved it.
10. Checking the output
- You are responsible for anything you send, sign or approve, whether or not an AI tool drafted it.
- Check every price, part number, tolerance, quantity and date against the source record before it goes into a quote, drawing, purchase order or contract.
- AI tools can state wrong facts with confidence. Check any fact, standard or regulation an AI tool cites against the original source.
11. Safety and code
- AI output never replaces a qualified person’s review for safety-related work, machine programs or controller code.
- Prove out any machine program an AI tool drafted using [our normal prove-out procedure] before it runs in production.
12. Decisions about people
- Do not use AI to decide hiring, pay, discipline or termination. A person makes the decision, with [HR owner].
- Ontario, 25 or more employees: if AI screens, assesses or selects applicants for a publicly advertised job, the posting says so. This includes AI used by a recruiting firm working for us.
- Quebec: if a decision about a person is based only on automated processing of their personal information, tell them. Tell them no later than when you tell them the decision.
13. AI that takes actions
- An AI tool may draft email, orders or changes to records.
- A named person approves each one before it is sent, placed or saved.
- No AI tool gets permission to send money, sign documents or delete records.
14. Payment and identity requests
- AI can imitate a voice, a face on video and a person’s writing style.
- Confirm any request to change banking details, send money or share access by calling a number already in our records. Do not use a number or link given in the request.
- Report a suspicious request to [contact], even if you did not act on it.
How these scams work is covered in AI-driven fraud and impersonation.
15. Being open about AI use
- Follow any customer contract or customer requirement about disclosing AI use.
- Tell your manager when an AI tool drafted a document going to a customer [adjust to your practice].
16. Reporting a mistake
- If company information went into the wrong tool or account, tell [contact] within [24 hours].
- You will not be disciplined for reporting a mistake quickly.
- [Owner] decides whether the law requires notice to a regulator or to the people concerned, and records the incident in [register].
- [Register] also records every breach of security safeguards involving personal information and, in Quebec, every confidentiality incident.
17. Records we keep
- [Owner] keeps the approved tools list, who holds an account on each tool, each tool approval, the incident register and training records.
- These records are kept for [period].
18. Monitoring
- [Company name] [does / does not] log use of approved AI tools. [Describe what is logged, such as prompts, files and sign-ins, and who can see the logs.]
- This section matches our [electronic monitoring policy]. In Ontario, an employer with 25 or more employees on January 1 of a year must have a written one.
19. Training
- Complete [training] before you receive an account on an approved tool.
- Complete a refresher every [12] months, and whenever a new tool is approved.
20. If the policy is broken
- [Existing discipline policy] applies.
- A mistake reported under section 16 is handled under that section.
21. Review
- [Owner] reviews this policy every [6 or 12] months.
- [Owner] also reviews it when a new tool, a new law or a new customer requirement arrives.
22. Language
- Quebec: this policy is issued in French [and in English]. If both versions exist, the French version is available on terms at least as favourable.
23. Acknowledgement
- I have read this policy and I will follow it.
Name: [name]. Signature: [signature]. Date: [date].
How to put it in place
- Pick the approved tools first, so section 5 names something real. Compare business AI tools and what they do with your data, and use the checklist in what makes an AI setup secure.
- Fill in the placeholders, name the owner and set the next review date.
- If you have staff in Quebec, issue the policy in French.
- Walk through it with staff and collect a signed acknowledgement from each person.
- Train staff on the approved tools with your own documents, as described in AI training for your team.
- Put the next review date on the calendar, and review the policy whenever a new tool arrives.
Who signs off a new tool, and what records back that decision, is set out in the AI governance setup for a smaller company. That page also explains ISO/IEC 42001, a standard for an AI management system, and the voluntary NIST AI Risk Management Framework.
How ThriveAI helps
ThriveAI is an AI engineering company in Ottawa that builds private AI systems for manufacturers and distributors in Ontario and Quebec, on their own data. It works hands on with your team, and Derik Lawlis, the founder, leads every project and stays close to the build.
The platform ThriveAI builds on is designed to keep your company’s data on your own server in Canada. You choose the model that reads it: one that runs on that server, or a hosted model under a written zero data retention agreement. Zero data retention means the provider does not store your prompts or its answers after it responds, except where the law requires it or its safety systems flag a request (Anthropic’s data retention page, read September 27, 2026). Not every hosted model is offered under zero data retention, and a hosted model may process requests outside Canada.
A system ThriveAI builds on that server can be the tool your policy names in section 5 for Confidential information. Stage one is a working prototype for one job, at a fixed price, in weeks, and you keep it. Working sessions run on site with your team, in French or English. More on how a project runs is on the About ThriveAI page.