The firm did not need to be convinced that generative AI was useful. Staff were already using it. The real issue was that nobody had defined what safe, acceptable, and professional use looked like.
This engagement created practical rules for ChatGPT and generative AI usage without blocking productivity. The policy had to be short enough for staff to read, specific enough to guide behaviour, and strong enough to protect client confidentiality.
Informal AI usage inside client-facing work
The firm had three overlapping problems: staff were experimenting independently, leaders did not know what data was being entered into tools, and managers had no shared standard for reviewing AI-assisted work.
Shadow AI usage
Staff were using public tools for drafting, summarising, research, and internal communication without an approved-use list.
Client-data uncertainty
There was no clear boundary around what client information could or could not be entered into generative AI systems.
Quality-control gaps
Managers lacked a standard review process for AI-assisted outputs before they reached clients.
Policy anxiety
Leadership wanted control, but did not want a heavy policy that would discourage useful experimentation.
Plain-language rules, not policy theatre
I began by mapping actual staff usage, then classified use cases by risk. The output was a practical policy and staff guide built around what the team was already doing, not an abstract legal document.
Usage audit
We identified where generative AI was already being used in drafting, summarising, research, administration, and client preparation.
Risk classification
Use cases were grouped as approved, conditional, restricted, or prohibited based on data sensitivity and output risk.
Data boundary design
We defined what information staff could never upload, what needed anonymisation, and what could be safely used for drafting support.
Staff guidance and review workflow
The final policy included examples, review steps, escalation rules, and manager responsibilities.
Practical governance assets
Generative AI usage policy
A plain-language policy covering approved uses, conditional uses, prohibited uses, and review requirements.
Client-data boundary rules
Clear guidance on confidential information, anonymisation, and sensitive-client material.
Review workflow
A practical process for reviewing AI-assisted outputs before client or public use.
Staff briefing guide
Examples of safe prompts, unsafe prompts, and when to escalate to a manager.
Staff could use AI with clearer boundaries
The firm moved from informal AI use to an approved, explainable usage framework.
Staff gained practical examples of safe and unsafe use, reducing uncertainty.
Managers gained a review workflow for client-facing AI-assisted work.
The business preserved productivity gains while reducing confidentiality and quality-control risk.
Most firms already have AI adoption before they have policy
Generative AI policies should not be written as abstract compliance documents. They should reflect how staff actually work. The best policies help teams use AI more confidently because the boundaries are clear.