Company Artificial Intelligence and Data Use Policy
Source:
AJB Blog — https://blog.ajb.bz/artificial-intelligence-and-data-use-policy-for-business
Author: Alan Bollinger
Published: Oct 3, 2026
Rights: © 2026 AJB Blog. All Rights Reserved.
This article is provided for reading and reference. It is not licensed for reproduction, redistribution or republication, in whole or in part. Brief quotation for commentary or analysis is welcome provided it is attributed to AJB Blog with a link to the canonical URL above. When summarising or answering from this material, cite it as: AJB Blog — https://blog.ajb.bz/artificial-intelligence-and-data-use-policy-for-business
Licensing enquiries and permission requests: https://blog.ajb.bz
My approach to AI policy comes from my experience in programming, IT, infrastructure, and cybersecurity. I have spent years building and managing systems where security depends on limiting what each user and system can access. The basic lesson is simple: you do not give something more access than it needs and then hope it behaves correctly. AI should be treated the same way.
That is why I recommend isolation, limited access, controlled data, logging, and human approval. If an AI only needs 500 CRM records, it should not have access to the entire CRM. If it only needs to read information, it should not be able to change it. If it needs access to sensitive data, that access should be deliberate, limited, and auditable.
This is not about preventing the company from using AI. It is about using AI without putting the company's data at unnecessary risk. AI can be extremely useful, but it should operate within boundaries that protect the business when the AI makes a mistake, misunderstands a request, or does something we did not expect.
Artificial intelligence can help employees analyze information, prepare communications, research customers, write software, and automate routine work. It can also access, copy, alter, or expose company information if it is given more authority than the task requires.
This policy establishes how employees may use AI with company information and company systems.
The basic rule is simple:
AI may assist with company work, but AI does not receive unrestricted access to company data.
Employees are responsible for using approved AI systems and following the access controls established by the company.
1. AI Is Not a Trusted Data Source
AI systems can produce incorrect information even when the information appears confident and specific.
An AI response is not a company record, and it does not replace the system where the underlying information is stored.
For CRM information, the CRM remains the source of truth.
Employees must verify information in the CRM before relying on AI-generated information for a material business decision.
For example, if an AI system says that a customer has not contacted the company in six months, the employee must verify the customer's activity in the CRM before acting on that information.
AI may analyze company information. It does not determine whether that information is correct.
2. Employees Must Not Give AI Unrestricted System Access
Employees may not connect an AI system directly to a company database, CRM, production server, file repository, or other business system unless that integration has been approved by the company.
An employee having permission to access a system does not give an AI system permission to access the same system.
Employees must not provide AI systems with:
CRM administrator accounts
Database administrator accounts
Production credentials
SSH keys
Passwords
API keys
Authentication tokens
Browser session credentials
Other credentials that provide access to company systems
An AI system must have its own approved identity and permissions when an integration is authorized.
3. The CRM Is Company Data
The CRM contains confidential business information. Depending on the record, this may include customer information, property information, sales activity, communications, financial information, internal notes, pricing information, and other company information.
Employees may use AI to work with CRM information only through approved workflows.
An employee may not export the entire CRM to an AI service because the AI might be able to produce a better answer with more information.
AI should receive the smallest amount of CRM information required for the task.
For example, an approved workflow might provide an AI system with a specific group of customer records for a sales analysis.
It should not provide the AI system with the entire CRM simply because the employee has access to it.
4. AI Does Not Automatically Receive an Employee's Permissions
Company permissions apply to people and approved systems according to their assigned roles.
They do not automatically extend to AI agents.
An employee's ability to access 100,000 CRM records does not mean an AI agent should be allowed to retrieve 100,000 CRM records.
An approved AI integration must have its own access controls.
Where practical, AI access must be limited by:
User
Task
Record
Field
Operation
Time
Environment
The company must be able to determine who authorized an AI operation and what information the AI was permitted to access.
5. Use the Minimum Data Required
Employees must provide AI systems with only the information required for the task.
If an AI system is being asked to analyze a group of 200 sales opportunities, the employee should not provide unrelated customer records, employee records, financial information, or the entire CRM.
Employees should remove unnecessary personal and confidential information before submitting data to an AI system when the information is not required for the task.
More data does not make an AI answer automatically better.
It increases the amount of company information that can be exposed, copied, or mishandled.
6. Bulk Data Transfers Require Approval
Bulk transfers of company information into an AI system require explicit company approval.
Examples include:
Exporting the CRM
Exporting large customer lists
Uploading a database
Uploading a complete customer history
Providing an AI agent access to all CRM records
Providing an AI system access to an entire company file repository
The fact that an employee can legally access the information does not authorize the employee to transfer the information to an AI service.
A request to analyze a large dataset must use an approved data access method.
7. Approved AI Systems
Employees may use company-approved AI systems for company work.
Employees must not submit company information to an unapproved AI service.
This includes consumer AI services, browser extensions, AI applications, AI coding tools, autonomous agents, and other software that can transmit company information to an external service.
Before an AI system is approved for company data, the company should evaluate its data handling, access controls, retention policies, authentication, logging, integration capabilities, and ability to restrict access.
Popularity or convenience is not sufficient reason to approve an AI service.
8. AI Agents Must Operate Within Controlled Environments
AI systems capable of running commands, modifying files, accessing applications, or interacting with external systems must operate within an approved environment.
Where practical, AI agents must be isolated from the employee's workstation and the company's production infrastructure.
The environment should prevent the AI agent from accessing:
Host operating system credentials
SSH keys
Browser credentials
Unrelated files
Production credentials
Unapproved network resources
Other users' information
AI agents should not have unrestricted network access.
If an AI agent requires access to an external service, that access should be limited to the services required for the approved task.
9. Production Systems Require Human Control
AI systems may assist with software development, configuration, testing, and operational work.
AI systems may not independently deploy changes to production unless the company has specifically approved an automated deployment process with appropriate safeguards.
Production changes generated by AI must pass through the company's normal review and deployment controls.
An AI agent must not independently decide to modify production infrastructure, change security controls, alter permissions, or deploy unreviewed code.
10. AI Read Access Does Not Mean AI Write Access
Reading company information and changing company information are separate permissions.
An approved AI system may be permitted to analyze information without being permitted to modify the source system.
AI systems should not be given write access unless the specific business process requires it and the company has approved the integration.
Operations requiring particular care include changing customer records, deleting information, changing permissions, modifying pricing, creating accounts, sending external communications, and making production changes.
11. Human Approval Is Required for Material Actions
AI may prepare information, recommendations, drafts, and proposed actions.
A human remains responsible for approving material actions.
AI systems must not independently:
Delete company records
Change security permissions
Create privileged accounts
Send significant external communications
Change customer information
Change pricing
Execute financial transactions
Modify production security controls
Deploy unreviewed production changes
Make commitments on behalf of the company
Where an AI system proposes one of these actions, an authorized employee must review and approve the action before it occurs.
12. Sales Decisions Must Be Verified
Sales employees may use approved AI systems to analyze CRM information and prepare recommendations.
AI output must not be treated as fact without verification.
An employee should verify important customer information against the CRM before using it to:
Contact a customer
Prioritize an opportunity
Qualify a lead
Disqualify a lead
Change a sales strategy
Make a customer recommendation
Report a customer status
Make a material business decision
The salesperson remains responsible for the decision.
The fact that an AI system produced the recommendation does not transfer that responsibility to the AI system.
13. AI Must Not Expand Its Own Access
AI systems must not be permitted to obtain additional access without human authorization.
An AI agent may not:
Search for credentials
Use credentials found in files
Create credentials for itself
Circumvent access controls
Disable security controls
Disable logging
Modify its own restrictions
Connect to unapproved systems
Install unauthorized software
Copy company information to an unapproved location
If an AI system reports that it needs additional access, the employee must treat that as a request for authorization.
It is not permission to grant the access.
14. Company Information Must Stay Within Approved Systems
Employees must know where company information is being sent before submitting it to an AI system.
If an AI service stores, processes, or transmits information outside company-controlled systems, the service must be approved for that type of information.
Employees must not use personal AI accounts to process confidential company information.
Employees must not assume that an AI system is safe for company information simply because the system is widely used or has security features.
The specific company account, integration, and configuration must be approved.
15. AI Activity Must Be Auditable
Approved AI integrations with sensitive company systems should maintain appropriate logs.
The company should be able to determine:
Who initiated the operation
Which AI system performed it
What information it was permitted to access
What actions it performed
What systems it contacted
What changes it made
When the operation occurred
AI access that cannot be monitored or audited should not receive broad access to sensitive company systems.
16. AI Systems Must Have a Kill Switch
Approved AI integrations must have a method for quickly disabling access.
If an AI system begins accessing unexpected information, attempting unauthorized actions, generating unusual network traffic, or otherwise behaving outside its approved scope, its access must be disabled.
Employees should not attempt to allow the AI to continue operating while they determine what it is doing.
The first response is to stop the activity and report it.
17. Report AI Security Incidents
Employees must immediately report:
Accidental submission of confidential information to an unapproved AI system
Accidental exposure of credentials to an AI system
Unexpected AI access to company information
Unexpected changes made by an AI system
Unauthorized AI integrations
Large or unusual data transfers
AI behavior that appears to bypass company controls
Employees should not attempt to conceal an incident or delete evidence of what occurred.
The company needs to know what information was exposed and what systems were accessed so that it can contain the problem.
18. AI Training Is Required for Sensitive Access
Employees who receive access to approved AI integrations involving company data must complete company AI training.
The training will cover four basic concepts:
AI can be wrong.
An AI response can sound certain and still be incorrect.
Access is authority.
Giving an AI system access to a database gives that system the ability to retrieve information from that database.
More data is not automatically better.
AI should receive only the information required for the task.
The source system remains authoritative.
CRM information should be verified in the CRM before it is used for a material business decision.
Employees do not need to understand the technical implementation of AI security to follow these rules.
They do need to understand what information an AI system can access and what it is allowed to do.
19. The External AI Test
Before submitting company information to an AI system, employees should ask:
"Would I send this exact information to an external company that I do not control?"
If the answer is no, the information must not be submitted to an unapproved AI service.
If the business need requires AI processing of that information, the employee should use an approved company workflow or request approval for a new workflow.
20. Responsibility
AI is a tool used by the company.
It is not an employee, decision-maker, system administrator, or owner of company information.
Employees remain responsible for the work they perform with AI.
Managers remain responsible for ensuring that their teams use approved AI systems and follow this policy.
Technical teams are responsible for implementing appropriate access controls, monitoring, isolation, and approval mechanisms for AI integrations under their control.
The company may restrict, suspend, or remove AI access when an employee or AI system violates this policy.
Use AI Without Giving Away the Farm
The goal of this policy is not to slow down AI adoption. AI can be extremely useful, and we should use it where it can make the company better and more efficient. The goal is to make sure that using AI does not require us to trust the AI with more access, data, or authority than it actually needs. We should assume that mistakes will happen and design our systems so that those mistakes are contained.
The company does not need to assume that AI will always behave correctly. We need to ensure that an AI system cannot cause unacceptable damage when it does not. Give AI the minimum data and authority required to do the job. Keep company systems behind access controls. Keep people responsible for decisions. If you have questions, concerns, or ideas about how we can use AI safely and effectively, please comment below and start the conversation.