Benefits of Implementing Internal and External AI Policies for Your Business
AI utilization has dramatically increased in recent years. It is used in our daily lives and likely in your business, whether it was introduced formally or not. With growing regulatory attention and customer expectations around AI, two AI policies can empower your employees and build trust and confidence among your customers: an internal AI use policy that outlines acceptable use for your team, and an external AI use policy that describes your company’s philosophy and uses for AI. Simple, understandable, and easy-to-use policies can provide your employees with guardrails to use AI effectively and demonstrate your organization’s commitment to transparency and technological advancement.
The Growing Role of AI in Business
In the ever-evolving world of AI, your employees are likely already leveraging the technology within your business, and your customers are likely curious about how it affects them. Internal and external AI policies can promote effective and ethical use, reduce risk, and foster customer trust.
The Evolving AI Regulatory Landscape
AI governance is no longer just a best practice, it is increasingly a matter of legal compliance. At the federal level, agencies such as the Federal Trade Commission (FTC) have signaled heightened enforcement attention on AI-related claims, particularly around deceptive practices, algorithmic decision-making, and data use in AI systems. At the state level, legislatures nationwide are actively proposing and enacting AI-specific legislation, creating a patchwork of requirements that varies across jurisdictions. Colorado’s Automated Decision-Making Technology Act (ADMTA) (SB 24-205, as amended by SB 26-189), effective January 1, 2027, requires transparency and disclosure requirements on automated decision-making technology that influences consequential decisions in areas such as housing, healthcare and employment. Notably, ADMTA violations are treated as deceptive trade practices under Colorado law, with potential penalties of up to $20,000 per violation. Enforcement authority rests only with the Colorado Attorney General, as the statute provides no private right of action. Illinois has enacted laws addressing AI (Illinois Human Rights Act (Public Act 103-0804)), including provisions finding that civil rights violations occur when AI is used in employment or recruitment matters if notice is not provided or if it is used in a way that causes discrimination. Other states are considering similar measures addressing algorithmic discrimination, automated decision-making, and AI transparency. Organizations operating across multiple states should monitor developments in their specific jurisdictions, as regulation continues to evolve. Additionally, organizations operating in multiple nations should be mindful that non-U.S. frameworks, such as the European Union’s AI Act, may impose additional or differing compliance obligations on AI systems accessible abroad.
Why AI Policies Matter Today
As AI regulation continues to grow, proactive AI management provides both defensive and strategic value.
- Internal AI policies help organizations demonstrate compliance with emerging regulation, reduce litigation exposure, and establish defensible processes before an incident occurs.
- External AI policies serve a distinct but complementary purpose: they address organizational expectations, differentiate your organization in the marketplace, and create a foundation for customer trust.
- Together, these policies position your organization as a responsible AI adopter, an increasingly valuable competitive advantage as clients’ and regulators’ expectations regarding AI increase.
Internal AI Acceptable Use Policies
As AI becomes embedded in daily business operations, establishing clear internal guidelines is essential. An internal AI Acceptable Use Policy provides the framework your employees need to leverage AI tools effectively while protecting your organization from unnecessary risk.
What is an internal AI Acceptable Use Policy?
An AI Acceptable Use Policy (“AUP”) is a set of internal guidelines that describe how AI may be utilized by employees. AI AUPs serve three functions:
- Empowerment: Clear guidelines, expectations, and uses give employees confidence to utilize AI effectively.
- Protection: When employees know when and when not to use AI, as well as which AI platforms to use, data is better protected and risk is more effectively avoided.
- Accountability: Clear expectations on how decisions regarding AI are made within the organization help ensure AI growth occurs safely and in alignment with the organization’s goals.
What Should Be Included in an Internal AI Policy?
An internal AI AUP should provide simple, easy-to-understand guidance on what employees can use AI for. Information in an internal AUP should include:
- Definitions: With new and evolving technology, terms that are clear to engaged or technical employees may be confusing for newly adopting employees. Clear definitions of technical terms and key internal terms will ensure the AUP is understood by all team members.
- Permitted Platforms: With the number of AI models growing daily, a clear understanding of which platforms the company supports is important. An AUP should specify whether Large Language Models such as Claude or ChatGPT, AI tools in applications like Copilot, industry-specific AI platforms, or internal platforms are permitted for employee use.
- Acceptable Use Cases: Clearly laying out the use cases where AI can be applied in your organization will empower your people to use AI effectively while avoiding its use in situations where it can cause harm. Acceptable AI use often includes research, summarizing, analysis, or coding.
- Unauthorized Use Cases: Clearly outline what constitutes unacceptable AI use, which can include tasks involving private client or personal information, areas where discrimination can occur, or significant decisions requiring human judgment.
- How to Request New Tools: AI innovation often comes from curious or interested employees within your company. Providing a clear path for suggestions, ideas, and approval of new tools incentivizes your team to help the firm grow in a safe and organized manner.
- When Human Oversight Is Needed: Clearly outline areas in which human oversight is required for AI output. This could include hiring decisions, externally posted content, or specific customer recommendations.
- How Data Is Organized: One of the most common issues regarding AI usage is determining which categories of data may be used in which platforms. Clear guidelines on when, whether, and which AI platforms can receive public, internal, sensitive, or other forms of data will ensure employees keep the right content in the right platforms.
- Vendor AI Risk Assessments: Organizations today are engaging with AI in two primary ways: internal development of AI models and workflows, and use of third-party AI platforms such as Copilot, Claude, ChatGPT, and industry-specific platforms. An effective AUP should address how the organization safely and effectively utilizes both.
- Internal AI Risk Assessments: For internally developed AI, this includes prioritizing privacy and security into process development. For third-party tools, this includes establishing a vendor assessment process that evaluates data handling practices, security, consumer protections, and compliance certifications before integration.
External AI Policies
While internal policies govern how employees use AI, external policies communicate your organization’s AI practices to the world. An external AI policy addresses questions from customers and the public about how your organization deploys AI and handles their data.
What is an external AI policy?
An external AI policy is a public-facing statement that describes how your organization uses AI, what data practices support that use, and how your organization ensures AI is deployed responsibly. Unlike an internal policy, which guides employee behavior, an external AI policy is designed to inform and reassure customers, prospective customers, and the public.
How an External AI Policy Differs from Other Privacy Disclosures
Organizations may wonder whether an external AI policy is necessary given the existence of privacy policies, terms of use, cookie policies, and other data-related disclosures. While these policies address general data and privacy concerns, they typically do not address specific AI-related issues, including how AI systems make decisions, whether human oversight is provided, what safeguards prevent bias or discrimination, and how AI-generated outputs are verified. An external AI policy fills this gap by providing transparency about your organization’s AI-specific practices that traditional privacy disclosures were not designed to answer. As customers and business partners increasingly raise questions about AI usage, a dedicated AI policy demonstrates that your organization takes these concerns seriously and is invested in responsible use of AI.
An effective external AI policy builds trust and confidence when it is simple, understandable, and user-friendly. External AI policies achieve two primary goals:
- Provide Transparency: As a new technology, AI can create skepticism. When companies are honest about their AI usage, customers feel confident the company is using AI responsibly and can trust that they are not being deceived.
- Build Customer Trust and Confidence: Demonstrating that your organization is forward-thinking and thoughtful regarding AI usage shows clients that thorough and efficient results are top priorities.
What Should Be Included in an External AI Policy?
An external AI policy is an opportunity to reassure and impress current customers, prospective customers, and the public. A high-level, simple, and genuine explanation goes a long way to build trust.
- Company Philosophy: This provides a big picture to customers of how your organization is leveraging AI and doing so responsibly. The company philosophy can be as simple as a statement on how the organization’s mission, values, or goals drive AI use. Key elements include:
- AI standards within the organization: Describe how your organization will ensure AI use is conducted fairly, securely, ethically, and honestly.
- How the firm plans to ensure safe and responsible AI use going forward: With AI constantly evolving, describing the organization’s commitment to updates, monitoring, and auditing can showcase the firm’s ongoing commitment to ethical use.
- Who is accountable for ethical AI use: While AI is a valuable tool for your organization and clients, it is the people behind it who truly create the results and ensure its safe and responsible use. Highlighting thought leaders who drive innovation forward and ensure ethical oversight is a valuable way to demonstrate the organization’s AI responsibility.
- Disclosure on AI Usage for Clients: This part of the policy describes how your business is utilizing AI both directly with customers and in background processes.
- Direct client interaction: Describe when and whether AI directly connects with customers, website visitors, or others—whether through tailored recommendations, generated content, or decision-making tools.
- Internal assistance: While disclosure of background processes is not universally required, proactive transparency about how AI assists employees is an opportunity to demonstrate innovation and build trust.
- Data usage for training: A common question organizations receive from customers is whether the data they provide is used to train AI models. An external AI policy should directly address this concern.
- Data usage in AI model training: State whether customer data is used to train AI models. If data is used for training purposes, describe the circumstances and how customers can opt out should they choose.
- Third-party AI evaluation: If your organization uses third-party AI tools, describe how you have vetted those providers’ data procedures. Customers want assurance that their data is not being shared with or used by third parties in unexpected or risky ways.
- Data retention procedures: Explain how long AI-related data is retained and the process for data deletion upon request.
How to Get Started
Outlining organizational rules and philosophies regarding AI can seem daunting. Small actions and thoughtful reflection are a great starting point.
- Assess current AI usage: Understanding what AI tools are in use and how they are being used is the first step to a thoughtful AI policy.
- Identify gaps: Are certain areas of AI use riskier than others? Is sensitive data interacting with AI today? Categorize AI usage from most concern to least concern.
- Discuss AI use internally: How do your organization’s goals, values, or mission guide your AI journey?
- Draft both internal and external policies: It can be helpful to review existing data, privacy, or security policies already in place and ensure they are aligned.
- Communicate with employees: Transparency and awareness among your team help ensure the policies lead to the goals and outcomes your organization is looking for.
- Be prepared for change: AI is changing rapidly, and your business should be prepared to change as well. AI policies should be considered living documents; quarterly review ensures they stay up to date.
- Policy Rollout: Once policies are complete, conduct training sessions so employees understand the guidelines and feel confident using AI tools.
- Re-certification and Updates: Whether quarterly, annually, or when significant policy updates occur, a process of re-certification and updates to your policies helps maintain compliance awareness and reinforces accountability.
Conclusion
AI is constantly evolving, and each business is different. There is no single right way to govern or describe your organization’s AI use and philosophy. While perfection is not necessary for an AI policy, taking action—no matter how small—will help ensure your organization is better prepared for the changes ahead.
Koley Jessen is committed to staying informed about developments in Artificial Intelligence and will provide guidance as new information emerges. If you have questions about your business’s Artificial Intelligence usage or data privacy, please contact a member of Koley Jessen’s Data Privacy and Security Practice for assistance.
Special thanks to Summer Associate Jack Cohen for his contributions to this article.
This content is made available for educational purposes only and to give you general information and a general understanding of the law, not to provide specific legal advice. By using this content, you understand there is no attorney-client relationship between you and the publisher. The content should not be used as a substitute for competent legal advice from a licensed professional attorney in your state.