Sign in to watch this video
The written lesson, interview questions and practice are below — sign in to play the video lesson.
Sign inA good policy is short, specific, and enabling — not a legal wall of "thou shalt not." It tells people what they CAN do, with which tools, and the few hard lines they must never cross.
What a usable policy covers
- 1Approved tools + tiers (with data controls) — and which to use for what.
- 2Hard "never paste" list: customer PII, secrets, unreleased financials, NDA material.
- 3When human review is mandatory (anything customer-facing or shipped).
- 4Attribution + ownership — AI-assisted work is still the author’s responsibility.
- 5Where to share what works — prompts, wins, gotchas.
✕
The data line is non-negotiable
Under DPDP and most contracts, the company is still responsible for personal data even after it’s pasted into a third-party tool. Make the "never paste" list crystal clear and use enterprise tiers with data-use controls for real work.
✓
Enable, then guardrail
Lead with "here’s how to get value safely," not "here’s everything that’s forbidden." A policy people resent is a policy people route around.
Takeaway
Keep the policy short and enabling: approved tools, a hard "never paste" list, mandatory-review cases, ownership, and a place to share learnings.