Artificial intelligence, in the forms this policy governs, produces output by predicting likely content from patterns in the data it was trained on. Unless it is connected to a live source, it is not looking anything up, and it has no way to check what it produces against a source of truth.
Fluency is not accuracy. A wrong answer arrives sounding exactly like a right one, and the system gives no signal that anything is off. This is how these tools behave normally. It is not a fault or a sign that something has gone wrong.
Output quality follows input quality. General instructions produce general output. Specific instructions, real context, and a clear statement of what correct looks like produce something usable.
Everything you type into an AI tool leaves your control the moment you send it. It travels to a vendor, is processed on their systems, and may be retained. Approval does not undo that. An approved tool is one the Company has assessed and accepted for specific data and specific uses; it is not a tool you can put anything into.
So there are two separate questions, and both have to be answered before you paste anything. Is this tool approved for this use? And is this data allowed in a prompt at all?
The registry entry for each approved tool states what it may be used for and what is prohibited in it. Those prohibitions are the operative limit. Where an entry is silent, the list above still applies.
Two habits make the rest easy. Before you paste, read what you are about to paste, not what you think it is. And if you are weighing whether something is sensitive enough to matter, that hesitation is the answer: leave it out.
The Human Ownership Standard, also referred to as No AI Slop, is the standard this policy applies to every AI-assisted output. Artificial intelligence is a tool, and the individual who uses it is accountable for the result.
Any output produced with AI assistance that carries your name, your team's name, or the Company's name belongs to you, not to the AI system. Output that has not been read, understood, and confirmed accurate is not ready for use.
Ownership of AI-assisted work requires all five of the following:
- Read the output in full, not a summary or excerpt.
- Independently verify material factual claims.
- Edit the output to reflect the Company's voice and the facts as known.
- Remove anything that cannot be verified or is not yours to stand behind.
- Be able to defend the output if questioned: understanding what it does and why, verifying it behaves as intended, and accepting accountability for the outcome.
Covered people. All employees of the Company in every department, including leadership. All contractors, consultants, temporary workers, and agents performing work on behalf of the Company. All third parties who access organizational systems or data while providing services.
Covered systems. Generative AI producing text, images, code, audio, or video. Agentic AI taking autonomous actions. Analytical and decision-support AI embedded in software platforms. AI features within approved applications. Custom or internally developed models.
Six principles govern any situation the policy does not explicitly address:
| Principle | What it requires |
|---|---|
| Human ownership | Every AI output that represents or affects the organization has a named human owner before use. |
| Least privilege | AI gets the minimum access needed for the specific approved task. |
| Transparency | Disclose AI use where the policy, a contract, a regulation, or professional expectation requires it. |
| Proportionate risk | Controls match risk. Low-risk use gets light oversight; high-risk use gets rigorous review. |
| Continuous oversight | Approval today is not approval forever. Tools and access are reviewed on a set cadence. |
| No silent agents | Autonomous action requires documented authorization, defined scope, logging, and human interrupt. |
Different output types carry different minimum review standards. These supplement, and do not replace, the Human Ownership Standard.
| Output type | Minimum review |
|---|---|
| External communications | Full read and edit by the named sender, who executes the send personally. |
| Legal or contractual documents | Full review plus legal sign-off. Attorney review for anything legally binding. |
| Financial analyses and reports | Full review plus numerical verification, with written attestation on file. |
| Code and technical artifacts | Functional testing by a competent reviewer before use. No autonomous merge or deploy. Deployment requires explicit human action. |
| Regulatory and compliance filings | Full review plus sign-off by the accountable manager for that filing. |
| Presentations and board materials | Full review by the presenter, who is accountable for every claim. |
Disclosure is required for external documents submitted to regulators, courts, or government agencies including the FAA and TSA; client-facing deliverables where the engagement agreement specifies it; published content where platform or industry rules require it; and internal communications where a material business decision rests on AI-generated analysis.
Violations are handled consistently and progressively. Deliberate violations, and violations causing material harm, may bypass steps up to and including termination, at the discretion of the President and the AI Steering Committee. This framework supplements existing disciplinary policy rather than replacing it.
| Behavior | First | Second | Third |
|---|---|---|---|
| Using an unapproved AI tool | Documented coaching. Access suspended pending review. Intake form required. | Written warning. Access tier downgrade. | Escalation to the President; potential termination. |
| Distributing unreviewed AI output | Documented coaching. Remedial training within 10 days. | Formal written warning. Manager notified. | Escalation to the President. |
| Sharing confidential or regulated data in an AI prompt | Incident report filed. Mandatory security training. | Written warning. Access suspension pending review. | Escalation to the President and External Legal. |
| Non-completion of required training | Access suspended until completion. | Written warning. | Escalation to the President. |
| Deliberate policy misrepresentation | Immediate escalation to the President and External Legal. | ||
Exceptions. A written request to the CISO stating the provision at issue, the business justification, the duration requested, and the compensating controls. Exceptions cap at 90 days and renew only by re-approval. Every exception is recorded in the Exception Register.
Knowledge Check
Complete all seven sections above to unlock the assessment
Complete all 7 content sections to unlock the assessment.