Somebody in your organisation has been meaning to write the AI section of the acceptable use policy for about eight months. This is that section, plus the slides, plus the awkward message you have to send when someone has already done it.
Public domain, like the share images. No attribution, no sign-up, no permission needed. Change every word if you want to.
Drop this into an acceptable use policy, an IT policy, or a staff handbook. Replace the bracketed parts. It is deliberately short — a policy nobody finishes reading is a policy nobody follows.
Do not paste customer or employee data, credentials or keys, source code, contracts, financial information, or health and legal records into public AI tools. This includes ChatGPT, Claude, Gemini, Copilot and any other assistant not covered by a written agreement between [ORGANISATION] and the vendor. A prompt is a disclosure. Once text has been sent, it cannot be recalled, and depending on the tool it may be stored, reviewed by a person, or used to train a future model. If you are unsure whether something is sensitive, that uncertainty is the signal: ask [TEAM] before you send it. To see what is in a block of text before an AI tool does, use the checker at dontpastethat.com/check-a-paste — it runs in your browser and sends nothing anywhere. If you have already pasted something you should not have, tell [TEAM] today. Reporting it promptly is the correct action and is not treated as a disciplinary matter in itself. Delay is what turns a small problem into a notifiable one.
The last paragraph is the one that does the work. Most AI policies are written entirely in prohibitions, which means the first person to make a mistake has every incentive to say nothing — and a disclosure nobody reports is a disclosure nobody can contain. If you cut anything, don't cut that.
The whole thing, in the time you actually get in an induction. Pair each with a share image if your deck wants a picture.
IF YOU WOULDN'T POST IT ON OUR PUBLIC WEBSITE, DON'T PASTE IT INTO A PUBLIC AI TOOL. - It leaves the company the moment you press send. - There is no unsend. - This applies to your personal account too.
NEVER PASTE 1. Customer and employee data — names, emails, IDs, account numbers 2. Credentials and keys — passwords, API keys, tokens, connection strings 3. Source code and internal documents — proprietary code, roadmaps, decks 4. Contracts and financials — agreements, pricing, unreleased numbers 5. Health and legal records — anything regulated or privileged Source code is the one with real exceptions. Ask rather than assume.
DO THIS INSTEAD 1. Redact first. The AI helps just as well with [CUSTOMER] as with the real name. Ask about the pattern, not the person. 2. Use the approved tool. If we provide one with data protections, use that one — not your personal account. 3. Not sure? That's the signal. Ask [TEAM]. Check any text before you send it: dontpastethat.com/check-a-paste Test yourself in five minutes: dontpastethat.com/paste-test
Someone has just pasted a contract into a chatbot in a shared channel. The instinct is to write something stern. Don't — the goal is that they tell you next time, and shame is the single most reliable way to make sure they don't.
Hey — heads up, that one had customer details in it. Public AI tools keep what you send them, so best not to run that through it. No drama, easily done. If it's useful, there's a checker that tells you what's in a block of text before you send it, and it runs entirely in your browser: dontpastethat.com/check-a-paste
That block had a live key in it — can you rotate it now rather than later? Treat it as disclosed, because it has been. Rotating takes ten minutes. Working out whether it was actually exploited takes weeks and never reaches a confident answer, which is why rotating first is the cheaper move every time. Once it's rotated, let [TEAM] know so it's logged. Nothing else needed from you.
Subject: One thing about AI tools before you start Welcome aboard. One request that isn't in any of the paperwork: be careful what you paste into public AI tools. Anything you send leaves [ORGANISATION], and it can't be recalled. The short version of what not to send, and what to do instead, is here — it takes about two minutes to read: dontpastethat.com There's also a five-minute test if you'd like to check your own instincts. Most people score lower than they expect, including the people who wrote the policy: dontpastethat.com/paste-test Anything you're unsure about, ask [TEAM] first. Asking is always fine.
The paste test is ten scenarios, one at a time: would you paste this? It scores out of ten and produces a card you can download.
It is built to teach judgement rather than a reflex. Three of the ten are perfectly safe, and the person who answers "wouldn't paste" to everything scores between five and seven — which is the lesson. "Never use AI for anything" is not a policy anyone follows; knowing which three of ten are fine is what people actually need.
Staff awareness activity is an evidence requirement under ISO/IEC 27001 A.6.3, SOC 2 CC1.4, Essential Eight maturity reporting, and the "appropriate organisational measures" language in most privacy regimes. The score card carries the date and the result, so it can go in a training folder alongside everything else.
Describe it accurately, which means describing it narrowly. This is evidence that a person completed an awareness activity on a given date. It is not accredited training, it is not a certification, and it does not by itself satisfy any control. Anyone who writes "certified" on it has created a worse problem than the one they were solving.
Nothing about a run of the test is recorded anywhere. The score exists in the page you are looking at and in the card you download — there is no server-side record, which also means there is no attendance report. If you need one, ask people to send you the card.
The link does more work in the places people already are than on a page they have to remember to visit.
Everything on this page is released under CC0 — public domain. No attribution, commercial use fine, and rewriting it in your own voice is encouraged rather than merely tolerated. Deliberately not CC BY: an attribution requirement nobody can satisfy inside an internal policy document would make ordinary use technically infringing, and this exists to be used.
One ask, not a rule: leave a link to dontpastethat.com somewhere in it. It is the only thing that turns a paragraph someone skimmed into a page they can actually read when they need it.