The AI paragraph for your policy

Paste it.

Drop this into an acceptable use policy, an IT policy, or a staff handbook. Replace the bracketed parts and change any word you like.

Deliberately short. A policy nobody finishes reading is a policy nobody follows.

The paragraph

Acceptable use — public AI tools
Do not paste customer or employee data, credentials or keys, source
code, contracts, financial information, or health and legal records
into public AI tools. This includes ChatGPT, Claude, Gemini, Copilot
and any other assistant not covered by a written agreement between
[ORGANISATION] and the vendor.

A prompt is a disclosure. Once text has been sent, it cannot be
recalled, and depending on the tool it may be stored, reviewed by a
person, or used to train a future model.

If you are unsure whether something is sensitive, that uncertainty is
the signal: ask [TEAM] before you send it. To see what is in a block
of text before an AI tool does, use the checker at
dontpastethat.com/check-a-paste — it runs in your browser and sends
nothing anywhere.

If you have already pasted something you should not have, tell [TEAM]
today. Reporting it promptly is the correct action and is not treated
as a disciplinary matter in itself. Delay is what turns a small
problem into a notifiable one.

If you cut anything, don't cut the last paragraph

Most AI policies are written entirely in prohibitions. The predictable result is that the first person to make a mistake has every incentive to say nothing — and a disclosure nobody reports is a disclosure nobody can contain.

The clocks that matter run from discovery, not from the mistake: 72 hours under GDPR, 60 days under HIPAA's breach rule. An organisation that hears about a paste on the day has options. One that hears about it in a regulator's letter has none.

Naming the reporting route is not softness, it is the control. Everything above it is advice; that paragraph is the only part that changes what happens after something goes wrong.

A shorter version, if the policy is already long

One-paragraph version
Don't paste customer or employee data, credentials, source code,
contracts or health and legal records into public AI tools — a prompt
is a disclosure and there is no unsend. Check anything you're unsure
about at dontpastethat.com/check-a-paste, or ask [TEAM]. If you've
already sent something you shouldn't have, tell [TEAM] today; reporting
it promptly is the right call and is not a disciplinary matter.

What to change before you use it

  • 1[ORGANISATION] and [TEAM]name the actual team, and if possible the actual channel. "Ask security" is a dead end if nobody knows where security lives
  • 2Name the approved tool, if you have onea prohibition with no permitted alternative gets routed around. If people have a sanctioned option, this paragraph is where they find out
  • 3Check the categories against your businessa law firm needs privileged material called out; a health service needs patient records first; a software company will want the source code nuance, which is genuinely "it depends" rather than "no"
  • Don't add "and any other confidential information"it reads as thorough and functions as noise. People comply with lists they can hold in their head

Where the categories come from

The five are the same five the rest of this site is organised around, each with a page explaining what counts and what to do instead. If someone pushes back on a line in the policy, that page is the answer — send it rather than arguing.

The licensing bit

Everything in this kit is released under CC0 — public domain. No attribution, commercial use fine, and rewriting it in your own voice is encouraged rather than merely tolerated. Deliberately not CC BY: an attribution requirement nobody can satisfy inside an internal policy document would make ordinary use technically infringing, and this exists to be used.

One ask, not a rule: leave a link to dontpastethat.com somewhere in it. It is the only thing that turns a paragraph someone skimmed into a page they can actually read when they need it.