How to Set Your Own Rules for AI at Work
Your company has an AI policy, or it doesn’t, and either way you are still making a dozen small judgment calls a day that no policy document addresses: is this email too sensitive to paste, does this deliverable need a disclosure line, did I actually read what came back before I sent it. A team policy sets the outer boundary. It does not make these calls for you.
Most people handle this by improvising each time, which means the answer depends on how rushed you are that particular afternoon. A short personal rule set, three or four sentences you actually follow, closes that gap without waiting for anyone else to write a policy.
A Team Policy And A Personal Rule Are Not The Same Thing
A team policy answers “what is allowed here.” Your personal rules answer “what do I actually do, every time, without having to think about it.” The policy might permit a tool for a category of work; your rule decides whether this specific email fits that category on a Tuesday afternoon when you’re behind. You need both, and the personal version is the one that is missing for most people, because it feels too small to write down.
Three Rules Cover Almost Everything
You do not need a long document. Three decisions, made once and written down, cover the situations that come up daily.
What goes where. Decide, in advance, which categories of text, client names, financial figures, anything under NDA, personal information, never go into a public AI tool, and which tool you use for text that does need to stay off public services. Making this decision once removes the on-the-spot judgment call that is easiest to get wrong when you’re rushed.
When you disclose. Decide the threshold in advance: anything published, anything a client relies on, anything carrying your name as the sole author. Below that line, you don’t disclose and don’t need to think about it each time.
What you check before sending. One concrete review step, not “I’ll look it over.” Compare the rewritten version against your original point by point, or read the whole thing aloud, whatever actually catches errors for you, and do it every time, not just when something feels risky.
A Rule You’ll Actually Follow Is Specific
Before:
I try to be careful about what I put into AI tools and I always check things before sending, especially for important stuff.
After:
Client names, figures, and anything under NDA never go into a public AI tool, they go into the local rewriter only. I disclose AI assistance on anything published or client-facing, nothing else. Before sending, I compare the result to my original line by line, every time, not just when it feels important.
The first version sounds responsible and commits to nothing checkable. The second names the categories, the threshold, and the exact check, so on a rushed Tuesday there is nothing left to decide.
Write It Down Somewhere You Will Actually See It
A rule you keep in your head erodes the first time you’re in a hurry. Put it somewhere you pass through daily: pinned in your notes app, the top of your task list, a saved Context you load before drafting anything sensitive. The habit that matters is not remembering the rule, it’s not having to remember it, because it’s already in front of you.
This gets easier with a team policy behind it rather than instead of it. See how to write an AI use policy for a small team and BYO AI policy for teams if your team doesn’t have one yet, and is it safe to paste work emails into ChatGPT for the specific question your “what goes where” rule is answering. The habit of actually checking output before it goes out is worth its own read too: see keeping a human in the loop when AI drafts.
None of this is hypothetical caution. Reporting on a 2025 enterprise data security study found that a large majority of employees using generative AI tools copy and paste material directly into them, much of it from personal, unmanaged accounts their employer cannot see, let alone control. A personal rule is the only thing standing between you and that pattern on any given afternoon. Read the coverage of the report for the numbers.
A Wrivio Context For Your Own Rules
Turn your three decisions into something you load before drafting anything sensitive, rather than a rule you’re relying on memory for.
Before rewriting, remind me: client names, figures, and anything under NDA stay out of public AI tools. Disclose AI assistance only on published or client-facing work. Flag if this draft looks like it should go to local processing instead of cloud. Keep every name, date, figure, and commitment exactly as written.
Press Ctrl+Shift+Space, paste the draft, and check the diff, then check it again against your own rule, not just against the source text.
Common Questions
Do I need a personal AI rule if my team already has a policy?
Yes, a policy sets the outer boundary but rarely tells you what to do with the specific message in front of you right now, which is what a personal rule is for.
What is the single most useful personal rule to start with?
A firm line on what never goes into a public AI tool, since that decision made in advance prevents the mistake that is hardest to undo.
How often should I revisit my own rules?
Whenever your work changes meaningfully, a new client type, a new tool, a new category of sensitive data, otherwise a rule set that’s working doesn’t need frequent rewriting.
Should my personal rules be stricter than the team policy?
They can be; a policy sets a floor, not a ceiling, and being more cautious than required with your own judgment calls costs little.
What if I don’t have time to check every AI-assisted draft?
Build the check into the rule itself as a fixed, short step, comparing line by line or reading aloud, so it takes the same few minutes every time instead of becoming optional when you’re busy.
Make your own review step easier to actually follow, with local processing for anything sensitive: Download Wrivio for Windows.
Read Next
How to Write a Message Supporting a Decision You Argued Against
The gap between disagree and commit and quiet sabotage is what you write next. A structure for backing a decision in writing without erasing your objection.
How to Write a Message Correcting Your Own Mistake
You sent the wrong number, missed a deadline, or broke something. How to own it in writing in a way that rebuilds trust instead of drawing it out.
How to Ask a Coworker to Redo Work Without Friction
The work came back wrong and you need it done again. How to ask for a redo that fixes the work without bruising the person or slowing them down next time.
Keeping Confidential Drafts Out of AI Browsers
Agentic browsers act inside your logged-in sessions, which is exactly why they are risky for confidential text. A practical guide to keeping drafts safe.
This article is filed underWorkplace Writing, which has 132 articles.