Free tools Windows power users keep installed
One-click scans. No signup required.
Govern employee use of generative AI with clear rules, named owners and controls that match the task’s risk. Approve tools and use cases before work data is entered; specify what information employees may share, when a person must verify or approve output, and how to report problems. Then train staff, monitor whether the controls work and revise them as tools and work practices change.
Set ownership and keep an inventory
Start by defining who and what the policy covers: employees, contractors, devices, work accounts and work activities. Make clear that a tool’s availability does not itself authorize its use for organizational work.
Name an executive risk owner and operational owners from the functions involved in your organization, such as IT or security, privacy, legal, HR, procurement and business teams. Assign specific responsibility for approving tools and use cases, assessing risk, handling incidents, maintaining the inventory and reviewing the policy. NIST’s AI Risk Management Framework (AI RMF) treats governance as a continuing activity across the AI lifecycle, with documented roles, communication and leadership accountability.
Keep an inventory of approved tools and material use cases. Record enough information to identify what each system does and who is accountable for it:
#1 Best Overall
- Tool and provider, intended purpose, approved users and approval owner.
- Data categories employees may enter, along with integrations and access to organizational systems.
- Risk assessment, required human oversight and applicable restrictions.
- Approval date, review date and any conditions that would trigger reassessment or retirement.
Include generative AI embedded in software already used at work, not just stand-alone chatbots. An integration can change what information a system can access and therefore what needs review.
Write rules employees can apply to real tasks
A policy should answer practical questions in plain language. Employees need to know which tools and uses are approved, what data is permitted in each tool, when output must be checked, who makes consequential decisions and how to raise a concern. NIST’s Generative AI Profile recommends acceptable-use policies and guidance for different human-AI arrangements; adapt the rules to the actual service and work context.
Rank #2
- Approved tools: Name the approved services and provide a route to request a new tool or use case. Explain that approval for one tool or purpose does not automatically cover another.
- Data: Specify which public, internal, personal, confidential, regulated, employee and customer information may be entered into each approved service. If a category is not explicitly permitted for that tool, employees should not enter it until they receive approval.
- Permitted and restricted tasks: State which tasks may use AI assistance, which require prior review, and which are not allowed under the policy. Explain how to escalate an unusual or high-consequence use.
- Verification: Tell employees what they must check before relying on or sharing output. Depending on the task, this may include factual claims, calculations, citations, code, generated content or whether the output is suitable for its intended audience.
- Human authority: Identify decisions that require an accountable human reviewer, who may approve them and who remains responsible for the final decision.
- Disclosure: Explain when employees must identify AI assistance under organizational policy, law, customer terms or professional practice.
- Reporting: Provide a clear channel for suspected data exposure, harmful or unreliable output, errors and policy violations.
Make the rules specific enough to use at the point of work. For example, an employee should be able to determine whether a particular approved tool may receive a particular category of information, and whether the output needs review before it is sent to a customer or used in a decision.
Match controls to the use, not just the tool
NIST recommends risk management proportionate to organizational risk tolerance; it does not prescribe one employee-use tier system. An organization can use local categories to make approvals easier to apply, provided each use is assessed on its own context. The table below is one practical model, not an official NIST classification.
Rank #3
| Local category | Example policy treatment | Questions to resolve |
|---|---|---|
| Routine assistance | Allow approved, low-impact tasks under standard tool and data rules. Require employees to check output before relying on it. | Is the input permitted? Could an error cause harm? Is the output being used in a way that needs review? |
| Controlled use | Require prior approval and documented safeguards for sensitive data, external-facing work, broad system access or uses where an error could have significant consequences. | Who may be affected? What happens if the result is wrong or biased? Who reviews it, and can that person override it? |
| Prohibited or exceptional use | Prohibit uses that conflict with organizational requirements, or require explicit review by appropriate accountable owners before any exception. Do not let an employee infer permission from tool access. | Is the use lawful and consistent with organizational commitments? Is there a qualified owner and meaningful oversight? Can the risk be controlled at all? |
For each proposed use, consider the task, the people affected, the type and sensitivity of input data, the consequences of an incorrect or biased result, the amount of human oversight, the provider’s data terms and the system’s access to other information. Also consider whether the organization can monitor the use and respond if something goes wrong. Stronger potential impacts call for stronger approval, testing, documentation and review.
Do not treat confident-sounding output as evidence that it is correct. NIST’s Generative AI Profile identifies confabulation among the risks organizations should address. Set verification requirements according to the consequence of error and the employee’s ability to check the result, rather than applying the same review rule to every task.
Rank #4
Review providers, data handling and integrations
Before employees use a third-party service for organizational work, review the intended purpose and how the service handles the information it receives. NIST’s Generative AI Profile discusses due diligence and third-party controls, including procurement review, service-level agreements and assurance materials. Depending on the use, a review can cover:
- What information the service collects, retains, deletes or may use to improve its products, and whether those practices meet organizational requirements.
- Security controls, access management, provider transparency and incident-notification commitments.
- Contract terms, including service levels and relevant assurance materials.
- Intellectual-property concerns and any limits on using or sharing generated output.
- Connections to internal files, code, email or other systems, and the scope of information those connections expose.
Record the review and its conditions in the tool inventory. Decide who will reassess a service if the provider changes its terms, an integration expands, the approved purpose shifts or a concern emerges. Include a safe way to disable access and decommission a service without losing track of connected workflows or data.
Best Value
Train employees and monitor whether the rules work
Give employees practical examples drawn from their work: what can be entered into each approved tool, how to verify an output, when disclosure is required and what to do when a result is uncertain. Provide role-specific guidance for managers, approvers and reviewers, and train partners or contractors where they have responsibilities under the policy. NIST’s AI RMF and Generative AI Profile emphasize training that fits people’s roles.
Set a review schedule and revisit the policy after a material incident, a significant new integration or a change in applicable requirements. Check whether employees understand the rules, whether the approved-tool inventory is accurate and whether the safeguards are addressing the risks identified. Monitoring and review should have named owners, rather than being left to an informal expectation that someone will notice a problem.
An example of this work appears in the EEOC’s September 20, 2024 compliance plan: it reports that agency leadership sent employees and contractors a communication on March 21, 2024 outlining generative AI risks and existing technology policies, and describes an AI evaluation process and attention to staff expertise and professional development. That is an agency example, not a legal template or a requirement for all employers.
Keep the policy within its proper legal scope
NIST describes the AI RMF as voluntary. Its recommendations can help organizations design governance, but they do not determine the legal obligations for a particular employer, jurisdiction or high-impact use. Have qualified counsel review requirements that apply to your location, workforce, industry and use case. NIST released its Generative AI Profile on July 26, 2024; consult NIST’s published materials for the framework and profile when developing or updating internal rules.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

