You will be able to find your company's AI rules, apply them to your own tasks and ask the right questions where they are unclear.
If you use an AI assistant for work, sooner or later you need to know what your employer allows you to put into it. A straight answer can take some effort to get. Company AI policies vary a lot. Some employers have a long formal policy, some sent a short email once, and some have nothing written down.
Start by finding the policy, in whatever form it exists, or ask someone for it.
Hafiz, an invented example, works at a firm and asked his manager what it allowed for AI use. The manager forwarded an email sent the previous year. It told staff they could use the company's business assistant for internal drafting, that free tools were not to be used for client work, and that they should "use common sense" with personal data. The firm had nothing else in writing, and Hafiz finished reading it with more questions than he had when he started.
Many companies now have written rules on generative AI, and they tend to deal with the same four areas. Read yours with these in mind.
Approved tools are the ones the company has cleared for work. Often that means an assistant inside the office suite, such as Copilot in Microsoft 365 or Gemini in Google Workspace, running under work accounts. It can also mean a business plan of a standalone assistant. A tool missing from the list is usually not approved for work data, however popular or free it is.
The second area is banned uses, meaning tasks AI must not be used for. Typical ones are making decisions about people, for example in hiring or discipline, with no human review. Others are passing off AI output as professional advice and producing images of real people.
Third, a well-written policy sets out which data may go into which tool. The tiers might run like this: internal drafts can go into the company assistant, client data can go in only after redaction (taking out names and other identifying details first), and personal data such as NRIC numbers or health details goes into no tool at all.
The fourth area is disclosure: when you have to tell people AI was used, and who needs to be told.
Of everything a policy says, the point most worth keeping is that the rules change with the tool. An approved enterprise assistant is used under a contract your company negotiated, and an administrator controls its settings. Because of that, it may be cleared for material that should never be typed into a personal account. One piece of data can be fine in one tool and forbidden in another.
At Hafiz's firm, internal policy drafts are allowed in the company assistant and in no personal account. Whether the same draft is permitted depends only on where he types it.
So when a task comes up, ask "may I put this data into this tool?" rather than "may I use AI for this?" Keep work data in approved tools, even when a personal one would be easier. The convenient option is often the wrong one. Your personal account may be on your phone, already open and better at the job, but if it is not approved for that data, you shouldn't use it for that data.
If you can't find any policy, don't put work data into any assistant until you have asked. Start with your manager. If your company has a data protection officer or an IT team, they will usually know whether a business plan exists and what it permits.
The way you ask shapes what you get back. "Can I use AI?" tends to get a shrug. A question like whether you may paste supplier email threads, with names removed, into the company's assistant to draft replies can be answered properly. Name the tools you want to use, the kinds of data involved and the tasks you have in mind, and take the tasks from your audit in lesson 1.4.
Hafiz wrote four questions about specific tasks and sent them to his manager. Four clear answers came back by email. Two were yes in the company assistant, one was yes after redaction, and one, about staff medical information, was a firm no in any tool.
Record every answer along with who gave it and when. A short written reply is best. When you get an answer in conversation, follow up with a one-line email setting out what you understood. Policies get revised and people change jobs, and a written note protects you if someone later asks why you handled something the way you did.
Some companies and clients expect to be told when AI was involved. Look first at your company policy. It might ask for a note in reports saying an assistant helped draft them, or it might ban AI on certain client deliverables entirely. Before using AI on work for a particular client, read that client's contract as well, since some contracts set their own terms on AI use.
Where there is no rule, think about what the person reading would expect. A colleague is unlikely to need telling that an assistant tidied the wording of an internal update. A client paying for a professional report from your team may well expect to know if large parts of it were drafted by AI. If they found out afterwards, it would hurt their trust far more than a short note would have.
If you are unsure, disclose. A line such as "drafted with the help of an AI assistant and checked by the author" costs nothing and settles the question.
Your next step is your own version of Hafiz's four questions. Find your company's AI policy, or ask for it, and write down what it says about tools, data and disclosure.
Find your company's AI policy or ask for it, and write down which tools are approved, which data is allowed in each, and any disclosure rules.
Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).