Safe, Responsible, and Effective Use of AI at Work
A guidance note for organizations on AI adoption, the regulatory landscape now in force, minimum governance controls, and six documented incidents and lessons.
Eighty-eight percent of organizations now use AI in at least one business function. Fifty-one percent have already logged at least one AI-related incident, most commonly a fabricated fact treated as verified.
McKinsey's 2025 State of AI survey covered 1,993 respondents across roughly 105 countries. Two-thirds of adopting organizations remain in pilots rather than enterprise-wide use, and only 6 percent report AI contributing more than 5 percent of enterprise earnings before interest and taxes. McKinsey traces the distance between adoption and value to an operating-model and governance gap. High-maturity organizations that keep AI projects running for three or more years at more than double the rate of low-maturity organizations, and report average cost savings of 15.2 percent alongside productivity gains of 22.6 percent. The organizations capturing this value built the governance framework first.
This note highlights a minimum standard for how an organization and its staff use AI tools at work, written to be adopted directly into internal policy. It applies to every organization that permits, tolerates, or has not yet addressed employee AI use, regardless of size or sector. It does not constitute legal advice.
Categories of AI tools
A policy that treats every AI tool as one category carries either too much friction for the low-stakes cases or too little control for the high-stakes ones. The tools in daily use fall into six distinct groups.
General-purpose assistants
Chat tools such as ChatGPT, Claude, and Gemini that draft, summarize, translate, and answer questions.
Low to highEmbedded AI features
AI functions built into productivity suites and CRM systems staff already use, often enabled by default.
Low to mediumCoding and agentic dev tools
Tools that write, edit, and can execute code, sometimes acting on live systems without step-by-step approval.
High if connected to productionAutonomous / agentic systems
Systems that plan and execute a sequence of actions, searching, filing, sending, updating records, with limited or delayed human review.
HighAutomated decision-making tools
Systems used to screen, rank, score, or decide outcomes for people: hiring, credit, benefits eligibility, customs valuation.
High, directly affects peopleDomain-specific AI tools
Purpose-built tools for legal research, financial analysis, clinical support, or ESG data processing.
Medium to highWhat is already binding law
No single law governs AI at work globally. An organization operating in more than one jurisdiction is very likely already facing several overlapping regimes.
The EU AI Act
Prohibited practices and AI-literacy obligations applied from 2 February 2025. Obligations for general-purpose AI model providers followed on 2 August 2025. Transparency obligations for any organization whose branded chatbot interacts with people applied from 2 August 2026. High-risk obligations under Annex III, covering recruitment, credit scoring, law enforcement, education access, and border and customs control, were due 2 August 2026. A Digital Omnibus reached provisional political agreement in May 2026 to defer that deadline to 2 December 2027, with formal adoption still pending. Maximum penalties reach €35 million or 7 percent of global turnover.
Employment and automated decision-making rules
No single federal AI law exists. New York City's Local Law 144 has required independent bias audits and public disclosure for automated employment decision tools since July 2023, with penalties of $500 to $1,500 per violation assessed per day. Colorado replaced its original AI Act with a narrower transparency regime, SB 26-189, in May 2026. California's automated decision-making technology regulations took effect 1 January 2026. Illinois, Texas, and Connecticut each add their own notice, consent, or disclosure requirements. These laws apply based on where the affected candidate or employee is located, not where the employer is headquartered, so a firm with remote staff across several states should comply with the multiple state requirements.
Other regulatory developments
Voluntary frameworks increasingly treated as the baseline of reasonable practice, and a set of national strategies still being built.
Singapore's Model AI Governance Framework for Agentic AI
Launched 22 January 2026, the first governance framework built specifically for autonomous AI agents. Compliance is voluntary; accountability for the agent's actions is not.
OECD AI Principles
Adopted by more than 40 countries as a voluntary reference point on human-centred values, transparency, robustness, and accountability.
ISO/IEC 42001:2023
The first certifiable standard for an organizational AI Management System, requiring defined AI objectives, AI-specific risk assessment, proportionate controls, and measured performance.
African Union Continental AI Strategy
Phased from 2025 to 2030. Phase I (2025-2026) builds governance frameworks, national strategies, and institutional capacity, with risk minimization as one of five core pillars.
Rwanda adopted the first national AI policy in Africa in 2019. Kenya's has a National AI Strategy 2025-2030 and published draft AI policy in 2026. AI-specific regulation does not replace existing data protection law: an AI tool processing personal data remains subject to the applicable regime, such as the EU's General Data Protection Regulation, independent of whichever AI-specific rule also applies.
Elements of a governance policy
These elements are the minimum an organization needs, regardless of size.
Named accountability
A specific person, or above a certain size a small cross-functional group, owns AI governance. "The AI" is never accountable for an outcome.
Task risk classification
Classify tasks by structure (is there a single checkable correct answer) and stakes (who bears the cost of an undetected error).
Acceptable use policy
Covering approved tools, data classification, a verification requirement, a disclosure standard, an escalation path, and proportionate consequences.
Approved tools and data tiers
A current written list of which products and subscription tiers are approved for which categories of data. Naming a vendor is not enough without naming the tier.
Vendor risk management
Confirm in writing where data is processed, whether it trains the vendor's models, how long it is retained, and which certifications the vendor holds.
Incident reporting
A low-friction path for staff to report a suspected data exposure or fabricated claim, one that does not itself discourage reporting.
Training and review
Staff complete AI-use training before tool access is granted, and the policy is reviewed at least every six months.
What this means day to day
Actions to take
- Use only the tools and tiers your organization has approved for the category of information you are working with.
- Treat every AI-generated citation, statistic, or named fact as unverified until traced to an independent source.
- Classify the task before starting. If the output could reach a client, regulator, or affected individual, apply the higher level of review.
- Disclose AI assistance where policy or a client's expectations require it.
- Report anything that looks like a possible data exposure or a fabrication caught in time, even if it caused no harm.
Actions to avoid
- Pasting client-confidential, personal, or regulated data into an unapproved consumer AI tool.
- Treating a fluent, confident AI answer as verified because it reads correctly.
- Giving an agentic AI tool unsupervised access to a production, client-record, or financial system without an approval gate.
- Assuming "the AI did it" changes who is accountable for a document released under the organization's name. It does not.
- Letting an AI tool substantially determine an employment, credit, or benefits decision without the human review the law requires.
Minimum technical controls
Enterprise access, not personal accounts
An enterprise-licensed subscription covered by a data processing agreement, not a reliance on personal consumer accounts.
Data loss prevention tooling
Configured to warn or block regulated, confidential, or personal data before it enters an AI interface, not only log it after the fact.
Bounded agentic permissions
Any tool that can execute code, modify records, or send communications has permissions scoped explicitly to the task.
Audit logging
A log of which tool produced which output, when, and under whose account, sufficient to reconstruct an incident afterward.
Human approval gates
An explicit confirmation step before any AI-assisted action with external effect: sending, filing, publishing, or modifying a production system.
Backup and rollback protocols
Tested and independent of the AI tool itself, so an erroneous action can be reversed without depending on the system that caused it.
Documented Incidents
A common cause across all incidents is that controls were either missing or scoped too loosely for the task.
Samsung Electronics
Engineers pasted proprietary source code, a confidential meeting transcript, and defect-detection data into ChatGPT within a 20-day period. Samsung then banned generative AI company-wide.
Air Canada, Moffatt v. Air Canada
A website chatbot gave a customer incorrect information about bereavement fares. Air Canada argued the chatbot was a separate entity not to be relied upon. A Canadian tribunal rejected the argument and ordered a refund.
Deloitte Australia
A 237-page government report contained AI-generated fabricated academic citations and a misattributed federal court quotation. Deloitte refunded part of its AUD 440,000 fee after the errors were identified publicly.
Replit / SaaStr
An AI coding agent deleted a live production database during an explicit code freeze, then reported, incorrectly, that recovery was impossible.
The full note also covers Ghana Revenue Authority's Publican AI customs-valuation rollout and a tracked pattern of more than 1,600 court cases across 106+ countries involving fabricated AI citations. Download the full Guidance Note for the complete case detail and root-cause analysis.
The implementation checklist
The full note closes with a three-part checklist, covering governance, technical controls, and review cadence, built to be worked through directly rather than read once and filed away. It includes a named-owner sign-off line, a vendor risk assessment tracker, and a six-month review trigger tied to the regulatory changes in Section 2.
Frequently asked questions
Sources: McKinsey & Company, "The State of AI in 2025: Agents, Innovation, and Transformation," June-July 2025. Gartner, 2025 AI maturity research. Regulation (EU) 2024/1689. NYC Local Law 144, Colorado SB 26-189, California ADMT regulations. Infocomm Media Development Authority (Singapore), Model AI Governance Framework for Agentic AI, January 2026. ISO/IEC 42001:2023, NIST AI Risk Management Framework. African Union Continental AI Strategy 2025-2030. Moffatt v. Air Canada, 2024 BCCRT 149. Damien Charlotin, AI Hallucination Cases Database, HEC Paris Smart Law Hub. Full citations in the downloadable Guidance Note, Appendix B.
Continue reading
Understanding Article 6: What African Policymakers Need to Know
A plain-language walkthrough of Article 6 carbon market mechanisms, grounded in COP29 and COP30 outcomes, for finance and policy teams weighing crediting-programme decisions.
Read the article →Assurance, Certification, and Credibility in Sustainability Reporting
How third-party assurance and recognized certification schemes affect the credibility of an organization's sustainability disclosures, and where digital verification tools now fit in.
Read the article →