What should an AI use policy say for HR and managers?
Seven sections, and the data classification one carries most of the protection.
Last updated: August 02, 2026
Direct Answer
A workplace AI use policy should cover seven things: which tools are approved and who approves new ones; what data may never enter AI tools, including employee identifiers and medical information; where human review is mandatory, especially hiring, discipline, and termination; verification duties for AI-drafted content; disclosure expectations; who owns AI governance; and what happens when the policy is violated. One page done clearly beats ten pages nobody reads.
Controlling authority: Title VII and the ADA, which govern by disparate impact regardless of intent, and TRAIGA (Tex. H.B. 149), which is intent-based and enforceable only by the Texas Attorney General.
The Seven Sections That Do the Work
Scope and approved tools: name what is permitted, name the approval path for anything new, and state that embedded AI features in existing software count. Data rules: no employee names or identifiers, no medical or leave information, no complaint or investigation content, no confidential business data in unapproved tools. Human review: AI never makes the final call on hiring, discipline, pay, or termination, and a named human owns each decision.
Verification: whoever uses AI output is responsible for every fact in it, full stop. Disclosure: when AI meaningfully shaped a document or decision process, say so internally. Governance: one named owner maintains the tool inventory and this policy. Violations: handled like any other policy breach, proportionate and consistent.
| Section | What it must say | The failure it prevents |
|---|---|---|
| Permitted and prohibited uses | Named tools, named tasks, and the tasks that are off limits | “Use good judgement” is not a policy. |
| Data classification | What may never be entered: names, medical information, complaint details, pay data, anything from a personnel file | The single largest exposure, and the easiest to prevent. |
| Human accountability | A named person owns every output; AI is never the author of a decision | Removes the “the tool said so” defence before anyone tries it. |
| Verification duty | Every factual or legal statement is checked before use | Fabricated citations and invented policy language. |
| Record status | AI drafts are discoverable, and prompts may be too | Managers assume the draft is private. It is not. |
| Vendor and tool approval | Who approves a new tool, and on what criteria | Shadow adoption of unvetted tools. |
| Review cadence | When the policy and the tool list are revisited | A policy naming tools that no longer exist. |
Making It Real Instead of Shelfware
Adoption is a training problem, not a drafting problem. A one-hour session with real examples: here is a write-up drafted safely with placeholders, here is the same task done dangerously with names and invented facts. Managers follow rules they have seen applied.
Revisit the policy on a schedule, because the tools change quarterly. The inventory review and the policy review belong on the same calendar entry, and the TRAIGA governance work described elsewhere in this library plugs into the same rhythm. For Texas employers, the policy plus the inventory plus training is the practical compliance core.
Status check, current as of August 2026: the EEOC removed its May 2023 Title VII technical assistance on algorithmic decision-making, and its ADA AI guidance, from its website on 27 January 2025. Those were non-binding technical assistance documents. Their removal changed the explanation, not the obligation — Title VII disparate impact analysis and the ADA apply to an automated selection tool exactly as they applied before. An employer that relaxed its testing because the guidance disappeared has misread what disappeared.
| Source | What it does | What it does not do |
|---|---|---|
| Title VII and the ADA | Still the operative risk. Disparate impact liability attaches regardless of intent, and regardless of whether a vendor built the tool | It does not excuse you because the algorithm is a third party’s. |
| TRAIGA (effective 1 January 2026) | Prohibits developing or deploying AI with the specific intent to discriminate on protected characteristics, plus a narrow set of other prohibited uses | It is intent-based, not impact-based. It was pared back substantially before passage and imposes far less on private employers than commentary suggests. |
| TRAIGA enforcement | The Texas Attorney General only | There is no private right of action. Your TRAIGA exposure is regulatory, not litigation. |
| The four-fifths rule | The screen that will actually surface your problem | It is a triage indicator, not a safe harbour above 0.80. |
| EEOC AI technical assistance | Removed from the EEOC website on 27 January 2025 | Those were non-binding technical assistance documents. Removing them changed the explanation, not the obligation. Title VII and the ADA are untouched. |
| Your vendor contract | Allocates cost and cooperation between you and the vendor | It does not transfer liability to the vendor. The employer is the one that made the decision. |
Policy Gap Risks to Watch
The absence of a policy does not slow AI adoption; it just removes the guardrails. Watch for these.
- Managers using AI for people decisions with no rules at all
- Sensitive data flowing into consumer tools by habit
- AI-drafted documents issued unverified under manager signatures
- Embedded AI features activating via product updates nobody reviewed
- A written policy that was never trained, so nobody follows it
Test the policy against what people already do
Draft the one-pager this month, using the seven sections above, and route it through leadership fast. A good-enough policy in force this quarter outperforms a perfect policy next year.
Pair it with the tool inventory, because a policy governing unknown tools governs nothing.
| Requirement | What to ask for | Why |
|---|---|---|
| Adverse impact testing | Results by race, sex, ethnicity and age, on your applicant pool | A vendor’s aggregate testing says nothing about your population. |
| Validation evidence | Job-relatedness and business necessity, documented | This is the defence if impact appears. |
| What the model actually scores | The features and their weights, at least in summary | You cannot defend a decision you cannot describe. |
| Accommodation pathway | A documented alternative for candidates who cannot use the tool | An ADA obligation the vendor will not discharge for you. |
| Human review point | Where a person can override, and on what basis | A fully automated rejection is the hardest fact pattern to defend. |
| Audit and data rights | Your right to test, and to export your own data | Without it you cannot run the four-fifths screen at all. |
| Change notification | Notice before the model is retrained or changed | A silent model update can move your selection rates overnight. |
Scores policy language against the obligations it is supposed to discharge.
When the policy is not being followed
Get the policy tailored rather than templated if you operate in the public sector, handle grant compliance, or already use AI in hiring, because those contexts add specific obligations.
We build AI use policies with the manager training included, which is the half that makes the paper matter.
Get a Straight Answer for Your Situation
General rules only go so far. If this question is live in your organization right now, talk it through with a senior HR consultant before you act. One conversation now costs less than one claim later.
Contact UsThis page provides general HR information for employers and is not legal advice. For legal interpretation or representation, consult qualified employment counsel.