AIforBC source-backed guide

A practical responsible AI use policy for a BC organization

The minimum operating decisions a British Columbia organization should make before employees use generative AI for real work.

Last reviewed August 13, 202613 minute readPrimary sources listed below

Direct answer

A useful AI policy names approved tools and owners, classifies permitted information, defines allowed and prohibited uses, requires source and human review, sets vendor and access controls, provides incident escalation, trains each role, and establishes a review cycle. A policy without a usable workflow and enforcement process is only a document.

What matters most

  • Start with tasks, information, and consequence—not a list of AI brands.
  • Make approved and prohibited behaviour easy to distinguish.
  • Require an accountable human for important outputs and decisions.
  • Connect policy to vendor review, access, logging, retention, incidents, and training.
  • Review the policy when tools, uses, vendors, or risks change.

Define scope, ownership, and purpose

State which employees, contractors, systems, and work activities the policy covers. Name an accountable owner and the people responsible for privacy, security, legal, records, procurement, and operational approval where those functions exist.

The purpose should be operational: enable suitable uses while protecting people, information, customers, the organization, and the quality of decisions. Avoid promising that policy approval makes every use safe.

  • Create a current register of approved tools, configurations, owners, and uses.
  • Require review before a new tool, integration, data source, or high-consequence workflow is introduced.
  • Give employees a clear route for questions and exceptions.

Classify information and permitted uses

Employees need a rule they can use during real work. A green-yellow-red model can translate the organization’s existing classification into AI-specific defaults, but it must not replace the underlying privacy, security, contractual, professional, or records analysis.

The Canadian Centre for Cyber Security advises organizations to establish plans and policies for AI use, select vendors carefully, and avoid entering personal or sensitive corporate data into prompts without proper controls.

  • Green: public, synthetic, or explicitly approved information used for low-consequence tasks.
  • Yellow: internal or sensitive information used only in approved configurations, for an approved purpose, with required controls.
  • Red: credentials, prohibited data, or personal/confidential information without an approved basis.

Set review and accountability rules

The policy should describe which outputs require source verification, expert review, second approval, disclosure, recordkeeping, or a decision not to use AI. Important decisions about people, rights, money, health, safety, employment, housing, or access to services need context-specific oversight.

NIST’s voluntary AI Risk Management Framework organizes work around governing, mapping, measuring, and managing risk. A small organization can use the same logic without creating a large bureaucracy: identify the task and affected people, test the system, record failures, assign controls, and decide whether the residual risk is acceptable.

  • AI output must not become the authoritative record without the normal approval process.
  • Citations, calculations, names, dates, and consequential claims require independent checking.
  • Employees must be able to escalate uncertainty without pressure to use the tool.

Connect vendor, access, and incident controls

A policy must connect to implementation. Review vendor data use, retention, deletion, access, security, location, subprocessors, training settings, audit rights, change notices, and contract terms. Configure accounts and permissions rather than relying on employees to interpret consumer defaults.

Define what constitutes an AI incident: sensitive data entered into an unapproved service, harmful or materially incorrect output used, suspicious model or agent behaviour, unauthorized automation, account compromise, or an unapproved integration. State who must be told, what access may be suspended, and how evidence and affected records are handled.

  • Use least privilege and separate administration from ordinary use.
  • Control integrations and shadow AI, not only browser chat tools.
  • Set retention and deletion rules for prompts, outputs, logs, and generated files.
  • Test the incident path during training.

Train, measure, and revise

A policy is effective when people can apply it to their work. Teach approved tools, information boundaries, the task method, verification, role-specific scenarios, exceptions, and incidents. Measure whether workers can demonstrate the expected behaviour—not only whether they attended.

Review the policy on a schedule and whenever a tool, vendor term, integration, workflow, law, or incident materially changes. Keep a change log so teams know which version applies.

Continue with a practical resource

Frequently asked questions

Answers before you take the next step

Can we ban confidential information in all AI tools?

That may be a useful default for unapproved services, but the full rule depends on approved purpose, tool configuration, contracts, legal obligations, security, and organizational policy. Define the actual information classes and controls.

Should the policy list approved AI tools?

Maintain a current approved-tool register with owners, configurations, uses, and conditions. The policy can explain the approval process so it does not become obsolete whenever the register changes.

Is employee disclosure of AI use always required?

Disclosure rules should reflect the task, audience, consequence, professional duties, contracts, and organizational standards. Define when and how disclosure is required rather than using a vague universal statement.

How often should the policy be reviewed?

Use a scheduled review and trigger an earlier review when tools, vendors, integrations, purposes, information, risks, incidents, or applicable requirements materially change.

Source trail

Primary sources used in this guide

  1. Generative artificial intelligence — ITSAP.00.041Canadian Centre for Cyber Security

    Current Canadian guidance on AI risk planning, vendor selection, data, oversight, review, and secure use.

  2. Principles for responsible, trustworthy and privacy-protective generative AI technologiesFederal, provincial, and territorial privacy authorities

    Joint Canadian privacy principles addressing necessity, consent, safeguards, transparency, access, accuracy, accountability, and vulnerable groups.

  3. AI Risk Management FrameworkU.S. National Institute of Standards and Technology

    Voluntary risk-management framework and generative AI profile organized around govern, map, measure, and manage.

  4. Protect Your Privacy When Using AI ToolsOffice of the Information and Privacy Commissioner for British Columbia

    BC guidance on information sharing, inaccurate output, privacy settings, retention, and human involvement.

AIforBC uses official and primary sources where practical. This guide provides general operational education, not legal, privacy, cybersecurity, or financial advice.

Need help choosing?

Describe the workflow before choosing the vendor.

Request an AI solution match