This guide covers one part of a company AI policy: what staff may put into Claude, and what they may not. Claude is Anthropic's AI assistant. Staff can type text into it, paste documents into it or upload files to it. Every one of those actions sends company information to an outside service. A policy is how you decide, in advance, which information may make that trip.
It helps to separate two documents. The UK Information Commissioner's Office (ICO) puts it this way: policies set out what the rules are, why they are in place and who they apply to, while procedures give directions on how to carry out those rules. Your AI policy says "no client bank details in Claude". Your procedure says which plan to log in to, how to redact a document and whom to ask for an exception.
A workable policy answers five questions:
- Approved tools and plans: which Claude plan staff use, and which they do not.
- Data: what may go in freely, what needs care and what never goes in.
- Approvals: who signs off a new use or an exception.
- Logging: what is recorded, where, and who can see it.
- Ownership: one named person who maintains the policy and answers questions.
You do not have to start from a blank page. The ICO notes that it can make more sense to adapt and extend policies you already have, such as data protection and information management policies. The rest of this post works through each question, then gives an outline and a one-week rollout.
