Skip to content

AI Tools Policy

Owner Patrick Tolvstein
Version 1.2
Created 2026-02-24
Last reviewed 2026-09-04
Next review 2027-03-04

Purpose

This policy governs the use of AI tools and autonomous AI agents within the organization. It exists to protect the security, confidentiality, and integrity of our systems, infrastructure, and customer data.


Scope

This policy applies to all employees, contractors, and anyone acting on behalf of the company. It covers all AI tools regardless of form - locally installed software, browser extensions, plugins, SaaS products, or systems integrated with existing services.


Approved tools

The following tools are approved for work use:

Tool Conditions
Microsoft Copilot Via official company account only - never a personal account
ChatGPT / Codex (OpenAI) Via approved company subscription only - never a personal account
Junie in PHPStorm Via approved company subscription only - never a personal account
Claude / Claude Code Via approved company subscription only - never a personal account
GitHub Copilot Via official company account only - never a personal account
Kive Image/design use only - via approved company subscription only, never a personal account

Personal accounts are never allowed

Using any approved AI tool through a personal or private account is strictly prohibited - regardless of the tool. Company data must only ever be processed through official company accounts. Using a personal account removes all organisational controls over data handling, logging, and retention.

All other AI tools require explicit approval before use. See Requesting approval below.


Prohibited use

The following is strictly prohibited without prior written approval from Patrick (PT):

  • Using any AI tool not listed as approved above
  • Using approved tools via personal or private accounts
  • Connecting AI tools to company systems, email, files, or external services without approval
  • Using autonomous AI agents (tools capable of taking actions on your behalf, accessing files, environments, or services)

Autonomous agents

Tools such as OpenClaw and similar autonomous agents that can act on a user's behalf - including accessing files, emails, local environments, and external services - are strictly prohibited unless explicitly approved in advance. These tools introduce significant risks around data security, compliance, and system integrity.


Data handling

Never share the following with any AI tool

  • Customer data or personally identifiable information (PII)
  • Credentials, passwords, or API keys
  • Internal URLs, domain names, or folder structures
  • Project names or file names that reveal company-specific details

All data must be anonymised before use in any AI context. This includes replacing or removing customer information, domain names, project names, and any other identifiers that could reveal sensitive or company-specific details.

This requirement applies to approved tools as well.

No informal exceptions

This rule applies without exception, regardless of which tool is used or who is believed to have authorised it. Verbal or informal approval - including from managers or board members - does not override this policy. The only valid exception process is a written, documented approval from Patrick (PT) via Requesting approval, confirming both the specific data involved and that a DPA is in place. If you are unsure whether an exception has been formally approved, treat it as if it has not, and check with Patrick (PT).


Requesting approval

If you believe an AI tool could create value for the company, reach out to Patrick (PT) before using it. He will conduct a proper assessment covering security, compliance, and data handling.

A data processing agreement (DPA) with the vendor must be in place before any tool can be approved. Do not assume approval is granted until this has been confirmed in writing.

Do not install or use the tool while the assessment is in progress.


Periodic usage review

To catch unapproved or unlisted tool usage early - rather than relying only on self-reporting - the company will run a short internal AI tool usage survey roughly every 6 months. Results will be reviewed by Patrick (PT) and used to update the approved tools list and this policy as needed.


Incidents

If you have shared data that should not have been shared with an AI tool — or suspect that you may have — contact Patrick (PT) immediately. Do not wait to be certain. Early reporting limits potential damage and is never penalised.


Questions

If you have any questions about this policy or are unsure whether a specific tool or use case is permitted, get in touch with Patrick (PT).


Changelog

  • v1.2 (2026-09-04): Revised following analysis of an internal AI tool usage survey. Added GitHub Copilot to the approved list, added a "no informal exceptions" clarification under Data handling, and added new Periodic usage review sections.
  • v1.1 (2026-06-25): Previous version.