AI Tools Policy¶
| Owner | Patrick Tolvstein |
| Version | 1.1 |
| Created | 2026-02-24 |
| Last reviewed | 2026-06-25 |
| Next review | 2027-06-16 |
Purpose¶
This policy governs the use of AI tools and autonomous AI agents within the organization. It exists to protect the security, confidentiality, and integrity of our systems, infrastructure, and customer data.
Scope¶
This policy applies to all employees, contractors, and anyone acting on behalf of the company. It covers all AI tools regardless of form - locally installed software, browser extensions, plugins, SaaS products, or systems integrated with existing services.
Approved tools¶
The following tools are approved for work use:
| Tool | Conditions |
|---|---|
| Microsoft Copilot | Via official company account only - never a personal account |
| ChatGPT / Codex (OpenAI) | Via approved company subscription only - never a personal account |
| Junie in PHPStorm | Via approved company subscription only - never a personal account |
| Claude / Claude Code | Via approved company subscription only - never a personal account |
Personal accounts are never allowed
Using any approved AI tool through a personal or private account is strictly prohibited - regardless of the tool. Company data must only ever be processed through official company accounts. Using a personal account removes all organisational controls over data handling, logging, and retention.
All other AI tools require explicit approval before use. See Requesting approval below.
Prohibited use¶
The following is strictly prohibited without prior written approval from Patrick (PT):
- Using any AI tool not listed as approved above
- Using approved tools via personal or private accounts
- Connecting AI tools to company systems, email, files, or external services without approval
- Using autonomous AI agents (tools capable of taking actions on your behalf, accessing files, environments, or services)
Autonomous agents
Tools such as OpenClaw and similar autonomous agents that can act on a user's behalf - including accessing files, emails, local environments, and external services - are strictly prohibited unless explicitly approved in advance. These tools introduce significant risks around data security, compliance, and system integrity.
Data handling¶
Never share the following with any AI tool
- Customer data or personally identifiable information (PII)
- Credentials, passwords, or API keys
- Internal URLs, domain names, or folder structures
- Project names or file names that reveal company-specific details
All data must be anonymised before use in any AI context. This includes replacing or removing customer information, domain names, project names, and any other identifiers that could reveal sensitive or company-specific details.
This requirement applies to approved tools as well.
Requesting approval¶
If you believe an AI tool could create value for the company, reach out to Patrick (PT) before using it. He will conduct a proper assessment covering security, compliance, and data handling.
A data processing agreement (DPA) with the vendor must be in place before any tool can be approved. Do not assume approval is granted until this has been confirmed in writing.
Do not install or use the tool while the assessment is in progress.
Incidents¶
If you have shared data that should not have been shared with an AI tool — or suspect that you may have — contact Patrick (PT) immediately. Do not wait to be certain. Early reporting limits potential damage and is never penalised.
Questions¶
If you have any questions about this policy or are unsure whether a specific tool or use case is permitted, get in touch with Patrick (PT).