Skip to content

AI Tools Policy

Owner Patrick Tolvstein
Version 1.1
Created 2026-02-24
Last reviewed 2026-06-25
Next review 2027-06-16

Purpose

This policy governs the use of AI tools and autonomous AI agents within the organization. It exists to protect the security, confidentiality, and integrity of our systems, infrastructure, and customer data.


Scope

This policy applies to all employees, contractors, and anyone acting on behalf of the company. It covers all AI tools regardless of form - locally installed software, browser extensions, plugins, SaaS products, or systems integrated with existing services.


Approved tools

The following tools are approved for work use:

Tool Conditions
Microsoft Copilot Via official company account only - never a personal account
ChatGPT / Codex (OpenAI) Via approved company subscription only - never a personal account
Junie in PHPStorm Via approved company subscription only - never a personal account
Claude / Claude Code Via approved company subscription only - never a personal account

Personal accounts are never allowed

Using any approved AI tool through a personal or private account is strictly prohibited - regardless of the tool. Company data must only ever be processed through official company accounts. Using a personal account removes all organisational controls over data handling, logging, and retention.

All other AI tools require explicit approval before use. See Requesting approval below.


Prohibited use

The following is strictly prohibited without prior written approval from Patrick (PT):

  • Using any AI tool not listed as approved above
  • Using approved tools via personal or private accounts
  • Connecting AI tools to company systems, email, files, or external services without approval
  • Using autonomous AI agents (tools capable of taking actions on your behalf, accessing files, environments, or services)

Autonomous agents

Tools such as OpenClaw and similar autonomous agents that can act on a user's behalf - including accessing files, emails, local environments, and external services - are strictly prohibited unless explicitly approved in advance. These tools introduce significant risks around data security, compliance, and system integrity.


Data handling

Never share the following with any AI tool

  • Customer data or personally identifiable information (PII)
  • Credentials, passwords, or API keys
  • Internal URLs, domain names, or folder structures
  • Project names or file names that reveal company-specific details

All data must be anonymised before use in any AI context. This includes replacing or removing customer information, domain names, project names, and any other identifiers that could reveal sensitive or company-specific details.

This requirement applies to approved tools as well.


Requesting approval

If you believe an AI tool could create value for the company, reach out to Patrick (PT) before using it. He will conduct a proper assessment covering security, compliance, and data handling.

A data processing agreement (DPA) with the vendor must be in place before any tool can be approved. Do not assume approval is granted until this has been confirmed in writing.

Do not install or use the tool while the assessment is in progress.


Incidents

If you have shared data that should not have been shared with an AI tool — or suspect that you may have — contact Patrick (PT) immediately. Do not wait to be certain. Early reporting limits potential damage and is never penalised.


Questions

If you have any questions about this policy or are unsure whether a specific tool or use case is permitted, get in touch with Patrick (PT).