Purpose
As part of our commitment to innovation and efficiency, we leverage AI technologies to enhance various aspects of our operations. However, it is essential that all staff members understand the risks associated with AI and use these tools responsibly. This policy outlines the rules and best practices for staff to follow to ensure corporate data is protected, that AI systems are used ethically, and that we mitigate any potential threats arising from AI technologies.
The purpose of this policy is to:
- Safeguard sensitive corporate information from exposure to third-party AI systems.
- Ensure AI tools are used in a responsible and ethical manner.
- Raise awareness about the potential dangers of AI, such as data leakage, unauthorised access, or misuse of corporate data.
- List approved Corporate AI systems
Scope
This policy applies to all employees, contractors, and authorised individuals with access to corporate systems, data, or AI tools. It governs the appropriate use of all AI technologies available within the company.
What is AI
For the purpose of this policy, Artificial Intelligence (AI) refers to any system, software, or technology that uses machine learning, natural language processing, automation, or other advanced computing techniques to analyse data, generate insights, make predictions, or assist in decision-making. This includes, but is not limited to, AI-powered chatbots, automation tools, data analytics models, and generative AI applications.
Guidelines for Using AI Tools
Confidentiality and Data Sharing Restrictions - Employees must not input into or share any confidential, sensitive, or proprietary company or customer data with any non-approved AI tools or systems (e.g., chatbots, AI-based text generators, cloud-based AI systems, etc.) without prior authorisation from a Director.
- Approved Systems - Only approved AI tools and platforms either provided or vetted by the company may be used for corporate tasks. Sharing data, company or customer information with unauthorised tools or unapproved third-party AI systems are strictly prohibited. The following AI tools are pre-authorised:
- Microsoft 365 Copilot Chat (https://m365copilot.com)
- Approved use: research, development and efficiency improvement tasks
- Can share company data: No data sharing allowed
- Notes: You should be signed in with your Fortus account so that data protection policies can be applied. The free version of Microsoft CoPilot (https://copilot.microsoft.com/) should not be used.
- Microsoft 365 Copilot (Full Version)
- Approved use: research, development and efficiency improvement tasks
- Can share company data: No data sharing allowed
Notes: You should be signed in with your Fortus account so that data protection policies can be applied. The free version of Microsoft CoPilot (https://copilot.microsoft.com/) should not be used.
- GitHub Copilot
- Approved use: or software development, coding assistance, and automation
- Can share company data: Yes
- Caveats: AI generated code needs to be specifically documented within all systems and needs to follow standard software development acceptance processes before being added to the any testing or production systems.
All code developed during the course of employment, whether using AI tools or not, remains the intellectual property of the company.
- ChatGPT (Public Version)
- Approved use: research, development and efficiency improvement tasks
- Can share company data: No data sharing allowed
Notes: You should not enter any corporate, customer, or sensitive data into the public version of ChatGPT. You should also disable memory features in public ChatGPT if used personally, and avoid sharing links to sensitive conversations.
- ChatGPT (Enterprise)
- Approved use: research, development and efficiency improvement tasks
- Can share company data: Yes, as long as you’re signed into the Fortus account.
Notes: You should be signed in to an authorised Fortus account before sharing any sensitive or corporate data.
- Private Instances of Public AI models - Hosted within a company corporate subscription in Azure
- Approved use: Training of models and processing of data from other corporate systems for data analysis
Can share company data: Yes
- Privately hosted LLM's
- Approved use: Research and development, education and training on private datasets outside of corporate network(s)
- Can share company data: No
Caveats: This is not to hold any corporate data or have results imported into any corporate environment
- All other AI systems:
- Approved use: Experimentation, general queries
- Can share company data: No. Users must be aware that these systems will store the queries run on them and the data shared with them, that this data is likely to be publicly searchable and/or accessed by hostile players
AI in 3rd Party Applications/Platforms
When using third‑party or SaaS applications that incorporate AI capabilities—such as finance platforms like Xero—employees must ensure that no confidential, sensitive, or customer data is entered into these systems unless the application has been formally reviewed, risk‑assessed, and approved for AI‑related processing by Fortus.
Many cloud platforms now include embedded AI features (e.g., automated insights, predictive analytics, document interpretation), and these must only be used in a manner compliant with our data protection, confidentiality, and information security obligations.
Staff must not enable or interact with AI‑powered features in unapproved services, and any new AI‑enabled tool must be submitted for security and legal review prior to use. This ensures that data is handled ethically, securely, and in accordance with UK GDPR and the Fortus Information Security Management System.
Dangers of AI
While AI presents numerous opportunities for growth and efficiency, there are also risks that must be considered:
- Data Privacy and Security Risks - Unprotected data shared with AI tools could be exploited, or viewable by anyone or any other system in the world, leading to data breaches or misuse of company information.
- Misinformation and Bias - AI algorithms can sometimes produce biased, inaccurate or entirely fictitious results. Staff must exercise caution and verify AI-generated outputs before using them in decision-making processes.
- Unintentional Data Exposure - AI systems that process data may inadvertently reveal sensitive information if not properly secured. It's crucial to avoid uploading or entering confidential data into systems that are not explicitly approved for such use.
Employee Responsibilities
- Cross-Check Information - Always verify AI-generated answers or recommendations against trusted, human-curated sources before making decisions. Never rely solely on AI outputs, especially when it involves critical business or operational decisions.
- Potential Inaccuracies - AI systems can sometimes produce incorrect, outdated, or biased information. Staff should be vigilant in identifying any discrepancies or inconsistencies in AI-generated content.
- Ask for Human Oversight - For important tasks, especially those involving sensitive or high-stakes decisions, seek guidance from relevant subject matter experts to ensure the accuracy and validity of AI suggestions.
- Avoid Blind Trust - Do not treat AI responses as absolute truth. Engage with AI outputs in a questioning and evaluative manner, recognizing the limitations of AI technologies.
- Vigilance - Always remain aware of where corporate data is being inputted and ensure it is handled according to company policy.
- Report Incidents - Any suspicious activity or unapproved sharing of corporate data with AI systems must be immediately reported to the Information Security Team.
- Disclosure - Use of AI systems in work should be documented and acknowledged
- Review - All output from AI systems must be reviewed by a human before internal or external use - whoever produces the AI assisted output is responsible for its content as though it had been written by them.
Usage Restrictions
- Third-Party AI Platforms - Employees must not use third-party AI systems or platforms for business purposes unless explicitly authorised by within this policy.
- Data Export - Staff are not allowed to upload any corporate or customer data to any 3rd party AI system unless it's part of the approved AI systems list. For the avoidance of doubt, corporate or customer data should not be uploaded to, or copied into, ChatGPT.
- New AI Systems - Any new AI based system needs to be submitted to the Information Security team for review and legal sign off before it can be used for processing or handling any corporate or customer data.
Automated Chatbots
Automated chatbots present a different challenge to other uses of AI. Given the desire to get automated responses back to users both internal and external as quickly as possible, it becomes inherently difficult to have these vetted by a human before release. To address this, the following points need to be addressed in addition to the areas already outlined for general AI usage.
Transparency and Disclosure
Clear Identification - Always make it clear to users at the start of the conversation that they are interacting with a chatbot, not a human. This is important for setting proper user expectations and maintaining trust.
- Data Usage Disclosure - Inform customers about how their data will be used, stored, and protected at the start of the communication process. This builds transparency and ensures compliance with privacy regulations.
- Clear Boundaries - Set clear limits on what the chatbot can do. If there are certain tasks that require human intervention, make that transparent to the user, and offer the option to escalate to a human agent.
- Internal Use - Staff must always ensure they are verifying answers provided by internal Chatbots prior to using the data provided.
Accuracy and Reliability
Predefined Scripts and Knowledge Base - Design the chatbot around a clear set of predefined responses and a knowledge base that is accurate, up-to-date, and aligned with your goals. The chatbot should be configured not to provide responses outside its knowledge base.
- Continuous Monitoring and Updates - Regularly update the chatbot’s knowledge base and monitor its interactions to ensure that it continues to provide relevant and correct information. This also helps detect any errors or gaps in the system that could cause harm.
- Logging - ensure that all interactions, prompts and responses are logged so these can be reviewed by a human in the event responses are not as expected.
- Brand Representation - externally accessible chatbots facing our customers are a direct representation of the company and as such this has to be considered as part of the use case and data being accessed and presented by the chatbot.
Error Handling and Escalation Protocols
- Graceful Handling of Errors - Ensure the chatbot is designed to handle errors gracefully. If the bot doesn’t understand a request, it should respond politely and ask for clarification or offer an alternative solution.
Escalation to Human Agents: Implement escalation protocols that allow the chatbot to transfer the conversation to a human agent when necessary or direct the user to the relevant members of staff. This is crucial for complex or sensitive queries that the chatbot cannot handle adequately.
User Testing and Feedback
User Testing - Before going live, conduct thorough user testing to identify potential issues with the chatbot’s usability, language, and functionality.
- Surveys - Collect regular surveys and gather feedback on the chatbot’s performance to identify areas for improvement
- Continuous Improvement - Set up a process for monitoring user feedback and improving the chatbot’s performance over time. Use analytics where possible to identify where the chatbot fails to meet user expectations and iteratively improve it.
Data Security and Privacy
AI systems must handle personal data in full compliance with applicable data protection regulations, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and any other relevant UK legislation. All personal data must be processed securely, ethically, and with appropriate safeguards to ensure confidentiality, integrity, and compliance with legal obligations. AI use must comply with ICO guidance and be transparent, accountable and privacy-preserving. Any AI use in finance, healthcare or legal work must meet regulatory requirements.
Compliance and Enforcement
The IT and compliance teams will be continually monitoring the use of AI within the business and perform regular audits to ensure that this policy is being adhered to. This includes, but is not limited to, inspection of the use of AI tools within the company and with corporate and customer data.
This policy forms part of your contract of employment and failure to adhere to it may result in disciplinary action, including but not limited to termination of employment, legal action, or other sanctions deemed necessary by the company.
Conclusion
The integration of AI into our operations presents an exciting opportunity, but it is critical that we approach its use responsibly. By following these guidelines, employees can help safeguard our data, maintain our company's integrity, and protect against potential risks associated with AI technology.
This policy will be reviewed at least quarterly by the business, with material changes in the AI landscape causing this to be reviewed more often when necessary.
Contacts
Fortus Data Protection Officer