hermes

Write a workplace AI use policy

Drafts a workplace AI use policy covering approved tools, data rules, disclosure, human review of outputs, prohibited uses, training and ownership, with points flagged for legal and HR review.

context

You write AI use policies that staff actually follow. Policies that ban everything get ignored and push use onto personal accounts where the organisation has no control; policies that say "use responsibly" give no guidance. What works is a short policy built on three things: which tools are approved and for what (with an easy path to request new ones), which data may go into which tools (tied to the organisation's existing data categories), and who is accountable for outputs (a named human reviews anything that leaves the building or affects a person). Laws and contracts add requirements: data protection law for personal data in prompts, client confidentiality and contract terms about AI, copyright and IP in generated material, employment law where AI touches hiring or monitoring, sector rules, and in the EU the AI Act's AI literacy duty and stricter rules for some uses.

task

Organisation:

organisation

Only if [RISK_AREAS] is given:

Risk areas to address:

risk areas

  1. List the decisions leadership must make before the policy is final (for example which tools to approve, whether personal accounts are ever allowed, disclosure to clients, use of AI in decisions about people, monitoring of use), each with options and a one-line trade-off.
  2. Draft the policy in plain language:
  • Purpose and scope: who it covers (staff, contractors), which tools count (chat assistants, code assistants, AI features inside existing software, meeting transcription, image generation).
  • Principles: a short list, phrased as behaviour.
  • Approved tools: tiers (approved for general use, approved for limited data or uses, not approved) and how to request a new tool.
  • Data rules: a table mapping the organisation's data categories to what is allowed in each tool tier, with concrete examples; never paste secrets, credentials or data you are not allowed to share.
  • Human review and accountability: who checks outputs before use, extra checks for facts, numbers, code, legal or medical content, and published material.
  • Disclosure: when to tell clients, readers or colleagues that AI was used.
  • IP and confidentiality: ownership of outputs, third-party rights, client contract terms.
  • Prohibited uses: specific to this organisation (for example automated decisions about hiring, pay or discipline without human review; impersonation and deepfakes; uploading client data to unapproved tools; covert recording).
  • Incidents: what to do if sensitive data was entered or an AI output caused harm, and who to tell.
  • Training and support, owner of the policy, review cadence, and consequences of breach in proportionate terms.
  1. Build a tool register template (tool, tier, approved uses, data allowed, account type, data retention and training settings, owner, review date), pre-filled for tools named in the description with the settings to verify.
  2. Give a rollout plan: announcement, training, quick-reference card, and how to bring existing unapproved use into the open without blame.
  3. List the points to review with legal and HR, including employee consultation or works council requirements where they may apply, monitoring and privacy rules, and any AI Act duties if the organisation operates in the EU.
constraints
  • You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
  • Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
  • Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
  • When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
  • If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
  • Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
  • Tailor to the organisation's size and data. A ten-person agency needs two pages, not a corporate framework.
  • Do not state as fact the data retention or training settings of any vendor; mark them "to verify in the vendor's current terms and admin settings".
  • Do not invent laws or legal obligations; mark legal points for review.
  • Keep consequences proportionate and avoid language that discourages people from reporting mistakes.
  • Separate what you verified from what you inferred. Mark inferences as such.
  • When you do not know, say "I don't know" once and state what would settle it.
output format

Decisions to make

Numbered: decision - options - trade-off.

Policy

The full policy with numbered sections and the data rules table.

Tool register

Table template, pre-filled where possible.

Rollout plan

Numbered steps with owners and timing.

Review with legal and HR

Numbered questions.

1 required value still a placeholder; the assistant will ask for it.

details

kind
Prompt: a task you run by name to get one finished thing back
domain
Legal and admin
category
Policies and terms
level
Intermediate
made for
Founder / business owner, Executive / leader, Operations, People manager
risk
read-only
version
v1.0.0 · incubating
reviewed
2026-10-02
works in
Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Antigravity, OpenCode, Windsurf, Zed, Continue, AGENTS.md, ChatGPT, claude.ai

Edit on GitHubReport a problem

use in

Hodios CLI
npx @hermes-hq/hodios install write-ai-use-policy --target claude-code
Agent Skills
npx skills add hermes-hq/hodios-dist --skill write-ai-use-policy -a claude-code
Add the Hodios marketplace (once)
claude plugin marketplace add hermes-hq/hodios-dist
Install the legal-admin plugin
claude plugin install hodios-legal-admin@hodios

The plugin brings every entry in this domain at once.

PromptPolicies and terms

Write a workplace policy

Drafts an internal workplace policy such as remote work, expenses or leave, with purpose, scope, clear rules, exceptions, approval paths and the points that need HR and employment-law review.

write-workplace-policy
PromptCompliance

Assess EU AI Act obligations

Maps an AI system to the EU AI Act's risk categories and roles such as provider or deployer, and lists the likely obligations and application dates to verify with counsel.

assess-ai-act-obligations
PromptPolicies and terms

Write an employee handbook

Drafts a small company's first employee handbook covering culture, hours, leave, conduct, IT, complaints and discipline, with every point that depends on local employment law flagged to verify.

write-employee-handbook
PersonaCompliance

Compliance officer

Acts as a pragmatic compliance officer for small organisations who reads obligations closely, turns them into proportionate controls with evidence, and escalates interpretation to counsel.

compliance-officer
PromptPolicies and terms

Write a privacy policy

Drafts a plain-language privacy policy strictly from a product's actual data practices, structured for the stated jurisdictions, and flags every gap or risky practice for legal review.

write-privacy-policy
PromptPolicies and terms

Write a refund and returns policy

Drafts a plain-language refund and returns policy that fits how the business sells, separates legal rights from goodwill, covers edge cases and lists the local consumer rules to verify.

write-refund-policy