Artificial Intelligence

Which AI Tools Are Your Employees Using? Simple Rules for Small Businesses

September 29, 20265 min read

Your team is most likely using AI tools already. Instead of banning them, a one-page note on what is allowed and what is not protects both you and your customers.

Someone in accounting may have opened an AI tool to tidy up an email, or someone in sales to draft a quote. Usually there is no bad intent; they just want to work faster. The problem is that it happens without your knowledge and without rules. Turkey's data protection authority (KVKK) has also pointed out that these tools are mostly used at work through individual choice rather than company decisions, and it published an information document on this in early 2026. This post offers a practical frame so a small team can use AI carefully without fear. You can produce the rules page in half an hour in a single meeting. In everyday tasks these tools genuinely help; the point is not to leave them without rules.

Try asking before you try banning

Ask a simple question in a meeting: 'Which tools do you use, and for which tasks?' In a blame-free setting you get honest answers. A ban does not stop usage, it only hides it. The goal is to see who uses what and to draw a safe frame. Some employees may hesitate to admit using a tool, so start by describing your own use. Write what you learn in a short table: tool, purpose, what information goes in. That table becomes the base of your rules. Say up front that nobody will be punished for answering. After the answers, sort the tools into three groups: clearly fine, use with care, and drop. That way the rule list is grounded in real usage.

The most important rule: what never goes in

Do not paste personal data such as a customer's name, phone, address, health or payment details, or company secrets such as price lists, contracts and customer lists, into a publicly available AI tool. Once the information goes in, you do not decide where it is kept or who can see it. On personal data, we suggest reading the generative AI guide published by KVKK; this is not legal advice, so ask a specialist about specific questions. Having patient notes summarized at a dental clinic, or pasting a reservation list into a tool at a restaurant, looks harmless at first but is risky. Doing the same task with anonymous, generic information usually gives the same benefit. If you are unsure whether something can go in, ask yourself: if this ended up in the wrong hands, would it harm my customer or my business? If yes, leave it out.

A practical fix: before giving a customer email to a tool, delete names, phone numbers and similar details or replace them with generic labels like 'Customer A'.

Work account or personal account?

If an employee enters work data through a personal account, that account leaves with them. Where possible, use a work account opened by the business and managed by someone responsible. Tools may offer settings on how data is used; review them together once. Conversations and files left in a departing employee's account slip out of the business's hands. Keeping a list of who opened which account, and sharing passwords through a manager, reduces that risk. A work account also lets you see, when needed, which tasks are done with the tool, and makes onboarding new staff easier.

The human is still responsible for the output

AI can state wrong information very confidently. If the output goes to a customer as a quote, a price, a contract clause, or touches something sensitive like health or law, the person sending it checks it. 'The tool wrote it' is not an excuse. For example, a tool may state a discount rate or a legal deadline wrongly, and because the text reads well, the error can go unnoticed. Verifying information against a source before sending should become a habit. In areas like health, law or tax, tool output is only a first draft; the final word belongs to the relevant specialist. The sender's name sits at the bottom of the email, not the tool's. That is why responsibility stays with the sender.

A one-page rule list you can adapt

  • Allowed: drafting emails, generating general ideas, summarizing public information, polishing text you wrote yourself.
  • Allowed with a check: customer-facing texts and quotes; a person always reads them before sending.
  • Not allowed: entering customer personal data, contracts, price lists, passwords or company secrets into a tool.
  • Not allowed: using a personal account for work data; only the tools and accounts the business has approved.
  • If unsure: ask your manager before entering anything; asking is never a mistake.
  • Anyone who wants to try a new tool gets it added to the list first; the list is reviewed every few months.

A short training solves most problems

A half-hour session is enough: explain the rules, try one or two real examples together, and show how to ask 'can I enter this?'. Just emailing the rules does not work; people remember when they see examples. Repeat the session whenever a new tool or new employee arrives, not just once a year. Hand new hires the rules page on their first day. As a good habit, ask each team member to share one example a month: 'What did AI make easiest for me this month, and what did I take care not to enter?' That turns the rules from a ban list into shared learning. At the end, have everyone briefly confirm they have read the rules page.

Tags:aiemployeesdata securityprivacypolicy