Lesson 25 · Expert · 20 min
Writing your team's AI usage policy
A ten-article template for a Copilot Chat usage policy: data, sources, proofreading, transparency, and the training required by Article 4 of the AI Act.
- Goal
- You will be able to write, in ten articles, your team's Copilot Chat usage policy, based on the tool's real perimeter and on the AI literacy obligation of the AI Act.
- Skills
- Frame

Your first attempt, unaided
Ask Copilot Chat to write the AI usage rules for your team, giving it nothing else. Read its answer looking for one thing only: the promises it makes on your behalf.
A usage policy tells your team what it may paste into Copilot Chat, what is logged, what goes out to the web, who proofreads, who signs, and how people get trained. Ten articles of five lines are enough, provided they rest on the tool's real perimeter and not on promises. Article 4 of the AI Act asks organisations for sufficient AI literacy among their staff: the policy and the completed course are the proof.
1Ten articles based on the real perimeter
A usage policy is written from facts, and Copilot Chat provides precise ones. Microsoft states that prompts and answers are logged, retained in the tenant for audit, and viewable by the administrator. They are not used to train the models. Queries sent to the Bing search engine follow a separate regime. They are a few words, without an identifier, sent outside the European Union data boundary. Uploaded files are stored in the work OneDrive. Sensitivity labels apply. An agent that reads shared data is billed per use and enabled by the administrator.
The regulatory frame fits in two articles of the AI Act, the European regulation on artificial intelligence. Article 4 requires organisations that deploy an AI system to ensure a sufficient level of AI literacy among their staff. The AI literacy framework of the OECD and the European Commission describes what that literacy covers. Article 50 requires generated content, images in particular, to be flagged. A team policy does not cite the law in detail; it derives observable behaviours from it.
Here is the ten-article template, to be adapted to your team.
- Purpose and scope. This policy applies to the team's use of Copilot Chat, with the work account and the green shield shown. The personal account is excluded. It complements the organisation's IT charter.
- What may be pasted. Public documents, fictional documents, internal documents without a restrictive sensitivity label. Test: I paste only what I could email to an external contractor. Names of people, amounts and health data are removed or replaced with placeholders.
- Logging. Everyone knows that their prompts and the answers are retained and viewable by the administrator according to the organisation's rules. We write in Copilot Chat as in a work email.
- Web search. Web queries leave the organisation. No internal information is phrased in a question asked with web search enabled.
- Verification and responsibility. Every figure, date, name and quotation is checked against a source before use. A deliverable that commits the organisation is proofread by its author, who remains responsible for it. Legal, HR and medical questions go through an expert.
- Transparency. A deliverable produced substantially with Copilot Chat says so when the recipient is external. Every generated image is flagged as such and shows neither a real person nor a real event.
- Agents. An agent shared within the team has instructions reviewed by the contact person and contains no confidential data. Any access to the organisation's shared data is requested from the administrator, never enabled on one's own initiative.
- Shared files and pages. A file uploaded for a sensitive task is deleted from OneDrive after use. A shared Copilot page follows the classification of the most sensitive document it contains.
- Training. Every team member completes the beginner course before any use on internal documents, and the intermediate course if they produce deliverables for external recipients. The contact person keeps the list of courses completed.
- Incidents and review. Any doubt (document pasted by mistake, suspicious answer, hidden instruction in a file) is reported to the contact person the same day. The policy carries a version number, a date, a contact person, and is reviewed every six months.


Diagram "Your team's AI usage policy"Diagram generated by AI and reviewed 2A team policy without invented promises
A purchasing manager wants a first draft of a policy for his team of twelve.
Weak prompt.
Write an AI usage policy for my team.Copilot produces two generic pages, valid for any tool, with phrases such as "do not share sensitive data" and a false promise: "conversations are not retained".
Strong prompt.
You are the assistant of the head of a twelve-person purchasing team that uses the Copilot Chat included in Microsoft 365, without a paid licence. Write a usage policy in ten articles of five lines at most, each phrased as an observable behaviour. Facts to respect and not to contradict: prompts and answers are logged and viewable by the administrator; they are not used to train the models; web queries leave the organisation; uploaded files are stored in the user's OneDrive; an agent that reads SharePoint is billed per use and enabled by the administrator. Constraints: formal address, no technical term without explanation, no promise about what Microsoft does not guarantee. End with the list of points I must have validated by the IT department.Copilot returns ten short articles, consistent with the facts provided. It adds a list of four points to validate, including the retention period of the logs and the rule for sharing agents.
What changes. The facts provided prevent invented promises. The "observable behaviour" constraint turns principles into checkable rules. The list of points to validate acknowledges that the team policy fits within the organisation's.
3Adapt the ten articles to your own team
Starting prompt, to be improved:
"Write the rules for using Copilot in the team."
Add the composition of the team and its usual documents. Take the facts of the Copilot Chat perimeter listed in "The concept". Impose the format in ten articles of five lines, the formal constraints, and the request for a list of points to have validated. The composer below helps you fill in the Constraints field. Then adapt the ten-article template to your team, name a contact person and date it. Have it reviewed by a colleague; failing that, reread it yourself 24 hours later, article by article, looking for what a reader could misunderstand.
Self-assessment grid: (a) every article describes a behaviour that can be observed; (b) no article promises what Microsoft does not guarantee; (c) contact person, version and review date appear at the top.
4The bias that enters by prompt and leaves amplified
An HR manager applies the policy and asks: "Write a job description for a dynamic, young sales rep who will know how to assert himself." The output contains discriminatory wording. The policy talks about verification, but the bias came in through the prompt itself. And a bias in the prompt comes out amplified in the answer. Correction: "Write a job description for a B2B sales position. Describe the missions, the observable skills and the expected results. Neutral wording, with no reference to age, gender or personality traits. End with a review that lists any potentially discriminatory wording under French employment law." Add to article 5 of your policy a line on the neutral wording of requests. Rule to remember: the policy also frames what we ask, not only what we get.
5Quiz
Three questions, instant feedback. Each option comes with an explanation.
6Proof of mastery
Submit your ten-article usage policy, adapted to your team, with the version, the date and the contact person, then the written feedback of a colleague who reviewed it, and the prompt you used to produce its first draft. If you are learning alone, replace that feedback with your own review 24 hours later, and the list of the articles you rephrased.
This lesson counts towards the Expert badgeSee the four badges
Criteria
What you wrote at the start of the lesson
Going further
The policy rests on the enterprise data protection described in the first lesson of the course. Article 7 refers to creating an agent. Article 9 is put into practice with the one-hour workshop. The Copilot prompts for legal teams sheet supplies the review prompts that article 5 assumes.
Frequently asked questions
Our organisation already has an IT charter, do we need a policy on top?
The team policy does not replace the charter, it refines it for one tool and one job. It cannot contradict it: have it reviewed by the IT department or the legal department before circulation, and cite the charter in its first article.
Does the AI Act apply to a small team?
Article 4 asks every organisation that deploys an AI system to ensure a sufficient level of AI literacy among its staff, with no size threshold. The form of the proof is free: a completed training course and a signed policy are one.
Should the personal account be banned?
Yes. The consumer entry point of Copilot does not offer enterprise data protection. The work entry point is m365copilot.com with the organisation's account, and the green shield is its visible sign.
How long should uploaded files be kept?
Microsoft states that they are stored in the user's work OneDrive, and the user can delete them at any time. The policy can require deletion after use for any sensitive document.
Sources
- Microsoft Learn, Enterprise data protection in Microsoft Copilot
- Microsoft Learn, Privacy and protections for Microsoft Copilot Chat
- Microsoft Support, Data protection when using Copilot Chat for work or school
- OECD and European Commission, Empowering Learners for the Age of AI (2026)
- Regulation (EU) 2024/1689 on artificial intelligence (AI Act)