How to Use AI at Work: A Starter Guide for Teams

A starter guide for teams: the three rules to agree before anyone opens a chat window, which account to use, eight safe first uses, what to keep away from AI, a one-page policy you can copy, and a 30-day way to roll it out.

7 min read

The safe way to start using AI at work is to agree three rules first, then pick a few low-risk jobs. The rules: only use a work account your company has approved, never paste in what that account is not cleared for, and a person checks everything before it leaves the team. The first jobs: drafting, summarizing, rewriting and turning notes into lists, where the AI writes a first version from material you give it and you correct it. Keep decisions about people, money, legal commitments and anything irreversible with a person. Write all of that down on one page, try it for a month, and adjust. The rest of this guide fills in each step.

Agree three rules before anyone starts

Most trouble with AI at work comes from people using it quietly, each in their own way, with their own accounts. Three rules, agreed out loud, prevent most of it:

  1. Approved accounts only. Work goes into the assistant the company pays for and has configured, not a personal account.
  2. Know what may go in. Decide which kinds of information the approved account may see, and name what never goes in any assistant, such as passwords, customers’ personal data or anything under a confidentiality agreement that does not allow it.
  3. A person owns the result. Whoever sends, publishes or acts on AI output is responsible for it, as if they wrote it themselves.

If people are already using assistants without these rules, start by finding out where. Shadow AI agents covers how to find assistants your team has already connected, without turning it into a crackdown.

Use a work account, and know what it promises

Business plans and personal plans handle your data differently, and the difference is usually in the terms, not the screen. Anthropic’s privacy center says that by default it does not use inputs or outputs from its commercial products (opens in a new tab), such as Claude for Work and the API, to train its models, unless you submit feedback or opt in.

Microsoft says of enterprise data protection (opens in a new tab) in Microsoft Copilot and Copilot Chat that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, and that your existing permissions, sensitivity labels and retention policies apply. Consumer plans have their own settings, which each person controls.

The practical rule is simple: pick one or two assistants, buy the business plan, have someone read the data terms and switch off what you do not want, and tell everyone that is the one to use. Which assistant matters less than everyone using the same one.

Eight safe first uses

Good first jobs share three traits: you supply the material, the output is a draft, and a mistake is caught before it matters.

  • Drafting emails and messages from your own bullet points, especially the awkward ones: a delay, a no, a reminder.
  • Summarizing a long document or thread you are allowed to share with the assistant, then reading the parts the summary flags.
  • Turning meeting notes into a list of actions, each with a verb and an owner.
  • Rewriting one text for a different audience: the customer version, the executive version, the plain-English version.
  • Writing spreadsheet formulas and explaining ones someone else wrote.
  • First drafts of standard documents: a job posting, a standard operating procedure, a checklist, an agenda.
  • Brainstorming names, headlines, questions to ask a vendor, or objections a customer might raise.
  • Research with sources, where you open and read every source before you rely on it.

For project managers, AI for project managers goes through twelve specific jobs and what to check on each, and prompts for project management with AI has prompts ready to paste.

What to keep away from AI

  • Decisions about people. Hiring, firing, performance ratings, pay. An assistant can tidy your notes; a person decides, and can explain why.
  • Money and commitments. Approving spend, quoting a price, promising a date to a customer.
  • Final legal, tax, medical or safety answers. A draft question for your lawyer or accountant is fine; the answer comes from them.
  • Anything irreversible. Sending to a mailing list, deleting records, closing a customer’s account.
  • Numbers you have not checked. Assistants can misread a table or invent a figure that looks plausible.

That last one deserves a name. NIST’s Generative AI Profile (opens in a new tab) (NIST AI 600-1) calls it confabulation: confidently stated but false content. It is why the rules above say a person owns the result, and why checking is part of the job, not an extra. Verifying AI-generated work sets out a review process that does not take longer than doing the work yourself.

A one-page AI use policy to copy

A small team does not need a long policy. It needs one page everyone has read. Adapt this:

AI use at work: our rules
1. Use only: [approved assistant], signed in with your work account.
2. Never paste in: passwords, keys, customers' personal data,
   health or financial records, or anything under an NDA that forbids it.
3. OK to paste in: our own drafts, notes, public information,
   internal documents marked for general staff use.
4. You own what you send. Read and check every AI draft before it
   leaves the team. Check every number, name, date and source.
5. A person decides: hiring, pay, performance, spending, prices,
   customer commitments, and anything that cannot be undone.
6. Say so when it matters: tell a customer or colleague when AI
   wrote most of something they will rely on.
7. Connecting an assistant to a company system (email, files, the
   task board) needs [name]'s OK first, with the narrowest access.
8. Questions or mistakes: tell [name]. No blame for reporting.
Reviewed: [date]. Next review: [date + 3 months].

If you want a framework behind it, the NIST AI Risk Management Framework (opens in a new tab) is the US reference: voluntary, and organized around four functions, Govern, Map, Measure and Manage. The NIST AI RMF for small teams translates it into plain steps, and AI agent governance for small teams covers who approves what.

Roll it out in 30 days

  1. Week 1: agree the three rules, choose the assistant, set up the business plan, and share the one-page policy.
  2. Week 2: each person picks two jobs from the safe list and tries them on real work, keeping a note of what saved time and what went wrong.
  3. Week 3: compare notes in a short meeting. Keep the prompts that worked in one shared place, and turn any mistakes into a line in the policy.
  4. Week 4: decide what comes next. For most teams that is a shared prompt library, or connecting the assistant to one company system, read-only first.

From chat to agents: the next step

The step after chat is letting an assistant act: read the inbox, file tasks, update records. That is where the risks change. An assistant that reads outside text, such as an email or a web page, can be steered by instructions hidden in it, which is explained in indirect prompt injection. Give each connected assistant the narrowest access that does the job, keep a person approving anything that writes, and make sure you can see afterward what it changed. Before you grant that access, run through the AI risk assessment template.

Where fenbs fits

fenbs is a task board where people and AI assistants are both members with a role. It suits the moment a team moves from chatting with AI to letting it do work. Tasks move through four lanes, To Do, Next Up, In Progress and Completed, and History records who changed what, with an assistant’s changes under its own name. Assistants connect over MCP at https://fenbs.ai/api/mcp, signing in through the browser or with a token you issue under Settings, with a name, scopes and an optional expiry, and revoking it there cuts the assistant off.

The one-page policy belongs there too. Record each rule on the Decisions and rules page, with the person who decided it, and every connected assistant reads the rules before it starts work; AI context notes hold the background every assistant should know. fenbs has no due dates, sprints or settable assignee, so it is a place for the work, not a replacement for your calendar.

Related

Ten jobs for a small business: AI agents for small businesses. Sorting jobs for AI: which tasks can AI agents automate. What AI context is: the glossary entry. Connecting an assistant: Claude or ChatGPT.

Questions people ask.

How should a beginner start using AI at work?

Use the assistant your company has approved, with your work account, and start with drafting and summarizing jobs where you supply the material and check the result. Emails from your own notes, meeting notes into actions and rewriting a document for a different audience are good first tasks.

What should you never put into an AI tool at work?

Passwords and keys, customers’ personal data, health or financial records, and anything under a confidentiality agreement that does not allow it. Beyond that, follow what your company has cleared the approved account for, and never use a personal account for work material.

Do small teams need an AI use policy?

Yes, but it can be one page: which assistant to use, what may and may not go in, who checks the output, which decisions stay with people, and who to tell about mistakes. Review it every few months as the tools change.

Is it safe to let AI make decisions at work?

Not for decisions about people, money, legal commitments or anything irreversible. AI can prepare the information and draft options; a person should decide and be able to explain why.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.