Please share

There’s the AI conversation that happens in the boardroom. Strategy decks, pilot programs, a steering committee. Then there’s the one that happens at 4:45 on a Thursday. Someone pastes a client contract into a free chatbot, because the summary is due at five. The second conversation decides your actual risk. Moreover, it’s the reason your company needs an AI acceptable use policy.

Shadow AI is already inside your business

Survey after survey finds the same pattern. Most employees already use AI at work. Many of them have never told anyone. However, that is not recklessness. Nobody asked, and they assumed the answer would be no.

People call this shadow AI. It is not a discipline problem. Instead, it is a governance vacuum, and your staff filled it on your behalf. An AI acceptable use policy is what closes that gap.

The risks are quieter than you’d expect

The typical AI incident is not dramatic. It is confidential material pasted into a consumer tool whose terms nobody read. Customer records. Unreleased financials. Source code. A signed NDA. There is no breach alert and no log entry. As a result, you find out late, or you never find out at all.

Then there is the output. AI is wrong at an uncomfortable rate. Worse, it is wrong in polished, confident prose. Fabricated citations have already produced sanctioned court filings and retracted research. The failure mode is not obvious garbage. Rather, it is plausible.

Meanwhile, somewhere in your organization, AI is probably touching a decision about a person. Who gets the interview. Who gets the rate. Who gets flagged. That is the moment this stops being an IT question.

New Jersey employers have a specific problem

New Jersey has moved faster than most states. In addition, it has aimed squarely at hiring.

In January 2025, the Attorney General and the Division on Civil Rights issued guidance on algorithmic discrimination as part of a broader Civil Rights and Technology Initiative. The message was blunt. Discrimination produced by an algorithm is treated the same as discrimination produced by a person. Furthermore, an employer can be liable for a tool it did not build.

Then in December 2025, the Division adopted disparate impact rules that the Attorney General’s office called the most comprehensive of their kind in the country. They name automated employment decision tools directly. Resume screeners. Application software that filters on availability. Video and facial analysis tools.

Three points matter most:

  • Intent is irrelevant. Once a neutral practice shows a disproportionate effect, the burden shifts to you to justify it with evidence.
  • The vendor is not your shield. The obligation to confirm that a tool complies sits with the employer, not the software company.
  • The reach is wide. The Law Against Discrimination protects more categories than federal law. It also covers any employer with New Jersey roles or New Jersey applicants, headquarters notwithstanding.

This is not a fringe issue locally, either. A 2024 Rutgers survey found that 63% of responding New Jersey employers were already using AI-enabled tools in recruiting and hiring.

Two more items belong on the list. First, the New Jersey Data Privacy Act adds opt-out rights around profiling that carries significant consequences, and its grace period has now closed. Second, the 2025 deepfake statute created criminal and civil exposure for synthetic audio and video used unlawfully. Cloned voices and fabricated likenesses count.

An AI acceptable use policy is permission, not restriction

Most companies get the framing backwards. They treat policy as a leash. In practice, it works far better as a green light.

Right now your most careful employees are avoiding AI, because nobody told them it was allowed. Your least careful ones are using it for everything. A good AI acceptable use policy inverts that. First, it clears the eighty percent of work that is genuinely low-risk. Then it draws a bright line around the twenty percent that is not.

Banning AI outright produces the worst available outcome. The usage does not stop. Instead, it moves to personal devices and personal accounts, where you cannot see it at all.

Four questions your policy has to answer

A real AI acceptable use policy answers four things for the person sitting at their desk on a Thursday afternoon:

  1. Which tools am I allowed to use?
  2. What can I never put into them?
  3. What am I accountable for when I use the output?
  4. Who do I ask when I am not sure?

If your organization cannot answer all four today, clearly enough that a new hire gets it right in week one, then you do not have an AI problem. You have a policy gap. Currently, it is being filled by whoever happens to be on deadline.

That is a solvable problem. It just does not solve itself.

Marzano HR Consulting

At Marzano HR Consutling, we work with businesses of all sizes to ensure they have policiues that mitigate risk and also increase employee engagement. We understand how AI impacts businesses. Reach out for a no-cost initial consultation.

Frequently asked questions

No statute requires the policy itself. However, the New Jersey Law Against Discrimination holds you liable for discriminatory outcomes from automated hiring tools — including tools you bought rather than built. Under the December 2025 disparate impact rules, the burden shifts to the employer to justify a screening practice with evidence. That evidence is documentation: vendor bias testing, job-relatedness, and the alternatives you considered. So while no law names the policy, the policy is how you produce the defense.

At minimum, four things: which tools are approved, what data can never go into them, who reviews AI output before it leaves the company, and where employees go with questions. The specifics depend on your industry, your client contracts, and the data you hold. Downloaded templates usually fail on the second item — data rules only work when they’re tied to your own classification scheme and your actual obligations. Keep it to one page. If a new hire can’t follow it in week one, it won’t change behavior.

Further reading


Please share