Thursday, 8 Oct 2026 · Hong Kong Hong Kong and China labour news in English
CLB.org.hk China Labour Bulletin Board
Hong Kong news · dedicated AI coverage 中國勞工資訊板 · Labour, employment, jobs and AI.
Artificial Intelligence

A practical AI-use policy for a Hong Kong workplace

A practical one-page AI-use policy for Hong Kong workplaces, covering approved tasks, prohibited data, human accountability, incident reporting and scheduled reviews, based on local and international frameworks.

A practical AI-use policy for a Hong Kong workplace

Why your workplace needs an AI-use policy now

Hong Kong employees and managers are increasingly turning to generative AI tools to draft emails, summarise reports, generate code and analyse data. Without a clear policy, the same tool that saves time can also expose confidential client information, produce biased outputs or create legal liability under the Personal Data (Privacy) Ordinance. A written AI-use policy sets boundaries everyone can follow, protecting both the organisation and its people.

Approved tasks: what staff can use AI for

A policy should list the specific work activities where generative AI is permitted. Based on the Hong Kong Digital Policy Office’s Ethical AI Framework, approved tasks might include:

  • Drafting internal communications, meeting notes and routine correspondence
  • Brainstorming ideas for presentations or marketing content
  • Summarising publicly available research or internal documents that have been cleared for AI processing
  • Generating boilerplate code or testing data (not production code or real customer data)
  • Proofreading and grammar checking of non-sensitive text

The policy should state that any use outside this list requires written approval from a designated manager or the data protection officer. This prevents “shadow AI” where staff experiment with tools on sensitive work without oversight.

Prohibited data: what must never be entered

Clear prohibitions are essential. The Hong Kong Generative AI Technical and Application Guideline highlights risks including data leakage. Your policy should explicitly ban inputting:

  • Personal data as defined under the Personal Data (Privacy) Ordinance (e.g., names, HKID numbers, phone numbers, addresses, health records)
  • Confidential business information, including financial figures, trade secrets, client contracts and unreleased product plans
  • Legal documents or privileged communications
  • Any information subject to a non-disclosure agreement
  • Login credentials, passwords or security tokens

Staff should be reminded that data entered into public AI tools may be stored on overseas servers and used for model training. Even anonymised data can sometimes be re-identified. When in doubt, the rule is: do not enter it.

Human accountability: who is responsible for AI output

No AI tool can be held accountable for a mistake – the human user and their manager are. The policy must state:

  • Every piece of AI-generated content must be reviewed by a competent human before it is used internally or externally
  • The person who submits AI-generated work takes full responsibility for its accuracy, completeness and compliance with company standards
  • AI outputs must not be copied and pasted without verification of facts, figures and sources
  • Managers are responsible for ensuring their teams understand and follow the policy

The NIST AI RMF Playbook emphasises that organisations should “assign responsibility and accountability for AI-related risks”. In practice, this means naming a specific role – such as a data protection officer or AI ethics lead – who oversees policy compliance and can answer staff questions.

Incident reporting: what to do when something goes wrong

Even with clear rules, mistakes happen. The policy should include a simple incident reporting procedure:

  1. If you accidentally enter prohibited data into an AI tool, or if an AI output contains incorrect or harmful information that has been used, report it immediately to your manager and the designated AI ethics lead
  2. The report should include the date, the tool used, what was entered or output, and any action already taken
  3. The organisation should log the incident, assess potential harm (e.g., data breach, reputational damage) and take corrective action
  4. No disciplinary action will be taken against staff who report an honest mistake promptly – this encourages transparency

This approach aligns with the “Manage” function of the NIST AI RMF Playbook, which calls for incident response plans that are tested and updated regularly.

Review dates: keeping the policy current

AI technology evolves rapidly. A policy written today may be outdated in six months. The policy should include a scheduled review cycle:

  • The policy will be reviewed at least every six months by the AI ethics lead or a designated committee
  • Reviews will consider new AI tools, changes in Hong Kong law (e.g., PCPD guidance), and lessons from any incidents
  • Staff will be notified of any updates within one week of approval
  • All staff must acknowledge the current version annually

The Hong Kong Digital Policy Office’s Ethical AI Framework recommends that organisations “regularly review and update AI governance practices”. A fixed review date ensures this happens rather than being postponed indefinitely.

Putting it all together: a checklist for your one-page policy

When drafting your own policy, include these elements:

  • Purpose – one sentence explaining why the policy exists
  • Scope – who it applies to (all employees, contractors, interns)
  • Approved tasks – a bullet list of permitted uses
  • Prohibited data – a clear list of what not to enter
  • Human review requirement – every output must be checked
  • Accountability – the user owns the output
  • Incident reporting – how and to whom to report problems
  • Review schedule – date of next review and responsible person

A policy is only effective if staff know about it and understand it. Distribute the policy in both English and Chinese, hold a brief training session, and make the document easily accessible on the company intranet. Encourage questions – a culture of curiosity about AI risks is far safer than one of silence.

By adopting a practical, written AI-use policy, Hong Kong workplaces can harness the productivity gains of generative AI while managing the very real risks to privacy, security and reputation. The frameworks published by the Digital Policy Office and NIST provide a solid foundation – but the most important step is to start the conversation in your own team today.

Sources and further reading

Guidance and regulations can change; check the current primary sources before applying them to a consequential workplace decision.

Adam
Editor in Chief

Editor in Chief overseeing CLB.org.hk coverage and editorial standards.