Privacy & Security

AI in the Workplace: Acceptable Use and Compliance Awareness Training

August 23, 2026·8 min read·Certified Training USA

The regulatory area: Fragmented and Still Moving

Unlike anti-bribery law or the GLBA Safeguards Rule, there is no single comprehensive federal statute governing how employees use AI tools at work. What exists instead is a growing patchwork of state and city laws, most of them focused specifically on AI used in employment decisions rather than on general employee AI use, and that patchwork is actively expanding and changing as this course is being written.

New York City's Local Law 144 is the most established of these laws. It requires employers using an automated employment decision tool, meaning software that substantially assists or replaces human decision-making in hiring or promotion, to conduct an independent bias audit of that tool and to provide notice to candidates before using it. It applies specifically to the tools themselves, not to general employee use of AI chat assistants for drafting emails or summarizing documents.

Illinois amended its Human Rights Act to address AI's use in employment decisions, with those amendments taking effect January 1, 2026. Colorado took a different path: its original 2024 AI Act was replaced by a revised framework under SB 26-189, which takes effect June 30, 2026. The fact that Colorado has already revised its own AI law once, before the original version even took full effect, is a useful signal of how unsettled this area still is.

For a compliance officer trying to build a durable program, the honest takeaway is that no single training course or policy document can promise full compliance with every current and future state AI employment law, because those laws are still being written and rewritten. What this course can responsibly do is build the employee-facing foundation, safe and appropriate AI use, that any broader compliance strategy will need regardless of how the specific state rules continue to evolve.

What This Training Covers, and What It Doesn't

This course is employee-use awareness training. It teaches staff how to use AI tools, generative chat assistants, writing tools, coding assistants, and similar products, safely and appropriately as part of their daily work. That includes understanding what kinds of company or customer data should never be entered into a public AI tool, how to verify AI-generated output for accuracy before relying on it, and when disclosure of AI assistance is expected or required.

It is deliberately not a bias-audit service, and it does not evaluate, certify, or fix an employer's AI-powered hiring, screening, or promotion tools. Bias auditing of automated employment decision tools, the kind of audit NYC Local Law 144 requires, is a separate, far more technical undertaking that involves statistical analysis of a specific tool's outcomes across protected categories, typically performed by a specialized auditor with access to the tool's underlying data and decision logic.

This distinction is worth stating plainly because it is easy to conflate the two: a company that has its employees complete AI acceptable-use training has done something genuinely useful for data privacy, confidentiality, and responsible use, but it has done nothing to satisfy a bias-audit requirement for its hiring software. Those are two different compliance obligations addressing two different risks, and treating one as a substitute for the other would leave a real gap.

If a company uses any automated tool in hiring, screening, or promotion decisions, whether that is a resume-scoring algorithm, a video-interview analysis tool, or an AI-assisted applicant tracking system, that use case needs its own, separate compliance review against laws like NYC Local Law 144, Illinois's amended Human Rights Act, and Colorado's SB 26-189, independent of whether employees have completed this general-use training.

Does this training make our AI hiring tools legally compliant?
No. This is employee-use awareness training. Compliance for AI-powered hiring or screening tools under laws like NYC Local Law 144, Illinois's amended Human Rights Act, or Colorado's SB 26-189 requires a separate bias audit and technical review of the tool itself, not employee training.

Who Needs This Training

Any employee with access to a generative AI tool, whether that access is officially sanctioned by the company or is a personal account an employee uses on a work device, is a reasonable candidate for this training. In practice that now covers a large share of most office workforces, since AI writing assistants, coding tools, and chat interfaces have become common default features in everyday software rather than specialized tools used by a narrow group.

Employees who handle sensitive company, customer, or client data deserve particular attention, because the most common real-world AI misuse risk is usually not malicious. It is an employee pasting confidential information, a customer's personal data, a draft contract, unreleased financial figures, into a public AI tool without realizing that data may be stored, logged, or used to train the underlying model depending on the tool's terms of service.

Managers and team leads who are considering or already using AI tools to help evaluate employee performance, draft disciplinary documentation, or screen job candidates need an additional layer of awareness beyond general use, since those specific use cases edge toward the kind of automated employment decision-making that state laws like NYC Local Law 144 regulate directly.

IT, legal, and compliance staff building or approving the company's list of sanctioned AI tools are a natural audience as well, since they are the ones translating this training's general principles into specific, enforceable rules about which tools employees may use and for what purposes.

Does This Make Your Hiring AI Compliant?

No, and this is worth restating clearly because it is the single most important distinction in this course. If your company uses an automated tool to screen resumes, rank candidates, conduct or analyze video interviews, or otherwise substantially assist a hiring or promotion decision, that tool falls under a different, more technical set of compliance obligations than general employee AI-use training covers.

NYC Local Law 144 requires an independent bias audit of the tool itself, conducted against real outcome data, along with public posting of a summary of that audit and advance notice to candidates. Illinois's amended Human Rights Act, effective January 1, 2026, and Colorado's SB 26-189, effective June 30, 2026, impose their own distinct requirements around AI use in employment decisions, and none of these obligations are satisfied by employees completing a general acceptable-use course.

The gap here is a common and understandable one: a company rolls out employee AI training, feels reassured that it has addressed its AI compliance exposure, and does not realize that its recruiting team's AI-assisted applicant tracking system is a separate, unaddressed compliance obligation entirely. That gap is exactly the kind of blind spot worth flagging directly to a compliance officer rather than leaving implicit.

If a company is using, or considering using, any AI tool in hiring, screening, or promotion decisions, the right next step is a dedicated legal and technical review of that specific tool against the applicable state and local laws, not an assumption that general employee training has already covered it.

How this standard compares, by OSHA citation count
Fall Protection
30,929
Hazard Communication
28,898
Respiratory Protection
17,672
Lockout/Tagout
17,359
Powered Industrial Trucks
12,902
Scaffolding
11,522
Walking-Working Surfaces
11,110
Machine Guarding
9,782
The course
AI in the Workplace: Acceptable Use and Compliance Awareness
Documents this training with an instant, verifiable certificate. $49.
View the course

What a Defensible Acceptable-Use Policy Looks Like

A defensible AI acceptable-use policy starts with a clear, specific list of approved tools rather than a vague statement that employees should use AI responsibly. Employees need to know exactly which tools the company has vetted and approved, whether that is a specific enterprise AI product with contractual data protections or a short list of consumer tools deemed acceptable for low-sensitivity tasks.

The policy should draw a clear line around what data can never be entered into a public or non-enterprise AI tool: customer personal information, unreleased financial or business information, proprietary source code, legal documents under privilege, and anything covered by a confidentiality agreement with a third party. This is the single most common real-world failure point, and a policy that addresses it clearly prevents most incidents before they happen.

The policy needs a verification standard: employees should understand that AI-generated content can be confidently wrong, and that output used in anything customer-facing, legally significant, or financially material needs to be checked against a reliable source before it is relied upon or sent out. This is particularly important for anything resembling legal, medical, or financial guidance, where an AI tool's fluent-sounding but incorrect answer can create real liability.

Finally, the policy should say plainly when AI-assisted work needs to be disclosed, whether that is internally to a manager, or externally to a client or customer, since expectations here vary by industry and by the specific state and local laws that continue to develop, and a policy that leaves this ambiguous puts employees in the position of guessing.

Does Online Training Satisfy Emerging Requirements

For the employee-use awareness component this course covers, well-built online training is a genuinely sound way to deliver the content, since the goal is building consistent understanding across a broad workforce rather than a highly technical or role-specific certification. A clear, scenario-based online course covering data handling, verification, and appropriate use gives most employees what they need.

For the bias-audit and automated-employment-decision-tool obligations under laws like NYC Local Law 144, no training course, online or otherwise, satisfies those requirements, because those obligations are about auditing a specific tool's technical outcomes, not about training people. This distinction bears repeating because it is the one most likely to be misunderstood by a company assuming that training equals compliance across the board.

Because this regulatory area is still actively changing, any training content, online or otherwise, has a shorter practical shelf life than something like GLBA or FCPA training, where the underlying statute has been stable for years. A course written against today's state of the law should be expected to need meaningful updates as Illinois's amendments take effect in January 2026, as Colorado's revised framework takes effect in June 2026, and as other states introduce their own rules.

The practical implication for a compliance officer is to treat this training as a living document rather than a one-time purchase, and to build in a specific process for checking whether the content still reflects current law at least once or twice a year given how quickly this area is moving.

How Often to Update Training and Policy

There is no established legal mandate for how often AI acceptable-use training must be refreshed, largely because this is such a new area that most of the relevant laws are focused on the tools themselves rather than on employee training cadence. That absence of a fixed rule is not a reason to treat the training as a one-time event; it is a reason to build in a deliberate review cycle.

A twice-yearly review of both the training content and the underlying acceptable-use policy is a reasonable practice given how quickly this area is moving, particularly around the effective dates of new state laws like Illinois's January 2026 amendments and Colorado's June 2026 framework. A company that reviews its policy only once a year risks being caught flat-footed by a law that took effect mid-cycle.

New employees should complete this training as part of onboarding rather than waiting for the next scheduled refresh, given how central AI tools have become to everyday office work and how quickly an untrained new hire could inadvertently expose sensitive data to a public AI tool in their first week.

Any time the company approves a new AI tool for use, or a new use case for an existing tool, such as beginning to use AI in any part of the hiring process, that specific change should trigger a targeted update to training and policy rather than waiting for the next scheduled cycle, since that is exactly the kind of change that can create new compliance exposure overnight.

Is there one federal law that governs workplace AI use?
No. There is currently no comprehensive federal AI-employment statute. The real obligations exist at the state and city level, including NYC Local Law 144, Illinois's amendments effective January 1, 2026, and Colorado's SB 26-189 effective June 30, 2026, and this area is still actively changing.

Practical Guidance for Compliance Officers and Employees

For a compliance officer, the first practical step is an internal inventory: find out what AI tools employees are actually using today, including tools that were never formally approved, before writing a policy that assumes a clean slate. Shadow use of consumer AI tools on work devices is extremely common, and a policy built without accounting for that reality will be ignored rather than followed.

Second, separate the two compliance tracks explicitly in your own planning: general employee-use training, which this course addresses, and automated-employment-decision-tool compliance, which requires a dedicated legal and technical review against laws like NYC Local Law 144, Illinois's amendments, and Colorado's SB 26-189. Keeping these as two clearly distinct workstreams, rather than one blended AI compliance project, avoids the gap described earlier in this article.

For an individual employee, the practical rule that covers most situations is straightforward: if you would not paste a piece of information into a public forum or send it to a stranger, do not paste it into a public AI tool either, unless the company has specifically approved that tool for that purpose. When in doubt about whether a tool or a use case is approved, ask before using it rather than after.

Every employee should also get comfortable treating AI output the way they would treat a first draft from a junior colleague who has never seen the company's specific context: often useful, sometimes confidently wrong, and always worth a second look before it goes anywhere that matters, whether that is a customer, a regulator, or a court.

Frequently asked questions

What does this course actually teach employees?

How to use AI tools safely at work: what data should never be entered into a public AI tool, how to verify AI-generated output before relying on it, and when to disclose AI assistance.

Does this course cover bias audits for hiring algorithms?

No. Bias auditing of automated employment decision tools is a separate, technical compliance obligation under laws like NYC Local Law 144, and requires a dedicated audit of the tool itself, not employee training.

How often does our AI acceptable-use policy need to be updated?

There is no fixed legal requirement, but given how quickly this regulatory area is changing, a twice-yearly review is a reasonable practice, with additional updates whenever a new AI tool or use case is approved.

Who should take this training?

Any employee with access to a generative AI tool, whether company-sanctioned or personal, along with managers considering AI-assisted evaluation and IT, legal, or compliance staff managing approved-tool lists.

What happens if an employee pastes confidential data into a public AI tool?

Depending on the tool's terms of service, that data may be stored, logged, or used to train the underlying model, which can create a genuine data exposure incident. This course teaches employees to recognize and avoid that risk before it happens.

Get your team certified

Every course maps to the regulation it satisfies and issues a verifiable certificate. Browse the catalog and certify your workforce today.

See all courses