How to Write a Code of Conduct for AI Use at Work

Photo: Brett Jordan / Pexels
Key takeaways
- A code of conduct explains the 'why' behind your AI rules; a usage policy handles the 'what' and 'how'.
- Five principles cover most of it: human oversight, transparency, fairness, privacy, accountability.
- It works best shared publicly and tied directly to your operational policy, not left to stand alone.
- Keep it to one page, written in 'we' language, signed off by one named leader.
- Pair it with a proper usage policy so your stated values and your actual rules match.
An AI usage policy tells your team what they can and cannot do with AI tools. A code of conduct for AI goes a layer deeper: it sets out the values behind those rules, not just the rules themselves. It answers why your organisation uses AI the way it does, not only what is allowed. Boards, investors and enterprise customers increasingly want to see this stated somewhere they can read in five minutes, not buried in clause 14 of a policy document. Written well, a code of conduct becomes the reference point every other AI decision gets measured against. Written badly, it is a page nobody remembers past the first read.
How it differs from an AI usage policy
An AI usage policy is operational. It names the approved tools, sets data-handling rules, and says who to tell if something goes wrong. A code of conduct for AI is principled. It states your stance on fairness, transparency, human oversight and accountability, the ideas that justify the rules rather than the rules themselves. Think of the policy as the how and the code of conduct as the why. In practice, most organisations need both. The policy tells a new starter exactly what to do on day one. The code of conduct tells a customer, an investor, or a new hire's future manager what your organisation believes about AI, in language they can quote back to you. Skip the code of conduct and your policy reads as a list of restrictions with no stated purpose. Skip the policy and your code of conduct is good intentions nobody can act on. See how to write an AI usage policy for the operational half of this pair.
What a good code of conduct actually contains
Five principles cover most of what an AI code of conduct needs to say. Human oversight: AI output gets a human review before it shapes an important decision or goes out to a customer. Transparency: the organisation says when AI was materially involved in something, rather than letting people assume it was human-made throughout. Fairness: AI use is checked for discriminatory patterns, particularly anywhere it touches hiring, pricing or customer decisions. Privacy: AI tools only process data where the right contractual and technical safeguards exist, no exceptions for convenience. Accountability: one named person owns AI use across the organisation, so 'nobody's job' never becomes the answer to a question. These five map reasonably well onto the broader characteristics the NIST AI RMF uses to describe trustworthy AI, so borrowing its language is a shortcut, not a sign you need the full framework. Each principle should get a sentence or two, not a paragraph. The temptation is to write a mission statement; resist it. A code of conduct a new employee can read in ninety seconds and repeat back accurately has done its job. One that needs a training session to explain has already failed the format.
Does a code of conduct replace the need for a policy?
No, and treating it as a substitute is the most common mistake. A code of conduct states values; it does not tell someone which tools are approved or what to do with a client's email address. Without an operational policy behind it, a code of conduct is unenforceable, nobody can be held to a value statement the way they can be held to a specific rule. The reverse failure is just as common: a detailed usage policy with no stated principles behind it, which reads as arbitrary even when the rules are sound. Use our free AI usage policy generator to produce the operational document first, then write the code of conduct as a short cover statement that explains the thinking behind it.
Tone and audience: who actually reads this
A usage policy is read by staff. A code of conduct is often read by people who will never open the policy: customers doing due diligence, investors during a raise, a candidate deciding whether to accept an offer. Write it in the first person plural, 'we believe', 'we commit to', not the second-person, 'you must' language of a policy. Keep it to one page. Avoid legal hedging; a code of conduct full of 'reasonable efforts' and 'where practicable' reads as a document written to avoid a lawsuit rather than one written to state a position. If your legal team wants to soften a line, ask what specifically worries them, then fix that sentence rather than hedging the whole document.
Where it earns its keep
A 25-person design studio picked up an enterprise client that needed a security and ethics questionnaire completed before signing. Two of the questions asked, in different words, what the studio's principles were for using AI in client work; a data-handling clause alone did not answer either one. The studio's operations lead pulled together a one-page code of conduct that afternoon, covering the same five principles above, and pointed the client's procurement team to it alongside the existing usage policy. The questionnaire cleared in a day. What mattered was not the document's length, it was one page, but that it existed, was dated, and matched what the studio's usage policy already said in practice. Without it, the studio would have been improvising an answer to a question it should already have covered.
What happens if you publish a code of conduct nobody follows?
It becomes a liability rather than an asset. A public statement about fairness and transparency that does not match actual practice is worse than no statement at all, because it gives a customer, journalist or regulator a specific claim to hold you to. If your code of conduct says AI output gets human review before it reaches a client, and an unreviewed AI draft goes out under your name, that gap is now the story. The fix is not softer language, it is tighter alignment: only commit to what your usage policy and your actual tooling already support, and update both documents together whenever either one changes.
Making it real rather than decorative
Put the code of conduct in onboarding, not just on the website. Reference it when a genuinely difficult AI decision comes up, a client asking you to disclose AI use, a hiring manager wondering whether an AI-screened shortlist is fair, and let it settle the question rather than sitting there as decoration. Cross-link it directly to your usage policy and your AI literacy training so a new starter sees the values and the rules in the same session, not as two disconnected documents six months apart. Review it annually alongside your policy. A code of conduct that never changes as your AI use grows either was not specific enough to begin with, or nobody is checking whether you still mean it.
Start with the values, then generate the rules
The order that works best in practice: settle on your five principles, write them down on a page, then build the operational policy that puts them into effect. If you already have a policy but no code of conduct, that is a missing page, not a missing programme. It is an afternoon's work, not a quarter's. For the day-to-day rules employees actually need, see our guide to AI policy for employees, and for the broader thinking this connects to, see our guide to responsible AI.
| Attribute | AI Usage Policy | Code of Conduct |
|---|---|---|
| Purpose | Sets operational rules: approved tools, data handling, reporting | States the values behind the rules: fairness, oversight, transparency |
| Primary audience | Staff who use AI day to day | Staff, customers, partners, investors |
| Tone | Instructional, specific | Aspirational, first person plural |
| Typical length | One to three pages | Under one page |
| Enforceability | Backed by a disciplinary process and attestation records | Backed by leadership example and cross-linking to the policy |
“A code of conduct without an operational policy behind it is a poster. A policy without a stated set of values behind it is just a list of prohibitions.”