Workers who disclose using AI can be perceived as 10 times lazier than colleagues who submit identical work, according to Atlassian's Teamwork Lab research. That finding exposes the challenge behind any AI disclosure policy: asking for transparency is easy, but making transparency safe is not.
When employees expect ridicule, lower performance ratings, or extra scrutiny, they hide their tools. Managers then lose the visibility needed to catch weak outputs, protect sensitive information, and spread effective practices. The wrong AI disclosure policy can therefore create less accountability, not more.
The solution is a risk-based operating system rather than a blanket demand to report every prompt. This playbook shows you how to define disclosure thresholds, review AI-assisted work, attribute contributions, protect psychological safety, and assign clear ownership. The goal is honest, responsible use that improves team performance without turning managers into AI police.
An AI disclosure policy must address workplace AI stigma
An effective AI disclosure policy treats stigma as an operational risk. Employees should know that disclosure will trigger the right level of review, not an automatic judgment about effort or competence. Managers must evaluate the quality, evidence, and impact of the work instead of treating AI use itself as proof of either innovation or laziness.
The scale of the perception problem is hard to ignore. Atlassian reported that people who disclosed AI use were judged 10 times lazier despite submitting identical work. A follow-up study surveyed 1,006 US knowledge workers from April 24 through May 6, 2026. Without cultural safeguards, an AI disclosure policy may ask employees to volunteer information that could be used against them.
Workplace AI stigma also changes behavior before a manager sees the final result. An employee may conceal an AI-assisted draft, skip a useful peer review, or quietly move work to an unapproved tool. Another employee may avoid AI altogether, even when it could remove repetitive work. This dynamic is explored further in Coommit's guide to why workers hide AI use from managers.
Your first management move should be explicit: separate tool use from performance evaluation. For example, if two analysts produce the same accurate report, do not downgrade one merely because an approved AI tool helped organize the research. Assess source quality, reasoning, accuracy, and business impact. If the AI-assisted report contains an error, address the missing review step rather than labeling the employee careless.
A credible AI disclosure policy should also protect good-faith reporting. State that employees will not be punished simply for disclosing permitted use or raising an AI-related concern. Misconduct, careless handling of data, and ignored review requirements can still have consequences, but honest disclosure should make responsible correction easier. That distinction is central to reducing workplace AI stigma.
Set risk tiers for disclosing AI use at work
Disclosing AI use at work should depend on risk, reliance, and audience. Require more detail when AI materially shapes a decision, handles sensitive information, or produces external-facing work. Allow lighter disclosure for low-risk assistance such as brainstorming or editing, provided employees still follow approved-tool and data-handling rules.
A practical AI disclosure policy starts with three questions: Could an error harm a customer, employee, or business decision? Did the output depend substantially on AI-generated facts, analysis, code, or recommendations? Was nonpublic data involved? These triggers are more useful than counting prompts or estimating what percentage of a document came from AI.
- Tier 1: Routine assistance. Examples include reformatting approved text, generating brainstorming options, or improving grammar. Team-level documentation may be enough; item-by-item disclosure usually adds little value unless another rule applies.
- Tier 2: Material contribution. Examples include drafting customer content, analyzing research, generating production code, or summarizing a meeting that drives assignments. Disclose the tool's role, identify the human reviewer, and retain supporting evidence.
- Tier 3: High-consequence use. Examples include employment recommendations, legal interpretations, security decisions, financial commitments, or outputs containing regulated or highly sensitive data. Require prior approval, specialist review, or prohibit the use when your legal and security teams determine the risk is unacceptable.
Write these tiers into the AI disclosure policy with examples drawn from your own workflows. A product team might classify alternative headline ideas as Tier 1, an AI-written launch brief as Tier 2, and automated customer eligibility decisions as Tier 3. Employees should not have to decode vague language such as significant use while a deadline is approaching.
Give employees one disclosure format
Keep the disclosure itself short: AI assisted with [task] using [approved tool]. I verified [facts, calculations, code, or sources], and [name or role] approved the final output. A developer using Claude Code or another agent could add which files changed, which tests ran, and which assumptions still need review. The AI disclosure policy should request decision-useful context, not a dump of every prompt.
Publish edge cases and update them during team calibration sessions. If employees repeatedly ask whether a task belongs in Tier 1 or Tier 2, the rule needs clarification. For broader controls involving autonomous tools, pair disclosure with an AI agent governance framework that defines access, authority, checkpoints, and human approval.
Standardize AI output review and AI attribution standards
AI output review should test the claims that matter, while AI attribution standards should show where automation influenced the result and who accepted responsibility. Your AI disclosure policy must connect these practices. Disclosure without review becomes paperwork; review without attribution leaves future users unable to judge the origin, limitations, or approval status of the work.
This matters because AI-generated records are already routine infrastructure. Google reported that more than 110 million attendees had used Meet's Take Notes for Me during the preceding month, an 8.5-fold year-over-year increase. As AI meeting notes reach mainstream scale, teams need a reliable process for turning generated summaries into verified decisions and assignments.
For every material AI-assisted deliverable, require the reviewer to check:
- Evidence: Can important factual claims be traced to a reliable source or original record?
- Completeness: Did the output omit dissent, constraints, dependencies, or unresolved questions?
- Permissions: Was the tool approved for the information it received?
- Quality: Does the work meet the same standard as fully human-produced work?
- Ownership: Is one named person accountable for approving and using the result?
The AI disclosure policy should scale review to consequences. A social post may need a quick factual and brand check. Production code needs tests, security controls, and a responsible maintainer. A meeting summary that changes a deadline should be compared with the recording or agreed decision before tasks are assigned. The related AI meeting bot policy template covers consent, recording, retention, and participation in greater depth.
Attribution should describe contribution, not transfer responsibility to a machine. Do not write that the AI decided or the model approved. Write that an employee used an approved agent to draft an analysis, verified named inputs, and approved the recommendation. Your AI disclosure policy should always leave a visible human owner for decisions that affect people, customers, money, or production systems.
A persistent workspace can make that chain easier to follow. In Coommit, people and AI agents can share one room containing the canvas, files, tasks, decisions, recordings, and work history. An agent can prepare the room, use its context during a call, and execute assigned work afterward, while the team retains the surrounding decision record. The AI disclosure policy still governs access and approval; the workspace keeps those controls close to the work.
Build psychological safety at work before enforcement
Psychological safety at work grows when leaders model the behavior they request. Managers should disclose their own AI use, invite questions before mistakes occur, and respond consistently to good-faith reports. An AI disclosure policy will fail if employees see senior leaders celebrate their own automation while scrutinizing everyone else's use.
The management context is already difficult. Gallup's State of the Global Workplace 2026 reports that manager engagement fell five percentage points, from 27% in 2024 to 22% in 2025. A complicated reporting regime can add pressure to an overloaded middle layer, so the AI disclosure policy should make reviews predictable rather than creating another stream of ad hoc approvals.
Team norms also lag behind adoption. Atlassian's 2026 State of Teams research says only 24% of leaders focus on using AI to improve teamwork. That leaves many organizations optimizing individual speed while ignoring shared context, handoffs, and trust. Managers can close this gap by discussing how AI-supported work moves through the team, not just which employees use a tool.
Run a 30-day policy pilot
- Week 1: Map current use. Collect anonymous examples of common AI tasks, uncertainties, and near misses. Do not use the exercise to identify or punish early adopters.
- Week 2: Calibrate scenarios. Ask the team to classify realistic examples into the three risk tiers. Record disagreements and revise ambiguous language.
- Week 3: Test the workflow. Apply the disclosure and review process to one recurring activity, such as meeting summaries, code changes, or customer drafts.
- Week 4: Retrospect. Review confusion, delays, errors caught, and employee sentiment. Publish changes and identify the policy owner.
Managers should correct process failures privately and share lessons without unnecessary names. They should also offer a clear appeal path when an employee believes a review was inconsistent. An AI disclosure policy earns trust through repeated, fair decisions—not a polished announcement. For more context, see the guide to building AI workplace trust.
Turn your AI disclosure policy into an AI policy template
An AI policy template should state purpose, scope, risk tiers, disclosure triggers, review requirements, attribution rules, prohibited uses, and enforcement ownership. Keep the core policy short enough to use during real work. Put changing tool lists and detailed examples in appendices that security, legal, HR, and operations can update without rewriting every principle.
Preserving human agency should be explicit. Microsoft's 2026 Work Trend Index research draws on 1,800 workers globally, including 819 leaders, 520 managers, and 461 employees. Its human-agency framing supports a concrete rule: automation may prepare options and execute authorized steps, but people need clear authority to question, pause, override, and escalate consequential work.
Copy-and-adapt policy language
Our AI disclosure policy supports responsible use of approved AI tools while preserving human accountability. Employees must disclose material AI contributions and any use involving sensitive information, consequential decisions, external deliverables, or outputs others may rely on as factual. Disclosures must identify the tool's role, the checks performed, and the human owner. Good-faith disclosure will not by itself reduce an employee's performance assessment. All users must follow applicable security, privacy, legal, records, and client requirements.
Adapt that language with your own definitions and escalation routes. Avoid declaring that every use of AI must be reported to a manager; such a rule creates noise and invites hidden workarounds. Also avoid making employees responsible for interpreting every legal or contractual restriction alone. The AI disclosure policy should direct them to an accessible owner when the right action is unclear.
Assign responsibilities in writing:
- Executive sponsor: Sets the risk posture and resolves conflicts between speed and control.
- Policy owner: Maintains examples, approved processes, training, and the revision log.
- Managers: Apply review tiers consistently and protect good-faith disclosure.
- Employees: Use approved systems, disclose when required, verify outputs, and escalate uncertainty.
Measure whether the AI disclosure policy improves decisions rather than merely increasing reports. Track disclosure completeness for sampled high-risk work, review time, material errors caught before release, rework caused by bad AI output, repeat incidents, and employee confidence in reporting. Segment results by workflow so a problem in code review does not lead to unnecessary restrictions on low-risk brainstorming.
Finally, define an incident response. Preserve the relevant artifact, pause further use if harm could continue, notify the responsible security, legal, HR, or operational owner, and examine why controls failed. Focus first on containment and learning. Deliberate concealment or repeated disregard can require discipline, but an honest mistake may reveal that the AI policy template was unclear or that managers never provided a usable review path. Teams facing uneven adoption can also use the manager playbook for closing the AI adoption gap.
Make your AI disclosure policy support human-AI collaboration
A durable AI disclosure policy does four things: it makes reporting safe, scales requirements to risk, connects disclosure to evidence-based review, and leaves a human accountable for consequential work. Start with real workflows, pilot the rules for 30 days, and revise them when employees encounter ambiguity. As agents become active participants before, during, and after team calls, policy must follow the work across that full cycle. Persistent rooms such as Coommit can keep human decisions, agent activity, files, and deliverables in shared context, but trust still depends on clear authority and fair management. The future of human-AI collaboration will not be secured by forced confessions. It will be built through visible ownership, proportionate controls, and a culture where responsible transparency is rewarded.