2) Scope of Permitted Uses of Generative AI The AI Officer shall maintain documentation specifying use cases in which generative AI is permitted, prohibited, or requires strict review within the organization. Relying on generative AI for tasks that strongly reflect an organization’s policy positions, or for work involving sensitive personal data or security concerns, may be particularly problematic. The use of generative AI for such tasks should therefore be restricted in advance or made subject to strict review procedures. By clearly defining in advance which uses are permitted, which require heightened scrutiny, and which are not allowed, organizations can enable their members to use generative AI in a consistent and principled manner. Of course, the scope of appropriate generative AI use will vary depending on each organization’s activities and values. For example, some organizations may conclude that relying on generative AI to draft official statements that express the organization’s core messages is inappropriate. Others may determine that, where the organization has issued statements on similar issues many times before and where final review is conducted by humans, limited use of generative AI assistance is acceptable. Each organization is free to adopt its own format, but one practical approach is to maintain and share a written list that categorizes use cases into permitted uses, uses requiring strict review, and 96 97

Select target paragraph3