The Inner Circle

 View Only
Expand all | Collapse all

Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

  • 1.  Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Mar 23, 2023 08:17:00 AM

    Anyone aware of templates or guidance for Acceptable Use Policy (AUP) for AI?



    ------------------------------
    Alex Sharpe
    Principal
    Sharpe42
    [email protected]
    Co-Chair Philosophy & Guiding Principles Working Group
    Co-Chair Organizational Strategy & Governance Working Group
    ------------------------------


  • 2.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Mar 24, 2023 08:10:00 AM

    So I would think a good template would be OpenAI's own policy at https://openai.com/policies/usage-policies.   I have found that ChatGPT itself can provide a pretty complete structure as well.



    ------------------------------
    Leo Magallon
    Senior Security Consultant
    Set Solutions, Inc.
    ------------------------------



  • 3.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Mar 30, 2023 11:35:00 AM

    I have not seen one yet but I imagine you could ask ChatGPT to write one for you. 😂



    ------------------------------
    Aaron Faby CISSP, CCSK
    Vice President, Information Security
    TWE Solutions
    ------------------------------



  • 4.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Mar 30, 2023 11:35:00 AM

    We are presently working with our legal team to create one specific to our business. There are nuances we want to ensure are addressed for us such as information leakage and copyright material in responses.



    ------------------------------
    Kathleen Bellotti
    Information Security Director
    U.S. Venture
    ------------------------------



  • 5.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Mar 31, 2023 01:16:00 AM
    Edited by Paul Wright Mar 31, 2023 01:16:48 AM

    @Kathleen Bellotti
    It's interesting to see you mention information leakage and copyright material.
    I learned yesterday that AI has been shown to be able to 'lie', which is an incredible concern.  It is interesting also that governments are asking for a 'pause' on it's use as there are no guiding principles.
    I suspect this conversation won't go away any time soon - exciting, but scary times!
    I will be putting this on my list of policies that need to be written!



    ------------------------------
    Paul Wright
    Genomics England Ltd
    Genomics England Ltd
    ------------------------------



  • 6.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Apr 04, 2023 11:58:00 AM

    Garbage in garbage out as they say.
    the key here is to treat it like an intern and be as specific about ur needs as you can through carefully crafted prompts.
    This is spinning off a whole new branch of "prompt engineering".
    This is a very powerful tool and it will be a shame to ban it's use like the large US banks have been doing.. they have legit concerns but a good AUP should help use it to its fullest potential.



    ------------------------------
    Uday Shetgeri
    Frost Bank
    Frost Bank
    ------------------------------



  • 7.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Apr 28, 2023 08:29:00 AM
    Edited by Rajiv Gunja Apr 28, 2023 08:29:51 AM

    @Kathleen Bellotti  -- I am interested in some of the lessons learned that you might have come across while drafting your document. Copyright (3rd party, our own, etc) materials, company specific info, proprietary code, architectures, data are pretty straight forward. Would like to know what was not obvious or apparent when you started the process and learned along the way. 

    Please share what you can. 



    ------------------------------
    ---
    Rajiv G Gunja

    Manager Infrastructure / Securiy
    Raytheon IIS / NASA (GSFC)
    Riverdale, MD

    ------------------------------



  • 8.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Mar 30, 2023 11:35:00 AM

    Hi @Alex Sharpe That's a really great question (and I'll be watching for other's responses with interest!)

    It is certainly something that all companies should consider, and we are certainly already validating code prior to release but of course the introduction of AI does introduce new threats.

    Without sounding flippant, I did reach out to ChapGPT to ask it to write 'our' AUP, and if nothing else it gets you from a blank piece of paper to a great starting point to 'humanise' and mature.

    I asked ChatGPT to "Write me an acceptable usage policy for ChatGPT" and it told me it's own policies, so I tried again with, "Write me an acceptable usage policy for ChatGPT for my developers to abide by within our company" and the response wasn't vastly different.

    I think it's missing the key elements, "thou shalt not release code without rigorous testing", "thou shalt not leave back doors in our code", etc.

    I watch this post with interest.  Good luck.

    Regards

    Paul (new member, first time poster, non-techie!)



    ------------------------------
    Paul Wright
    Genomics England Ltd
    Genomics England Ltd
    ------------------------------



  • 9.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Apr 05, 2023 08:26:00 AM

    Hi Alex,

    I know that Jim R & Michael R have posted a lot of interesting doc's around securing, governing AI etc

    Best 



    ------------------------------
    Emilio Mazzon CISM, CISA, CEng, CISM, CITP, CSA Board Director
    VP
    SNCL
    ------------------------------



  • 10.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Apr 07, 2023 12:05:00 AM

    @Emilio Mazzon  would it be possible to share or direct me to the links to the docs around governing AI, that you referred to? 
    Thank you for the help!


    Best Regards



    ------------------------------
    Mayurakshi Ray
    Advisor, Board Member
    CEO and Founder - WeaveStory
    ------------------------------



  • 11.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Apr 07, 2023 01:34:00 AM

    Hi,

    See, https://circle.cloudsecurityalliance.org/community-home1/librarydocuments?communitykey=0ba1c39f-45a1-4b95-859e-1e837232ba13&LibraryFolderKey=&DefaultView=

    Michael R



    ------------------------------
    Michael Roza CPA, CISA, CIA, CC, MBA, Exec MBA
    ------------------------------



  • 12.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Jun 15, 2023 11:50:00 PM

    https://circle.cloudsecurityalliance.org/viewdocument/eu-ai-standardisation-landscape-sta?CommunityKey=0ba1c39f-45a1-4b95-859e-1e837232ba13&tab=librarydocuments

    Michael Roza wrote a few documents way back in 2021 on AI and can be used for baseline reference.



    ------------------------------
    Srikanth Katuri
    CIOBP
    IQVIA
    ------------------------------



  • 13.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Apr 27, 2023 09:36:00 AM

    We have written an article about data protection restrictions for the use of ChatGPT in a company. 

    At the end of the article you find a free template for an "acceptable use policy ChatGPT" in word to download: 


    https://simpliant.eu/insights/is-chatgpt-gdpr-compliant


    AI usage in a company is very contextual so you probably need to adust it to your needs.

    I think it could be a good starting point though and hope it helps.

    Steffen Groß | Partner (Attorney-at-law, Germany)

    www.simpliant.eu | Fasanenstr. 12, 10623 Berlin

    e: [email protected]



    ------------------------------
    Steffen Gross
    Attorney-at-law
    Simpliant
    ------------------------------



  • 14.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted May 09, 2023 09:33:00 AM

    Hi all,

    I am addressing this issue in my own organization as well.  In addition to the more obvious problems with data leakage and personal data protection, there are two areas that are easier to overlook -- ethical and reputational concerns.

    One clear ethical concern is the use of generative services to produce complete or significant portions of a work product that a worker may assert as their own original work. I know many organizations may not have this as a top concern, but if there isn't some transparency around such significant "outsourcing" of labor, it can be a performance management issue that clouds the evaluation of a worker's capabilities and performance. This may be more of a concern for positions that are expected to produce some sort of intellectual capital.

    The reputation concern is related. If you have a worker including generated material in what is supposed to be an original work product, and that material is eventually included in some finished IP or copy, there could be issues due to all of the known accuracy and plagiaristic characteristics of these tools. Related to the first concern, if there is inadequate transparency, or perhaps even if proper citation is made, does the business want want to acknowledge its use.



    ------------------------------
    Ari Benderly
    CISO
    European Spallation Source ERIC
    ------------------------------



  • 15.  RE: Acceptable Use Policy (AUP) for Artificial Intelligence like ChatGPT

    Posted Jun 23, 2023 11:06:00 AM

    Alex,

    How about this https://compliancespecialistsusa.com/artificial-intelligence-acceptable-use-policy/



    ------------------------------
    Andrew Crawford
    Compliance Specialists
    Compliance Specialists
    ------------------------------