An unapproved AI tool may not be used for organizational work. This applies regardless of the tool's cost, general availability, or how low the risk appears.
AI features newly switched on inside software the Company already approved require separate review. Approving the software was not approving the feature.
Approval is per use case, not per tool. Being cleared to draft marketing copy in a tool is not clearance to process customer financial data in that same tool. A new use case requires a new intake submission.
Check the registry before using any AI tool for organizational work. Any employee may submit a tool for vetting through the AI Tool Intake Form, which routes to the CISO for a risk-tier determination.
| Risk tier | Decision timeline | Note |
|---|---|---|
| Tier 1 | Within 5 business days | Decisions are issued in writing. |
| Tier 2 | Within 15 business days | Approved tools reach the registry within 5 business days. |
| Tier 3 | Within 30 business days | Agentic capability is automatically Tier 3. |
- An AI tool operating under your credentials cannot reach systems, files, or data you are not personally authorized to access.
- Granting an AI system elevated permissions to work around a workflow inconvenience is a policy violation.
- When your access changes through promotion, role change, or departure, your AI access is adjusted at the same time.
- Shared or service-account AI access is prohibited without written CISO approval.
Default AI access by system. Variation from these defaults requires written approval from the CISO.
| System | Default access | Key condition |
|---|---|---|
| FOS | Read + draft | No automatic release of flights. A human reviews and executes all scheduling and dispatch actions. |
| Financial systems | Read + draft | Write access requires President and CFO written approval. No AI-initiated transactions. |
| HR and people systems | Read only | AI may not modify compensation, titles, employment status, or performance records. |
| Code repositories | AI-assisted | Human commit required. No autonomous merge or deploy. |
| Email and messaging | Draft only | No automatic send. Sending requires explicit human action. |
| External-facing content | Draft only | Full human review and approval before publication. |
| Customer and passenger data | Scoped read | Limited to approved fields. Governed by data classification and TSA SSI handling rules. |
| Identity and access management | Read only | AI may not provision, modify, or revoke user access under any circumstances. |
| Payment and transaction systems | Prohibited | No access without explicit AI Steering Committee approval. |
Approved tools can be extended, and the three ways of doing it carry very different weight. Two of them change how a tool works. The third changes what it can reach, which makes it an access decision rather than a preference.
Once a connector is enabled for the organization, you connect your own account to it. That is where the Non-Supersession Rule does its work: the tool sees what you are authorized to see in that system, and nothing more. Enabling a connector does not hand anyone access they did not already have.
Two consequences worth holding onto. A tool with a connector can read content you did not paste, so prompt hygiene applies to what the connector can reach, not only to what you type. And an AI tool reading from a connected system is reading whatever is there, including anything a colleague put in a shared folder without thinking about it.
An agentic system takes actions rather than producing content for you to review. That difference matters, because when the output is an action the mistake has already happened by the time you see it. Content can be corrected before it goes anywhere. An action cannot.
Every autonomous AI action is pre-authorized through a named Action Scope document approved by the AI Steering Committee. That document defines what the agent may do, which systems and data it may reach, the conditions it operates under, the maximum scope of any single action, and the escalation path when it hits a boundary.
Agentic systems may not initiate contact with anyone outside the Company, including customers, vendors, and regulators, without a human reviewing and approving each message.
Use AI freely in your personal life, on personal devices and personal accounts, for any purpose unrelated to Company business. No approval, oversight, or disclosure is required. That freedom ends where personal use touches organizational systems, data, or work product.
- Nothing unapproved on Company equipment. If it is not in the Approved Tool Registry, do not install it, sign into it, or open it on a Company laptop, phone, account, or network. This holds even when what you are doing is personal.
- No Company data in a personal account. Client information, passenger information, anything confidential: it does not go into your own AI account or into an unapproved tool. Your kitchen table counts the same as your desk.
- No Company work on a personal tool. Not drafts, not analysis, not code. Moving the finished output into an approved tool afterward does not fix it, because the data already left.
- Personal output is not Company work product. Something you made on your own account for your own purposes does not get submitted, forwarded, or folded into a Company deliverable.
If you are unsure whether a specific use qualifies as personal, treat it as organizational and apply the approval requirement.
Both AI modules are completed before AI tool access is provisioned. There is no exception for seniority, prior experience, or time pressure.
| Requirement | Detail |
|---|---|
| Before access | Both modules complete. Access is provisioned after, not before. |
| Passing score | 90 percent, so nine of ten. Three attempts, after which AI access is suspended until you pass. |
| Annual | Re-certification on both modules every year. |
| Role change | Within 10 business days of a role change that affects AI access. |
| Triggered | After an AI-related incident, a significant policy change, or deployment of a new high-risk tool. |
Reporting. Submit a safety report, the same way you would for any other safety event. Anonymous and confidential options are both available.
AI-related incidents fall into three categories:
| Report this | What happens |
|---|---|
| Shadow AI use, yours or a colleague's | Triaged by the CISO. During the amnesty window, no disciplinary consequence. |
| Suspected data exposure through an AI tool | Category A. Triaged by the CISO and Director of Safety within 1 business day. |
| A hallucination that drove a material decision | Category B. Same channel and triage timeline. |
| An AI agent acting outside its authorized scope | Category C. Addressed whether or not harm resulted. |
| A deepfake, AI fraud attempt, or AI phishing | Triaged by the CISO. External Legal engaged where there is legal exposure. |
Five resources exist to make all of this easy to act on. Each has its own page and QR code, posted in FOS under Compliance, Documents, Company, Other.
| Resource | Use it when |
|---|---|
| Approved Tool Registry | Before using any AI tool for Company work. Every employee is responsible for this check. |
| AI Tool Request | Something you want is not on the registry. Any employee may submit. |
| AI Amnesty Disclosure | You are already using something that is not on the registry. No consequence during the window. |
| Agentic AI Action Scope | You are deploying AI that takes action on its own. Automatically Tier 3. |
| AI Policy Exception | You need a time-limited exception. Caps at 90 days, renewable only by re-approval. |
Ask Gold Aviation is the Company's own assistant, built in Claude with our manuals, procedures, and company context loaded in. It is subject to this policy like any other tool, so check the Approved Tool Registry for its current status and approved use cases before relying on it for Company work.
Getting better at this. Nothing in this policy discourages using AI well; the standard is that you own what it produces, and the better you are at prompting, the less there is to fix. Anthropic publishes free training at anthropic.skilljar.com. The AI Fluency track is written for general users rather than developers and is the right place to start. It is optional and it is not a substitute for this module.
Everything in both modules reduces to this. Run it before anything AI-assisted goes anywhere.
| Check | Why |
|---|---|
| The tool is in the Approved Tool Registry, for this use case | Approval is per use case, not per tool. |
| Nothing prohibited went into the prompt | No SSI, personal, health, payment, or personnel data, in any tool. |
| The output has been read in full | Not skimmed, not summarized. All of it. |
| Material facts and figures verified | Against the source, not against the tool. |
| Edited into the Company's voice | And anything you cannot stand behind removed. |
| The minimum review standard for this output type has been met | Some types need legal, numerical, or manager sign-off. |
| AI involvement disclosed where required | Regulators, client deliverables, and material decisions. |
| You could defend it if questioned | That is the standard, and it is the last check for a reason. |
Knowledge Check
Complete all nine sections above to unlock the assessment
Complete all 9 content sections to unlock the assessment.