Skip to content

Revisions

This page tracks revisions to the AI Policies & Guidelines.


Revisions

Date Author Change Details
2026-03-16 FRT Released AI Policies & Guidelines AI Policies & Guidelines were released
2026-03-16 FRT Added Training section Added mandatory and recommended training tables to Getting Started & Best Practices
2026-03-17 FRT Updated links Updated training resource links and titles, added new recommended training resources to Getting Started & Best Practices
2026-03-18 FRT Added Usage Tiers (traffic light) Introduced Green/Yellow/Red usage tiers to clarify which AI tools may be used based on data sensitivity, replacing the previous binary approved/not-approved model
2026-03-20 FRT Renamed Architecture Board to AI CoE Replaced all references to "Architecture Board" with "AI CoE" (Centre of Excellence) across all AI policy & guideline files. Added AI CoE contact email (aicoe@dhigroup.com)
2026-03-20 FRT Added Prohibited AI Tool Categories Added new section covering AI Browser Agents and Fully Autonomous AI Development Agents, explaining why these categories are not permitted at DHI
2026-03-20 FRT Fixed training table references Changed "Copilot users" to "GitHub Copilot users" in Getting Started training tables
2026-04-02 FRT Merged Internal data sensitivity tiers Merged "Internal - Low sensitivity" and "Internal - High sensitivity" into a single "Internal" tier. Removed requirement for explicit justification and manager approval. Updated Yellow usage tier description accordingly
2026-06-01 FRT Fixed broken cross-page links Corrected readme.md links to README.md (case-sensitive on the published site) and fixed the broken "Data Protection" anchor (triple hyphen --- to single -) across General Purpose, Software Development, Value Add in Product, Getting Started, and Roll-out Status pages. Affected links: AI Policies & Guidelines, Usage Tiers, data sensitivity tiers, and data protection rules
2026-06-01 FRT Clarified classification as primary safeguard Added a note to the Data Protection section explaining that correctly classified confidential/PII data is inaccessible to Microsoft 365 Copilot, while the Green/Yellow/Red tiers remain the user's responsibility for data that is not yet correctly classified
2026-06-02 FRT Added Claude Cowork (general-purpose) Added Claude Cowork to the General-Purpose AI Tools approved-tools table as "under review", with a note explaining its higher risk profile vs. MS 365 Copilot (local agentic access to files/apps/browser/connectors; Anthropic excludes Cowork from Audit Logs, Compliance API and Data Exports; not for regulated workloads). Pending Legal and IT Security review
2026-06-02 FRT Updated roll-out status Updated GitHub Copilot status to rolled out (~120 staff in T&I); recorded Claude Code pilot dates (approx. 1 April - 1 July 2026, after which continuation is assessed); added Claude Cowork (under Legal/IT Security review, not yet approved) and a Perplexity trial (ongoing, Green-tier only)
2026-06-19 FRT Updated AI tool access links Wired each tool to its specific ServiceNow Employee Center catalog item (GitHub Copilot, Claude Code, Perplexity Pro) and restructured the Accessing AI Tools page so each tool section owns its seat model and request link; moved the Claude Code premium-seat upgrade detail into the Claude Code section and made the tool-choice section decision guidance only
2026-06-19 FRT Perplexity Pro made available Changed Perplexity from "trial ongoing" to "Perplexity Pro / Available" on Accessing AI Tools and Roll-out Status, and added Perplexity Pro (DHI licence) to the General-Purpose approved-tools table, approved for Green and Yellow use
2026-06-19 FRT Added Claude Code training recording and Viva Engage channel Added the recorded internal Claude Code Trial training session to the recommended training table, and linked the "AI in Software Development" Viva Engage channel under Sharing Knowledge in Getting Started & Best Practices
2026-08-12 FRT Added AI in Software Development as the governing page Added a new governing page for AI in software development covering the target state, hybrid development model, risks, developer responsibility, benefits, and the transferable capabilities DHI aims to build. It is now the entry point for the software development category
2026-08-12 FRT Moved Developer Responsibility out of the AI Policies & Guidelines Moved the Developer Responsibility rules (understand / test / review / own) from AI Policies & Guidelines section 5 into the new AI in Software Development page. The AI Policies & Guidelines retain the cross-category accountability statement and the human-in-the-loop model, which apply to all AI usage
2026-08-12 FRT Renamed the development tools page The former "AI in Software Development" nav entry is now "AI Development Tools", matching its content: approved tools and their conditions, MCP server policy, and AI in CI/CD pipelines. It remains the single source of truth for tool approval status
2026-08-18 FRT Claude Code and Claude AI treated as one tool One DHI seat covers both, so they share one entry and the same approval for Green and Yellow use, with no separate request. Personal claude.ai accounts remain Green only
2026-08-18 FRT Removed transitional licence wording The GitHub Copilot and Claude enterprise agreements are in place, so the guidance points at DHI seats instead of allowing personal licences
2026-08-18 FRT One centrally maintained list of approved tools The AI CoE maintains a single, centrally published list of approved AI tools, held in the three approval tables. Other DHI guidance references those tables rather than reproducing them, so tools can be added or removed without a policy revision. Every approved tool must have a confirmed non-training data clause or equivalent contractual protection
2026-08-18 FRT AI CoE and CISO approve new tools jointly Introducing, piloting, or connecting any new AI tool, service, or MCP server for Yellow or Red use now requires explicit written approval from the AI CoE and the CISO, with Group Legal, IT, and Core IT consulted as needed. Retires the earlier "Legal and IT approval" route in the Yellow tier, and updates the MCP approval categories and the Claude Cowork review status to match
2026-08-18 FRT Risk-based AI-content disclosure Disclosure is now proportionate to use rather than a single rule. Internal human-reviewed text or code needs no label; content published or shared without human review must be marked "Content generated by AI and may be incorrect."; client-facing content is disclosed where a contract, regulation, or reasonable expectation requires it; AI-generated media shared externally is always labelled per EU AI Act Article 50. Adds the chatbot disclosure requirement for systems reaching external users
2026-08-18 FRT Reframed the enterprise capability table Section 3 is now "What Enterprise AI Agreements Give You". It opens with the one rule that binds - no DHI or client data in a consumer or free-tier service that may train on it - and presents the five capabilities as advantages to weigh rather than requirements every tool must meet. The training opt-out remains non-negotiable for Yellow and Red work
2026-08-18 FRT Personal data split across the classification line Ordinary personal data (names, work email addresses, job titles) is Confidential and allowed at Yellow, conditional on DHI holding a data processing agreement with the vendor and on minimising to what the task needs. Sensitive personal data is Strictly Confidential and never permitted in any AI tool: GDPR Article 9 and 10 data, plus national ID, passport and payment details. Written consent does not unlock it, so it is no longer a Red-tier task. Red now covers confidential client data. Credentials and secrets remain prohibited at every tier
2026-08-18 FRT Strictly Confidential stated as out of bounds for AI The prohibition attaches to the classification rather than to personal data alone, so it now covers non-personal Strictly Confidential material as well: HR records, undisclosed financial and merger or acquisition information, contractual records, and third-party information held under NDA. Written client consent reaches Confidential client data only and does not unlock Strictly Confidential material
2026-08-27 FRT Added AI in Advisory Added a guideline for the use of AI in client advisory projects, covering permitted use, internal project tools and automation, sharing of internally developed tools, technology alignment and reuse, third-party components and licensing, deliverables provided to clients, contributing to DHI software, review and validation, and accountability. Tools shared beyond their author must be hosted in a proper DHI repository and reviewed by T&I, while automation of a person's own workflow needs no further review, and ownership of digital deliveries to the market rests with the T&I organization. It applies in addition to whichever usage category the work falls under