Atlassian’s Teamwork Lab recently published research on AI working agreements. The headline finding: 82% of teams who co-created an agreement said it made them more aligned on how to use AI.
Now, let me get one thing clear. I love AI. I’ve discovered the joy of building! I’ve vibe-coded tools and exercises I’ve used in leadership development sessions. I’ve built internal workflows for our business. I believe deeply that if we’re not using it, we’re going to get left behind.
I’m also the person on our team who gets twitchy the moment an LLM asks for read or write access to anything internal. The more I work with these tools, the clearer the risks become - what they access, what they retain, what we’d be agreeing to without realizing it.
A few weeks ago, my co-founders and I sat down to align on how we use AI responsibly at Collabic.
Quick context on how we make decisions. I’m responsible for our internal growth and development around AI, which means when something falls in that lane, you don’t come to the team with a question. You come with a POV. Well thought out, well researched, with clear recommendations. The other founders react, push back, refine. From there, we land somewhere better than any of us would have alone.
I came in with a proposal. The first thing I wanted to align on wasn’t actually the agreements. It was avoiding tool drift. We weren’t all using the same AI tools, and that fragmentation was going to cost us. We aligned on Claude as our foundational LLM, Claude Code for building, and got clear on the other tools we’d standardize on. That was the *what*.
The harder conversation was the *how*.
The tension that surfaced is the one I think most teams are sitting with right now: risk versus innovation. Move slow or move fast. Lock it down or open it up. My starting position leaned toward thoughtful caution. We need to be mindful about data & privacy and the permissions we give AI and what we connect it to.
That POV received some pushback from my other co-founders. Not because anyone wanted to connect everything to everything. None of us did. But because “never connect it to anything” wasn’t the right answer either.
Through that conversation, I realized something. Running a business is inherently risky. We use Gmail. We use Google Drive. Even with 2FA enabled on every account, we can still get hacked. The question isn’t whether we accept risk. We already do, every day. The question is how can we be thoughtful and intentional in how we use AI in a way that lets us still innovate.
That reframe untangled the whole thing.
We landed on a lot more agreements that day, but these are the ones tied directly to how we use AI responsibly:
All AI output gets reviewed by one of us (i.e. a human).
Enterprise licenses on every AI tool, so models don’t train on our data.
Anonymize PII and company data before anything touches an LLM.
Read and understand permission requests when installing something new. Read versus write, full access versus read-only and when in doubt, default to the most restrictive option.
Client materials never live in AI workspaces. They live in Google Drive. Side note: We’re also talking about data foundation and how we might need to rearchitect Drive so that if we ever do connect Claude, it’s only connected to internal Collabic data.
These aren’t permanent. As AI evolves (and it’s evolving faster than any of us can fully track!) our agreements need to keep evolving with it. What feels right today might be too cautious or too loose six months from now. We’ve committed to revisiting them regularly, not setting them and forgetting them.
Most leadership teams right now are talking about *what* AI tools to adopt and are laser focused on driving efficiency. Few are talking about *how* they want to use it as a team. What stays human. What gets outsourced. Where humans need to stay in the loop.
The agreements matter, but the conversation and tensions that it produces matters more.
And…I’m curious! What agreements around responsible use of AI have you landed on? What’s missing from ours that you’d add?

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.