Last updated: September 14, 2026 · By Vishal Swami, Founder & Lead AI Reviewer, AISagely
Who gets to define the rules for AI? No single party does. Three layers govern you at once every time you open ChatGPT, Claude, or Gemini: the company that built the model, the government where you're sitting, and (if you're at work) whoever wrote your employer's AI policy. They don't always agree, and knowing which one wins in a conflict is more useful than knowing any one of them by heart.
Short answer: Three layers set AI's rules at once: the provider's usage policy (OpenAI, Anthropic, Google), government regulation where you operate (the EU AI Act, US state laws), and your employer's internal AI policy if you have one. When they conflict, the strictest applicable layer wins. Check the provider's terms first, then local law, then your workplace rules.

In my testing, I read through the current usage policy pages for OpenAI and Anthropic side by side, then compared them against what I'd already covered on the EU AI Act’s enforcement timeline. The overlap is smaller than most people assume. A provider can allow something its own terms don't ban, a regulator can still make that same thing illegal where you live, and your employer can ban it anyway even when neither of the first two would stop you. None of the three layers defers to the others. Here's how to work out which one actually applies to what you're about to do.
What you'll need
Nothing to install. You need the actual usage policy page for whatever tool you use most, not a summary someone else wrote about it — OpenAI's usage policies were last updated October 29, 2025, and Anthropic's usage policy took effect September 15, 2025, so a two-year-old blog post about either one is already out of date. You also need to know, roughly, where you're operating from and where your users are, since that decides which regulation applies. If you're doing this for a team rather than just yourself, pull up whatever internal AI guidance already exists, even if it's just a Slack message from IT saying "don't paste client data into ChatGPT." That counts as a policy, even an informal one.
Step-by-step: how to work out whose AI rules apply to you
1. Start with the provider's usage policy for the specific tool
Open the actual policy page for the model you're using, not a general "AI rules" explainer. OpenAI, Anthropic, and Google each publish their own, and they don't match line for line — Anthropic’s usage policy, for instance, sets extra disclosure requirements for high-risk domains like legal, medical, and financial advice, requiring a qualified professional to review the output before it goes out. This layer is the one that decides whether your account gets throttled or suspended, so it's worth five minutes even if you never read another policy document again.
2. Check what your jurisdiction actually regulates
The provider's terms tell you what the tool will do. They don't tell you what's legal. If you or your users are in the EU, enforcement on GPAI model obligations and banned practices went live August 2, 2026, with fines under Article 99 running up to €35 million or 7% of global turnover for the worst violations. US rules are messier — no single federal AI law exists yet, so state-level rules and sector regulators (FTC on deceptive claims, state privacy laws) fill the gap. This layer overrides the provider's terms whenever the two disagree, because a company's usage policy can't legalize something a regulator has banned.
3. Check whether your employer already wrote its own rules
Ask before assuming there isn't one. In most companies I've talked to, some kind of AI guidance already exists, even if it's unofficial and never got written down properly — my guide to writing an AI policy covers how to formalize exactly this. An internal policy is almost always the strictest of the three layers, because it's the only one that can say no to something the provider and the regulator both allow. A company can ban pasting client names into any AI tool even though neither OpenAI nor your state government requires that.
4. Rank the three layers before you hit a conflict, not during one
Write down, in order, which layer wins when they disagree: illegal always loses regardless of what the provider allows, then your employer's policy governs anything legal but still restricted internally, and the provider's terms set the floor under both. Having this order settled before someone asks "can I use ChatGPT for this contract clause" saves you from making the call under pressure.
5. Put the answer somewhere your team can actually find it
A rule that lives only in your head isn't a rule anyone else can follow. Even a single shared doc with three lines — "approved tools," "never paste this," "who signs off on high-risk output" — beats nothing. If you're building this out further, the step-by-step structure in how to write an AI policy for your business turns this into something a whole team can reference.
Who actually sets the rules: the three layers compared
| Layer | What it controls | Example | Who enforces it |
|---|---|---|---|
| Model provider's usage policy | What the tool itself will refuse to generate | OpenAI's usage policies (updated Oct 29, 2025); Anthropic's usage policy (effective Sept 15, 2025) | The provider — throttles, suspends, or bans the account |
| Government regulation | What's legal to build, deploy, or automate in a jurisdiction | EU AI Act GPAI and banned-practice rules, enforceable since Aug 2, 2026 | Regulators and courts — fines, injunctions |
| Your organization's policy | What your team may paste in, ship, or automate without review | An approved-tools list and a data-handling rule | Your employer — HR, legal, or IT |
If you only remember one row, remember the third. It's the layer most people skip, and it's the one most likely to actually get enforced against you day to day, since your manager notices a policy breach faster than a regulator does.
Example prompts you can copy
Use these to speed up the audit, swapping in your own tool and jurisdiction:
- "Summarize [paste the provider's usage policy URL or text] in five plain-English bullet points aimed at a non-legal team. Flag anything that requires a licensed professional to review the output."
- "Compare these two AI usage policies [paste both] and list only the places where they genuinely disagree, not where they're just worded differently."
- "We operate in [state/country]. Based on this usage policy and what you know about AI regulation there as of today, what's the single biggest gap between what the tool allows and what's actually restricted locally?"
- "Draft a three-line internal note for my team: which AI tools are approved, what data can never go into a prompt, and who signs off before AI-assisted work ships to a client."
- "Given these three inputs — the provider's policy, the relevant regulation, and our internal rule — which one is stricter for [specific task], and what should we default to?"
Common mistakes to avoid
The one I see most often: treating the provider's terms of service as the whole answer, then acting surprised when a regulator or an employer applies a stricter rule on top. Second, assuming a tool's default behavior reflects the law rather than just the provider's own risk tolerance — a model answering a question freely doesn't mean it's legal to act on the answer in every country. Third, writing an internal AI policy once and never checking it against provider updates; both OpenAI and Anthropic have revised their usage policies within the last year, and a stale internal doc can end up permitting something the vendor no longer allows. Fourth, assuming "no internal policy" means "no rules" — it just means the only layers left are the provider's terms and the law, and both still apply. Fifth, skipping the disclosure requirements for high-risk domains like legal, medical, or financial output, which several providers now require explicitly rather than leaving to judgment.
Tools that make this easier
Once you know the three layers exist, the fastest next step is writing your own version of layer three — my guide to writing an AI policy for your business has a copy-ready structure and the prompts I used to draft one in an afternoon. If you're weighing which provider's terms you're most comfortable building around, Claude vs. ChatGPT compares more than pricing and covers where the two diverge on content restrictions. For the regulatory layer, what’s actually enforceable under the EU AI Act right now and how AI disclosure and messaging rules apply in practice both go deeper than this piece has room for. And if you're still getting comfortable with the tools themselves before worrying about their rules, start with how to use ChatGPT or how to use Claude.
My take
None of the three layers was built with the other two in mind, which is exactly why this feels confusing. Providers write terms to limit their own liability, regulators write law to limit societal harm, and employers write policy to limit their specific risk. Treat them as a stack, not a single rulebook: check the provider's terms because that's what gets your account banned, check the law because that's what gets you fined, and write your own internal policy because that's the only layer that actually knows what your team does all day. Skipping the third one is the mistake I see most, and it's the easiest of the three to fix.
Frequently Asked Questions
Who gets to define the rules for AI: is there one authority in charge?
No. There's no single body that sets all AI rules. Model providers, national and regional regulators, and individual employers each set rules independently, and none of them defers to the others.
How long does it take to check whose AI rules apply to me?
Reading the provider's current usage policy takes about ten minutes. Confirming the regulatory layer for your jurisdiction and checking whether your employer has an internal policy usually takes under an hour combined, unless you're building the internal policy from scratch.
What is the easiest way to do this?
Start with the provider's usage policy for the tool you actually use, since that's the layer that affects your account directly. Then check local regulation and your employer's rules, and write down which one wins if they ever conflict.
Do government AI regulations override a company's usage policy?
Yes, when they conflict. A provider's terms can't make something legal that regulation bans, though a provider can still be stricter than the law requires — and often is.
Can my employer restrict AI use more than the provider or the law requires?
Yes. An employer's internal AI policy is typically the strictest of the three layers, since it can prohibit things that are otherwise legal and provider-approved, like pasting client data into a general-purpose chatbot.