Most ethics codes still leave employees without usable AI rules
Fewer than one in ten surveyed employees said their organisation’s code explicitly covered AI or technology ethics. The gap is not solved by adding a paragraph; workers need examples, boundaries and an escalation route they can use.

What happened
LRN published its 2026 Code of Conduct Report, based on 2,000 full-time employees, and found limited explicit coverage of AI or technology ethics alongside persistent usability gaps.
Why it matters
A code that names AI but cannot guide a real data, accountability or escalation decision creates policy theatre rather than a reliable operating control.
LRN’s 2026 Code of Conduct Report offers a useful test of whether organisational rules have caught up with AI use. The study covers 2,000 full-time employees. Fewer than one in ten respondents said their organisation’s code explicitly addressed AI or technology ethics. HR Dive’s independent account also reports that nearly one in five employees said their code lacked practical guidance.
Those figures measure employee perceptions, not a legal audit of every code. They do not prove that a missing AI clause caused misconduct, nor that adding one would prevent it. They do reveal an operating problem: people are being asked to make consequential choices about data, delegation and accountability without a shared decision path.
Translate principles into decisions
The first design task is not to write a longer list of prohibited tools. It is to turn broad principles into decisions that recur in work. Can an employee place customer data into an external model? Who owns an output used in hiring, performance or pricing? When must a person verify a generated answer? What should a worker do when an authorised tool produces a discriminatory or unsafe recommendation?
Each question needs a bounded rule, a realistic example and a route for exceptions. Examples should cover the tools employees actually encounter, including embedded features that may not look like a separate AI product. The code should distinguish experimentation from production use and advice from a decision that changes a person’s rights or opportunities.
LRN also reports that 66% of respondents felt able to report misconduct without retaliation, down from 71% in the earlier result. That shift is not an AI-specific outcome, but it matters for AI governance. A policy depends on workers raising uncertainty before a questionable output becomes a completed action. If escalation carries social or career cost, the code’s formal permission to speak will not function as a control.
Test the path, not the prose
Policy owners should run short scenario drills with frontline employees, managers and control teams. Present a real work task, an approved tool and an ambiguous output. Ask participants to identify the data boundary, decision owner, verification step and escalation route. Record where answers diverge and whether the route resolves the issue before work stalls or harm occurs.
The evidence should be behavioural. Measure the share of scenarios in which people identify the correct boundary; median time to reach an accountable owner; resolution time for exceptions; and whether workers can decline unsafe use without losing access to ordinary support. Track recurring questions and revise examples when the same ambiguity appears across teams.
The strongest counterargument is that codes cannot absorb every technical change. That is right. The code should define durable principles and ownership, while linked playbooks carry tool-specific details. Another risk is false reassurance: high acknowledgement rates may show that staff clicked a document, not that they can apply it. Completion therefore belongs beside scenario performance, escalation quality and evidence from actual incidents.
The Skills Atlas can help separate policy literacy, data judgement, verification and escalation capabilities. The immediate decision is more concrete: identify three AI decisions employees already make, write the smallest usable rule for each, and test whether people can act correctly under time pressure.
Minimum operating evidence
Keep a versioned rule owner, approved-use boundary, worked examples, exception route, response target and change log. Preserve questions raised during drills and how they were resolved. Review the guidance when tools, data flows or decision rights change. A code is useful when it makes a difficult choice safer and faster—not when it merely proves that the organisation mentioned AI.