CIPR publishes new guidance on AI and digital ethics for internal communications

AI and Digital Ethics guide from the CIPR

The Chartered Institute of Public Relations’ (CIPR) has published new guidance on AI and digital ethics for internal communication. It’s a strong, practical contribution but one that reveals a persistent gap in how the profession understands enterprise AI risk.

AI and Digital Ethics for Communicators is designed as a practical playbook that internal practitioners can use on a day-to-day basis to help them use AI ethically.

The CIPR AI and Digital Ethics Guide is a member-only practical resource for communications professionals, focused on the ethical use of artificial intelligence in internal communication. It aims to help practitioners apply AI responsibly in day‑to‑day work by setting out:

  • Core ethical principles for using AI in communication practice
  • Five key roles for communicators: sense maker, trust steward, risk spotter, governance enabler, and change and capability enabler
  • Guidance on risk and governance, including privacy, security, transparency, and accountability
  • Practical prompts and considerations to support decision‑making rather than prescriptive rules

The guide is positioned as a working playbook, designed for selective use rather than linear reading, and forms part of CIPR’s wider professional development and ethics framework.

My favourite part is the five roles communicators play: sense maker, trust steward, risk spotter, governance enabler and change and capability enabler.

Overall I like it. My main concern is that it doesn’t clearly differentiate privacy and security risks between business and enterprise AI tools and personal or free AI tools.

It states bluntly to “remove personal data, client names, internal financials, and commercially sensitive information”. If that information is already stored on cloud servers then security and privacy permissions are typically inherited from existing access controls within Microsoft 365 or Google Workspace environments.

It does distinguish between personal and “free” (not sure why it is in quotes in the guide), but only on page 20 whereas the section I quote is on page 10! On page 4 it says “This is not a document to simply read cover to cover.” A bit of a problem!

In fact, not grounding the output in your own data will inevitably result in a weak, generic response. Exactly what many people complain about in AI outputs.

Issues around privacy, security and transparency/disclosure are covered in extensive detail with what appears to be a conservative interpretation of guidance and regulation. There are two full pages just on the transparency provisions of the EU AI Act.

It makes no meaningful reference to AI literacy obligations under Section 4 of the EU AI Act, which are directly relevant to the “change and capability enabler” role.

In contrast it covers IP and copyright in six short lines, which are mainly questions rather than guidance.

Reading the guide is worth five CPD points, including the five points needed for ethics. Although given it says don’t read it cover to cover I’m not sure at what point you are meant to claim the points!

This is a strong first version: practical, thoughtful, and clearly written. But it is not yet complete.

I’d recommend it is well worth reading cover to cover, rather than dipping in and out.

This excellent guide was produced by volunteers in the CIPR Inside Group and is exclusive member-only content for CIPR members.

If you want to know more about how should organisations interpret AI risk in practice, from an internal comms and external comms perspective, then please get in touch,

Malcare WordPress Security