AI policies: what your company should write down
An AI policy answers the questions staff actually have. Nine sections that fit on two pages, and the mistakes that get policies ignored.
The short answer
An AI policy is not primarily a legal document. It is the written answer to the questions your staff already have: which tools may I use and on which account, what may I put into them, do I have to check what comes out, may I use it for customer-facing work, do we tell customers, what if something goes wrong, and who do I ask. Nine sections answer all of that in two pages. Policies are ignored when they ban without providing an alternative, when they are longer than the reader’s patience, and when no person is named. Review it twice a year, because the tools change and so does the law.
The nine sections
| Section | What it says | Length |
|---|---|---|
| 1. Purpose | Why the policy exists: customers’ trust, contracts, the law, and getting the benefits safely | Three sentences |
| 2. Approved tools | Named tools on business plans, with the account to use; how to request a new one | A short list |
| 3. Data rules | What may never be entered into external tools; what the company assistant is for; how AI features in existing tools are handled | The most important section; keep it concrete |
| 4. Review rules | Anything sent to a customer or used for a decision is checked by a person; who is responsible for the output | A paragraph |
| 5. Disclosure | When customers are told they are dealing with an automated system; labelling of generated content; never claiming to be human | Checked by an advisor |
| 6. Customer-facing use | Which uses are allowed, which need approval, which are forbidden | A short list |
| 7. Intellectual property | What may be generated and used, ownership of outputs, respect for others’ rights | A paragraph, advisor-checked |
| 8. Incidents | What counts, who to tell, no blame for reporting | A paragraph |
| 9. Who to ask | A named person, and the review date | Two lines |
Writing it
- Collect the questions staff actually ask, from five conversations.
- Decide the answers with the accountable person and, for data and disclosure, an advisor.
- Provide the approved tools first, so section two lists things people can use today.
- Write the never-enter list concretely: personal data of customers and staff, credentials, financial details, contracts, confidential plans, client code.
- Name the person and set the review date.
- Walk it through once with examples in a team meeting; put the never-enter list near where people work.
Keeping it alive
Twice a year: new tools and features added to the approved list or explicitly excluded, the never-enter list checked against what people actually handle, disclosure rules checked against current law, incidents from the period reviewed for lessons. Ten minutes in the quarterly governance hour covers it, and the date at the top tells everyone the policy is current.
What this means for you
Write the two pages that answer your staff’s real questions: tools, data, review, disclosure, customer use, intellectual property, incidents, who to ask. Provide before you prohibit. Have an advisor check the data and disclosure sections. Name a person and a review date. A policy like that is followed, and it is what you show when anyone asks how your business uses AI.
Frequently asked questions
Do we need a lawyer to write an AI policy?
For the two pages that staff read, no; you need clarity about what you allow and why. Have a legal or privacy advisor check the data and disclosure sections against your obligations, especially if you handle personal or regulated data. The policy is a practical document first and a compliance document second.
What should the policy say about disclosing AI use to customers?
Whatever is true and whatever the law in your markets requires. In practice: tell customers when they are interacting with an automated system rather than a person, label AI-generated content where a reasonable customer would want to know, and never let an AI system claim to be human. Check current obligations for your jurisdiction and sector, because they are changing.
How do we make sure people actually read it?
Keep it to two pages, lead with what people may do rather than what they may not, put the never-enter list where people paste, walk through it once in a team meeting with examples, and name the person to ask. A policy that is short, permissive where it can be and specific where it must be gets read. A ten-page prohibition does not.