AI policies: what your company should write down

An AI policy answers the questions staff actually have. Nine sections that fit on two pages, and the mistakes that get policies ignored.

3 minread 733words last updated

The short answer

An AI policy is not primarily a legal document. It is the written answer to the questions your staff already have: which tools may I use and on which account, what may I put into them, do I have to check what comes out, may I use it for customer-facing work, do we tell customers, what if something goes wrong, and who do I ask. Nine sections answer all of that in two pages. Policies are ignored when they ban without providing an alternative, when they are longer than the reader’s patience, and when no person is named. Review it twice a year, because the tools change and so does the law.

The nine sections

SectionWhat it saysLength
1. PurposeWhy the policy exists: customers’ trust, contracts, the law, and getting the benefits safelyThree sentences
2. Approved toolsNamed tools on business plans, with the account to use; how to request a new oneA short list
3. Data rulesWhat may never be entered into external tools; what the company assistant is for; how AI features in existing tools are handledThe most important section; keep it concrete
4. Review rulesAnything sent to a customer or used for a decision is checked by a person; who is responsible for the outputA paragraph
5. DisclosureWhen customers are told they are dealing with an automated system; labelling of generated content; never claiming to be humanChecked by an advisor
6. Customer-facing useWhich uses are allowed, which need approval, which are forbiddenA short list
7. Intellectual propertyWhat may be generated and used, ownership of outputs, respect for others’ rightsA paragraph, advisor-checked
8. IncidentsWhat counts, who to tell, no blame for reportingA paragraph
9. Who to askA named person, and the review dateTwo lines

Writing it

  1. Collect the questions staff actually ask, from five conversations.
  2. Decide the answers with the accountable person and, for data and disclosure, an advisor.
  3. Provide the approved tools first, so section two lists things people can use today.
  4. Write the never-enter list concretely: personal data of customers and staff, credentials, financial details, contracts, confidential plans, client code.
  5. Name the person and set the review date.
  6. Walk it through once with examples in a team meeting; put the never-enter list near where people work.

Keeping it alive

Twice a year: new tools and features added to the approved list or explicitly excluded, the never-enter list checked against what people actually handle, disclosure rules checked against current law, incidents from the period reviewed for lessons. Ten minutes in the quarterly governance hour covers it, and the date at the top tells everyone the policy is current.

What this means for you

Write the two pages that answer your staff’s real questions: tools, data, review, disclosure, customer use, intellectual property, incidents, who to ask. Provide before you prohibit. Have an advisor check the data and disclosure sections. Name a person and a review date. A policy like that is followed, and it is what you show when anyone asks how your business uses AI.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Do we need a lawyer to write an AI policy?

For the two pages that staff read, no; you need clarity about what you allow and why. Have a legal or privacy advisor check the data and disclosure sections against your obligations, especially if you handle personal or regulated data. The policy is a practical document first and a compliance document second.

What should the policy say about disclosing AI use to customers?

Whatever is true and whatever the law in your markets requires. In practice: tell customers when they are interacting with an automated system rather than a person, label AI-generated content where a reasonable customer would want to know, and never let an AI system claim to be human. Check current obligations for your jurisdiction and sector, because they are changing.

How do we make sure people actually read it?

Keep it to two pages, lead with what people may do rather than what they may not, put the never-enter list where people paste, walk through it once in a team meeting with examples, and name the person to ask. A policy that is short, permissive where it can be and specific where it must be gets read. A ten-page prohibition does not.