Create rules people can actually follow
An AI policy should help staff make everyday decisions, not merely state broad principles. Adapt this structure to the organisation, workforce, country, sector, contracts and risk level before adoption.
State which tools and uses are approved, which information is prohibited, when human review and disclosure are required, who owns decisions and how users report mistakes or incidents. Pair the policy with examples and training.
Suggested policy structure
- Purpose and scope. State who, which systems and which work the policy covers.
- Approved tools and accounts. Explain how products are assessed, approved and accessed.
- Allowed and prohibited uses. Give practical examples, not only general statements.
- Data rules. Define personal, confidential, security, client and licensed information restrictions.
- Human responsibility. Make clear that the accountable person must review material outputs and decisions.
- Accuracy and evidence. Require checking of facts, citations, calculations and important omissions.
- Transparency and records. Define when AI use is disclosed and what prompts, outputs or decisions must be retained.
- Incidents and concerns. Provide a clear route for unsafe output, data exposure, bias, security events or complaints.
- Monitoring and review. Assign an owner and review triggers for tools, uses, law and lessons from incidents.
Starter wording to adapt
Purpose: We use approved AI tools only where they support a defined business task and the likely errors, information risks and effects on people can be controlled.
Responsibility: AI output does not transfer accountability. The person approving or using the output remains responsible for checking that it is accurate, appropriate, authorised and supported by reliable evidence.
Data: Users must not enter personal, confidential, security-sensitive, client-restricted or licensed information unless the specific tool, account and use have been approved for that information.
Incidents: Users must stop the affected use and report suspected data exposure, harmful output, misleading content, unsafe actions or material errors through the organisation’s incident route.
Policy decisions that need an owner
- Who can approve a new tool, connector, model or use case?
- Which uses require privacy, security, legal, HR or professional review?
- When must customers, staff or the public be told that AI was used?
- Which records demonstrate testing, approval and human decisions?
- Who monitors provider changes, costs, incidents and continuing benefit?
- How can a tool be suspended quickly across the organisation?
This is a planning template, not adopted policy
Have the appropriate employment, privacy, security, legal and professional owners review the wording for the organisation and jurisdiction. Rules that affect workers should be communicated and introduced through the applicable process.
AI use policy FAQs
Do small organisations need an AI policy?
A short, practical policy can be valuable wherever staff may use public or approved AI tools. Its detail should reflect the information, decisions, people and consequences involved.
Should an AI policy ban all unapproved tools?
It should clearly state the organisation’s position and provide a workable approval route. A rule that staff cannot understand or follow may drive hidden use rather than control it.
How often should an AI policy be updated?
Review it at a scheduled interval and when tools, uses, integrations, provider terms, incidents, laws or organisational risks change.
Continue your AI decision
Use the next guide that matches the question or risk you still need to resolve.
