Most AI use policies fail for the same reason: they were written to satisfy a requirement rather than to answer the questions an employee actually has at 10 a.m. on a Tuesday with a deadline in front of them.
Those questions are short. Can I use this tool? Can I put this information into it? Do I have to tell anyone? Who decides?
The four questions a policy must answer
1. Which tools are approved?
Name them. A policy that says "approved AI tools may be used" without listing any is not a policy, it is a shape. The list should include what each tool is approved for, because the answer is rarely uniform — a tool may be fine for drafting marketing copy and unacceptable for anything touching customer records.
Include the route to add one. If getting a tool approved takes six weeks and an unanswered email, staff will use it anyway and stop telling you.
2. What information may never go in?
This is the block that prevents actual harm. Be specific to your organization rather than generic:
- Personally identifiable information about customers, students, patients, or employees
- Protected health information, and anything with a sector-specific regime attached
- Credentials, keys, and access tokens
- Anything covered by a nondisclosure agreement or a confidentiality clause in a contract
- Unreleased financial results, legal strategy, and personnel matters
- Records subject to retention or public-records obligations, unless the tool is inside your records system
3. What must be disclosed, and to whom?
Decide deliberately, then write it down. Common positions: AI-assisted internal drafting requires no disclosure; AI-generated material sent to a client, a regulator, or the public requires review by a named human and, in some sectors, a disclosure line; anything used in a decision about a person — hiring, discipline, eligibility, grading — requires documented human judgment and, increasingly, a legal review.
4. Who owns it?
One person, by role, with a way to reach them. This single line is the difference between a policy that gets applied and a document that gets circulated. The owner approves tools, answers the edge cases, and keeps the approved list current.
The clauses people forget
| Clause | Why it matters |
|---|---|
| Accuracy and ownership | Whoever sends it owns it. AI-assisted work is verified before it leaves the organization, and the human who sent it is accountable for the content. |
| Vendor terms | Free consumer tiers commonly allow provider use of your inputs. Approved-tool status should depend on the terms, not the brand. |
| Decisions about people | Hiring, promotion, discipline, and eligibility carry legal exposure. Say plainly whether AI may be used, in what role, and what human review is required. |
| Records and retention | If your sector has retention or public-records duties, AI chats about official business may be records. Decide before someone asks in a request. |
| Reporting a mistake | Name a path to report that something went in that should not have. Without it, you find out much later and much worse. |
| Review date | A dated review commitment. An undated policy is a stale policy within a year. |
What makes a policy useless
- It is all prohibitions. People need a permitted path or they build their own.
- It names no tools and no person. Nothing is actionable.
- It was adopted without training. A policy nobody was walked through is a policy nobody follows. The rollout matters as much as the drafting.
- It confuses aspiration with rules. "We use AI ethically and responsibly" is a value statement. Put it in the preamble and then write the rules.
A workable rollout
- Find out what is already being used. Ask without penalty, because you need the truth more than you need compliance on day one.
- Draft two pages that answer the four questions.
- Have the people who will live under it read it and mark anything ambiguous.
- Deliver a short session — thirty minutes is enough — that covers the prohibited-data list and the reporting path.
- Publish the approved-tool list somewhere staff can reach it in one click, and put a review date on the calendar.
Organizations that get this right treat the policy as an operating document rather than a legal artifact. The test is simple: can a new employee, on their second day, find out whether they may use a tool for a specific task — without asking anyone?
Questions people ask
How long should an AI use policy be?
Two pages for the rules people have to follow, with any detailed procedures kept separately. If staff cannot find the answer to a live question in under a minute, the policy will be ignored and they will decide on their own.
Should we just ban AI tools?
A ban you do not enforce is worse than a permissive policy you do, because it moves the usage somewhere you cannot see. If the answer for a category of data genuinely is no, say so narrowly and explain why.
Who should own the policy?
One named person, with authority to approve tools and answer questions. Distributed ownership across a committee produces a policy that is updated by nobody.
How often should it be reviewed?
At least twice a year, and any time you add an approved tool or a regulator issues guidance in your sector. AI capability changes faster than most policy calendars assume.
Do small organizations need one?
Yes, and theirs can be short. One page that names approved tools, prohibited data, disclosure expectations, and a person to ask is enough to prevent the majority of incidents.