Think Build Implement Repeat
AI & Machine Learning

A One-Page AI Policy That People Will Read

Last updated:

Prohibition does not work here

The tools are free, useful and accessible from a phone. A policy that forbids them changes where they are used, not whether they are used — and usage on a personal account with no agreement in place is precisely the exposure you were trying to prevent.

The productive position is to provide something approved and be specific about the boundaries.

What belongs on the page

  1. Which tools are approved, and where to find them.
  2. What must never be pasted in — named, specifically: customer personal data, credentials, unpublished financials, anything under NDA.
  3. What always needs human review before it leaves the business.
  4. Who to ask when it is not clear.
  5. The consequence of getting it wrong, honestly — and a clear statement that reporting a mistake promptly is what matters.

Five points, one page, plain language. Anything longer will not be read, and an unread policy provides no protection.

Be specific about data

“Do not share confidential information” is too vague to act on. “Do not paste customer names, addresses, contract terms or anything from the finance folder” is a rule someone can follow at their desk.

Give examples of acceptable use as well as unacceptable. People generalise from examples far better than from principles.

Require review, not disclosure theatre

The important control is that a human reads and takes responsibility for anything that goes to a customer, a regulator or into a system of record. Whether it was drafted with assistance matters less than whether someone owns it.

Where AI-assisted output carries professional liability — advice, clinical, legal, financial — say explicitly that the qualified person is accountable for the content.

Provide a decent tool

The policy only holds if the approved option is good enough to do the work. A restricted tool that is worse than the free one people already use guarantees circumvention.

Budget for it. The licence cost is small compared with the exposure of everyone using consumer accounts with unclear terms.

Review it, briefly, twice a year

The tooling changes quickly and so do the terms attached to it. A short review every six months keeps the page current without becoming a project.

Note the date on the page so people can see it is maintained rather than forgotten in 2024.

Frequently asked questions

Should we ban AI for customer-facing writing?

Better to require review and hold someone accountable for the content. A ban is unenforceable and the review requirement addresses the real risk, which is unchecked output.

What about AI in code?

Same principle: assistance is fine, review is mandatory, and licence-sensitive or security-critical code deserves extra scrutiny. Generated code should never ship unread.

Do we need staff to sign it?

An acknowledgement helps, and comprehension helps more. A ten-minute session with real examples achieves more than a signature on a document nobody read.

What if a member of staff has already pasted customer data into a public tool?

Establish what was shared, check the provider's terms and retention, consider whether it is reportable, and use it as the reason to provide an approved alternative rather than as a disciplinary matter.

Keep reading

No AI policy and staff already using the tools?

The one-page version takes an hour. Happy to share the structure we use with clients.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

AI AgentsMachine LearningAI Integration