A One-Page AI Policy That People Will Read
Last updated:
Prohibition does not work here
The tools are free, useful and accessible from a phone. A policy that forbids them changes where they are used, not whether they are used — and usage on a personal account with no agreement in place is precisely the exposure you were trying to prevent.
The productive position is to provide something approved and be specific about the boundaries.
What belongs on the page
- Which tools are approved, and where to find them.
- What must never be pasted in — named, specifically: customer personal data, credentials, unpublished financials, anything under NDA.
- What always needs human review before it leaves the business.
- Who to ask when it is not clear.
- The consequence of getting it wrong, honestly — and a clear statement that reporting a mistake promptly is what matters.
Five points, one page, plain language. Anything longer will not be read, and an unread policy provides no protection.
Be specific about data
“Do not share confidential information” is too vague to act on. “Do not paste customer names, addresses, contract terms or anything from the finance folder” is a rule someone can follow at their desk.
Give examples of acceptable use as well as unacceptable. People generalise from examples far better than from principles.
Require review, not disclosure theatre
The important control is that a human reads and takes responsibility for anything that goes to a customer, a regulator or into a system of record. Whether it was drafted with assistance matters less than whether someone owns it.
Where AI-assisted output carries professional liability — advice, clinical, legal, financial — say explicitly that the qualified person is accountable for the content.
Provide a decent tool
The policy only holds if the approved option is good enough to do the work. A restricted tool that is worse than the free one people already use guarantees circumvention.
Budget for it. The licence cost is small compared with the exposure of everyone using consumer accounts with unclear terms.
Review it, briefly, twice a year
The tooling changes quickly and so do the terms attached to it. A short review every six months keeps the page current without becoming a project.
Note the date on the page so people can see it is maintained rather than forgotten in 2024.
Frequently asked questions
Should we ban AI for customer-facing writing?
What about AI in code?
Do we need staff to sign it?
What if a member of staff has already pasted customer data into a public tool?
No AI policy and staff already using the tools?
The one-page version takes an hour. Happy to share the structure we use with clients.