3. Building your AI policy and approving tools
What a workable AI policy covers
An AI acceptable use policy earns its keep by answering, in advance, the questions staff actually have. For most small and mid-sized firms it fits on one to two pages. If yours is longer, you're probably writing to impress rather than to be used.
The four things it must cover
- Approved tools. Name the specific tools and tiers staff may use for work, for example the organisation's enterprise account for a named product, not "AI tools generally". Say explicitly that personal accounts and unlisted tools are not for work use, and name the person to ask when someone wants a new tool added.
- Banned data categories. List what must never go into any AI tool without explicit sign-off: client confidential information, personal data beyond what an approved configuration permits, credentials and keys, unreleased financial or commercially sensitive information, and anything under an NDA. Concrete categories beat abstract warnings.
- Disclosure expectations. When must someone say that AI contributed to a piece of work? Typically: client deliverables where the client's agreement or expectations require it, published content, and any formal or regulatory output. Internal convenience uses generally don't need disclosure. Draw the line clearly so people aren't guessing.
- Human review requirements. Which outputs need a named human to check them before they're relied on, and what "checking" means. At minimum: anything client-facing, anything containing facts or figures, and anything feeding a decision about a person.
Make it usable
Write it in plain English, keep examples in, and state who owns the policy and how to ask questions. Then actually launch it: a short briefing beats a silent upload to the intranet. A policy nobody has read protects nobody, and it won't protect the organisation either when something goes wrong and staff say, truthfully, that they'd never seen it.
› Course contents
Why AI needs governing
The regulatory landscape
Building your AI policy and approving tools
Running AI day to day