Get Started
Chapter 38 min read

Writing a Policy People Follow

Most AI policies are long, defensive and ignored. What a one-page version contains, and why permission matters more than prohibition.

If your organisation has no AI policy, people are still using AI — they are just doing it on personal accounts, without telling anyone, which is the worst available outcome. A policy's first job is to make the safe path the easy path.

A page people read beats twelve pages legal signed off on.

What a working policy contains

  1. The approved tools, named, with which plan and how to get access. Vagueness here guarantees personal accounts
  2. The data tiers and what may go where — the previous chapter, in five lines
  3. What must never be shared, as a short concrete list, not a category
  4. Where a human must review before anything goes out: customer communication, published content, code that ships, anything with a number in it
  5. Disclosure expectations — when to tell a client, a reader or a colleague that AI was involved
  6. Who to ask when it is unclear, by name, and an explicit promise that asking is never penalised

The parts people get wrong

  • Naming no tools. 'Use approved AI tools' with no list means everyone picks their own
  • Requiring approval for every use. Approval queues do not slow usage down, they only move it off the record
  • Ignoring personal accounts. Explicitly say whether work may be done on personal accounts — silence is read as yes
  • Forgetting contractors and freelancers, who often handle the most sensitive material and have never seen the policy
  • Writing it once. Tools, plans and terms change every few months; an annual review with a date on the document is the minimum

A one-page skeleton

Fill this in and it is done

AI USE — [Organisation]          Last reviewed: [date]
Owner: [name, role]

APPROVED TOOLS
- [Tool], [plan]. Request access from [name].
- [Tool], [plan]. For [specific purpose] only.
Do not use work material on personal AI accounts.

WHAT YOU MAY SHARE
- Public material: any approved tool.
- Internal, non-sensitive: approved tools only.
- Customer or employee personal data: only [tool], and only
  when needed for the task. Remove names and identifiers first.
- Never, anywhere: passwords, keys, payment data, [regulated
  data specific to us].

HUMAN REVIEW REQUIRED BEFORE IT LEAVES
Customer messages · published content · code that ships ·
anything containing a figure or a legal statement.

DISCLOSURE
Tell a client when AI was used to produce a deliverable they
are paying for. Never present generated material as original
research or first-hand experience.

ACCOUNTABILITY
The person who sends it owns it. "The AI wrote it" is not an
explanation.

UNSURE? Ask [name]. Asking is never a problem. Not asking is.

Rollout matters as much as wording

Send it once and it is read by the people who already cared. Instead, walk through it in a team meeting with two real examples from your own work — one clearly fine, one clearly not — and ask people to bring the grey cases they have already hit.

The grey cases are the policy's real content. Add the answers to the page as they come up, and put the review date at the top so people can see it is maintained.

What to take from this chapter

  • No policy means shadow usage on personal accounts — the worst outcome
  • Name the approved tools and plans, and say how to get access
  • Lead with permissions; prohibitions alone push usage off the record
  • Cover personal accounts, contractors and a review date explicitly
  • Roll it out with real examples and collect the grey cases as they appear

Try it

Fill in the one-page skeleton for your team, even if you are not the person who normally writes policy. A concrete draft is far easier to get approved than a suggestion that someone should write one.