How do I write an AI policy for my organisation?

Stewart Masters · 8 Sep 2026

An AI policy sets out how employees are expected to use AI tools within the organisation — what's permitted, what requires approval, what's prohibited, and how to handle sensitive situations. The challenge is writing one that is specific enough to be useful but flexible enough to remain relevant as the AI landscape evolves rapidly.

What a good AI policy covers

A useful AI policy should address: permitted uses (what employees can use AI for without specific approval), prohibited uses (what is not allowed — typically anything involving sensitive personal data, confidential client information, or regulated outputs), approved tools (a list of vetted AI tools and any conditions on their use), data handling (what data can and cannot be inputted into AI systems), disclosure (when to disclose to clients or customers that AI was used), and escalation (who to ask when unsure).

Common mistakes

The most common mistake is writing a policy that is either so restrictive it's ignored (employees work around it with personal accounts) or so general it provides no actual guidance. The second is not reviewing it. AI tools and capabilities are changing monthly — a policy written in 2024 may already be outdated. Build in a review cadence and assign someone to own it.


Want to talk through any of this?
The most effective AI policies are written collaboratively with the people who will use them — not issued top-down. An employee who helped write the policy is more likely to follow it than one who received it in an email.

Get in touch →

SM
Stewart Masters

Strategic advisor to founders and operators. Chief Digital Officer at Honest Greens. Guest lecturer at IE Business School and ESADE. Based in Barcelona. Connect on LinkedIn →

Related reading

Board & Advisory Shadow AI and what boards need to know Board & Advisory How boards evaluate AI risk AI & Technology AI fluency for business leaders
← All questions