An AI policy sets out how employees are expected to use AI tools within the organisation — what's permitted, what requires approval, what's prohibited, and how to handle sensitive situations. The challenge is writing one that is specific enough to be useful but flexible enough to remain relevant as the AI landscape evolves rapidly.
What a good AI policy covers
A useful AI policy should address: permitted uses (what employees can use AI for without specific approval), prohibited uses (what is not allowed — typically anything involving sensitive personal data, confidential client information, or regulated outputs), approved tools (a list of vetted AI tools and any conditions on their use), data handling (what data can and cannot be inputted into AI systems), disclosure (when to disclose to clients or customers that AI was used), and escalation (who to ask when unsure).
- Permitted uses — what employees can do without additional approval
- Prohibited uses — explicit list with the reason behind each restriction
- Approved tools — vetted list with any conditions or limitations
- Data handling rules — what can and cannot be shared with AI systems
- Disclosure obligations — internal and external
- Escalation path — who to contact when unsure
Common mistakes
The most common mistake is writing a policy that is either so restrictive it's ignored (employees work around it with personal accounts) or so general it provides no actual guidance. The second is not reviewing it. AI tools and capabilities are changing monthly — a policy written in 2024 may already be outdated. Build in a review cadence and assign someone to own it.
Want to talk through any of this?
The most effective AI policies are written collaboratively with the people who will use them — not issued top-down. An employee who helped write the policy is more likely to follow it than one who received it in an email.
Get in touch →