Start with observed use, not legal phrasing
A credible policy does not assume management already knows every AI tool in use. Begin with a candid inventory: who uses AI, for which outcome, with which data categories and who checks the result.
The inventory is not a blame exercise. It lets the company distinguish useful practices from cases that need limits, additional approval or a stop decision.
Write rules for everyday decisions
An employee should be able to answer four questions quickly: may I use this tool, may I enter this data, who verifies the output and where do I report a problem? If the policy does not provide that route, people will improvise.
- approved, conditional and non-approved tools
- public, internal, confidential and personal data
- human verification proportionate to impact
- an owner and escalation route for each exception
Connect the policy to two different workflows
Approving a new tool and reporting an incident are different jobs. Approval evaluates purpose, data, provider and ownership. Incident handling limits harm, preserves facts and brings in the right roles.
Forms can be brief, but every request needs an owner and a visible decision.
Publish with training and a review date
The policy, employee guide, tool matrix and training material must agree. A session built around the company’s own use cases is more useful than reading a long policy aloud.
Schedule a 30-day review after launch. Real questions, approval requests and minor incidents show where the rules need clarification.
General educational material. It is not legal advice and does not replace legal, DPO, HR or security review appropriate to your organisation.
