You don't need a 30-page document. A single page covering tools, data, review and accountability will do. Here's what goes on it.
If your team uses AI and you've never told them how, you already have an AI policy. It's just an unwritten one, and everyone's version is different. A single page fixes that.
Name the tools people may use for work and which plan or account. Say who to ask before trying a new one. This stops a dozen unvetted apps quietly collecting company information.
Spell out what never goes in: customer personal data, credentials, confidential client material, unreleased financials. Give two or three real examples from your own business so it's not abstract.
AI gets things wrong, confidently. Anything customer-facing, legal, financial or factual must be checked by a person before it goes out. The person who sends it owns it, whoever or whatever drafted it.
Decide when you'll tell customers AI is involved, for example in a chatbot. Never present an automated reply as a named human.
Name one person responsible and set a date to revisit it; this field moves quickly. Pair the policy with our guide on what not to paste into ChatGPT and you've covered the essentials.
We can help you pick sensible first projects and set them up with the right guardrails.
Start a conversation →Yes, a short one. It takes an hour to write and saves arguments, or worse, later.
Rarely. It's more useful to require review and accuracy than to ban a tool people will use anyway.