Guide · 6 min read
A one-page AI use policy your team will actually follow
Long AI policies get read once and ignored. A policy people follow fits on one page and answers three questions: what is always fine, what is never fine, and what has to be checked by a person.
Why most AI policies fail
- ·They are written by people who do not do the work, so they ban things that are already happening.
- ·They regulate tools instead of tasks. Tools change monthly; tasks do not.
- ·They have no owner and no review date, so nobody can update them when reality moves.
The three-line structure
Always
Uses that need no approval. Be generous here — this is what makes the policy credible. Example: drafting internal summaries, rewriting your own text, generating test data.
Never
Hard lines, with the reason attached. Example: no client personal data in a tool without a data-processing agreement; no AI-generated numbers in a client deliverable without a human source.
Review
The middle ground: allowed, but a named person checks before it leaves the building. Example: anything client-facing, anything that becomes a decision, anything legal or financial.
Questions to answer before you write it
- ·What are people already doing that the policy will make visible?
- ·Which data can never leave, and do we actually know where our tools store it?
- ·Who verifies the review category, and what happens when they are on holiday?
- ·What does a mistake look like, and is it safe to report one?
- ·When do we look at this again — an actual date, not "quarterly"?
Worked example (small team, client services)
Always: internal drafts, summaries, code you would review anyway. Never: client personal data, or AI text sent to a client unedited. Review: proposals, anything with a number in it, anything that names a client. Owner: Camille. Reviewed: 30 September.
That is the whole policy. It fits in a Slack pinned message, and everyone can recite it. Expand it only when a real incident shows a gap — not before.
Where the rules should come from
Do not write this alone. The rules hold when the people bound by them wrote them, which is what the fifth phase of the session (Adopt Systems) is for: the room drafts the always / never / review lines together, and the owner is named in the room.
Take it further
Phase five of the workshop produces exactly this page — always, never, review, owner and date — from your team's own work.
