AI Policy: Writing Rules People Will Actually Follow
A 20-page AI acceptable-use policy that nobody has read protects no one. A short, specific policy people can actually remember does far more.
The business problem
Many companies now have an AI policy because a customer, auditor, or board member asked for one — and many of those policies were written once, filed away, and never actually operationalized. A policy that exists on paper but that no employee has read or would recognize in the moment they need it provides compliance cover without providing real risk reduction.
What a usable AI policy actually decides
A working AI policy doesn’t need to be exhaustive. It needs to make a small number of decisions clearly enough that an employee can apply them without asking anyone:
- What data may never go into an AI tool — customer PII, credentials, regulated data, unreleased financial information — a short, specific list beats a vague "use good judgment"
- Which tools are approved — a current, accessible list, not a policy that assumes people will ask before trying something new
- Who to ask about a tool that isn’t on the list — a fast, known path, so the answer to "can I use this" doesn’t default to "just try it"
- What review AI-generated output needs before it’s used — code, customer communications, and decisions about people each warrant a different level of human review before anything ships
“The best AI policy is the one an employee can actually recall in the moment they’re about to paste something into a chatbot. Length is not the same thing as effectiveness.”
Why it matters
A policy nobody has internalized doesn’t change behavior — it only provides a paper trail after something has already gone wrong. Given how easy it is to paste sensitive data into a public AI tool by habit, the policy’s real job is to be memorable enough to interrupt that habit before it happens, not to be comprehensive enough to cite afterward.
Practical guidance
Write the policy short — one page is achievable for most organizations. Pair it with the approved-tools list living somewhere people actually check, not buried in a policy repository. Reinforce it the same way other security awareness habits get reinforced: brief, repeated, role-relevant reminders rather than a single annual read-and-sign.
See how AI policy fits into a full AI governance structure.
Explore AI GovernanceQuestions, answered directly.
Short enough that an employee could reasonably remember its main points — often one page covers the essential decisions; length beyond that tends to reduce, not increase, how well it’s actually followed.
Yes, ideally through a maintained, accessible list rather than the policy document itself, since approved tools change more often than the policy should need to be rewritten.
Whoever owns AI governance overall, with a fast enough turnaround that employees aren’t tempted to skip the request and just use the tool anyway.
At least annually, and sooner if a new category of AI tool becomes widely available or a relevant regulation changes — AI policy tends to age faster than most other compliance documents.
Talk to a CISO about writing an AI policy people will use.
30 minutes. No obligation. No sales pitch.