By the end of this lesson you will be able to
- Draft a working AI policy in one sitting
- Classify your data into tiers that map to tool tiers
- Set review requirements proportional to the stakes
A policy is usually framed as a restriction. In practice it is the opposite: the people most held back by not having one are the cautious employees who would use AI well but are not sure what is allowed, so they do nothing.
The five sections
1. Approved tools
Name the specific platforms and the specific plans. This matters more than it sounds: a personal free account and an organisational business account have materially different data commitments, and staff will not know that unless you say it.
Approved AI tools: [Platform] ([Plan] tier), [others].
Do not use personal AI accounts or unapproved tools for any work
involving company or client data.2. What data may go where
The core of the policy. Four tiers covers almost every business. If you already have a data classification scheme, map onto that instead of inventing a parallel one nobody will remember.
| Tier | Examples | Where it may go |
|---|---|---|
| Public | Marketing copy, published content, general research | Any approved tool |
| Internal | Processes, non-sensitive comms, general documents | Business tier only |
| Confidential | Client data, financials, HR records, legal documents | Business tier, with review |
| Restricted | Health data, M&A, regulated financial data | Named controls only, or not at all |
3. What it may and may not be used for
Normally permitted
- Drafting and editing communications
- Summarising documents and meeting notes
- Research on approved topics
- First drafts of reports and proposals
- Repetitive writing and reformatting
Normally restricted
- Decisions about hiring, firing, or pay
- Performance assessments of named staff
- External communications sent unreviewed
- Anything touching restricted data
- Advice a client will rely on, unreviewed
The right-hand column is not "AI cannot help with this". It is "a person owns the outcome". AI drafting a job description is fine; AI deciding who to interview is not.
4. What gets reviewed before it leaves
All AI-assisted content sent externally — to clients, partners,
regulators, or the public — is reviewed by the person responsible
for it before sending.
You are accountable for the accuracy of anything you send,
regardless of how it was produced.
Higher-stakes output (legal, financial disclosure, formal client
deliverables) requires a second review by a qualified person.5. Who owns it, and who to ask
A named person, not a department. "Ask IT" produces nobody asking. And say explicitly that a mistake made while following the policy is an organisational problem rather than a personal failing — that single sentence does more for adoption than the rest of the document combined.
The disclosure question
Whether to tell clients AI was involved depends on your contracts, your profession, and what you promised. A rough rule that holds up: disclose when the client is relying on the output, not when AI merely helped you produce something you would have written anyway.
- Drafted an email you then edited and sent — rarely disclosable.
- Summarised a document for your own reading — no.
- Produced analysis a client will act on — usually yes.
- Any deliverable where a contract restricts sub-processing — check the contract first.
When genuinely unsure, disclose. The cost of over-disclosing is a short conversation. The cost of under-disclosing is a trust problem you cannot fix afterwards.
Do we need a lawyer to write this?
Not for the first version. Write the working policy yourself so it reflects how your business actually operates, then have it reviewed if you are in a regulated field or your client contracts have sub-processing terms. A lawyer-drafted policy written without operational input tends to be unusable.
What about AI features inside tools we already use?
Cover them explicitly. They are the easiest thing to miss, because nobody made a purchasing decision — the AI feature in your CRM or email client may operate under different terms than the base product. Ask the vendor specifically.
How often should it be revisited?
Every six months, and immediately whenever you add a tool or change a plan tier. Put a review date on the document itself — undated policies quietly become inaccurate and nobody notices until it matters.
Key takeaways
- One to two pages. A policy nobody reads protects nobody.
- Five sections: approved tools, data tiers, permitted uses, review requirements, who owns it.
- Name specific platforms *and* plan tiers — the tier is what determines the data commitments.
- Credentials and identity documents get their own absolute line.
- Say that mistakes made while following the policy are organisational, not personal. It is the sentence that unlocks adoption.
- Put a review date on it and revisit every six months.
