Governance

How to write an AI use policy your team will actually follow

Short, specific and reviewed regularly beats long and ignored. Here's what to include.

By Retrofit LabsPublished 4 min read

If anyone at your company uses AI tools for work, and they almost certainly do, you need a written AI use policy. Not because a policy prevents every problem, but because without one, every employee is making up their own rules about what's safe to paste into a chatbot. A good policy is short, specific and easy to follow.

Why you need one now

AI tools are easy to access. Employees often start using them with personal accounts to save time on writing, research or analysis. That's understandable, and often productive. The risk is that company data, customer information or confidential documents end up in services whose terms your business never reviewed.

A policy does three things. It tells people what's allowed so they can use AI confidently. It draws clear lines around sensitive data. And it gives you a basis for training, vendor decisions and handling mistakes consistently.

Keep it short

The most common failure is a policy that's too long. A ten-page document written in legal language won't be read, let alone followed. Aim for one or two pages that an employee can read in five minutes, with a longer appendix for details if you need one.

Write it in plain language, use examples, and focus on the decisions people actually face: "Can I use AI to draft this email?" "Can I paste this spreadsheet in?" "Do I need to tell the client?"

What to include

Most effective policies cover the same six areas.

1. Purpose and scope

Explain briefly why the policy exists and who it applies to. Include contractors and temporary staff if they handle company information. State that the goal is to use AI safely and productively, not to discourage it.

2. Approved tools

List the AI tools that are approved for work use and on which kind of account, for example "our company workspace account, not personal accounts." Explain how someone can request a new tool and who approves it. When business or enterprise plans are available, they typically come with stronger data protections than consumer accounts, but check each provider's terms rather than assuming.

3. Data rules

This is the heart of the policy. Define categories of information and what's allowed with each. A simple three-level approach works for many businesses:

  • Public: information already published, such as your website content. Fine to use with any approved tool.
  • Internal: general business information that isn't sensitive. Fine to use with approved company accounts.
  • Restricted: customer personal information, health information, financial account data, employee records, passwords, confidential client material and anything covered by a contract or regulation. Never enter into AI tools unless that specific tool has been approved for that specific kind of data.

Give concrete examples for each level. People remember "don't paste a customer's loan application" better than "don't input PII."

4. Human review

AI tools can produce confident, incorrect output. Your policy should say which outputs must be checked by a person before use. A reasonable default: anything sent to a customer or published externally, anything involving numbers, legal or regulatory statements, and any decision affecting a customer or employee must be reviewed by a responsible person. The person who uses the output is accountable for it.

5. Disclosure and transparency

Decide when customers, clients or others should be told that AI was involved. This varies by industry and by contract; some clients require notice or consent. At minimum, don't let AI impersonate a specific real person, and be honest if someone asks whether they're talking to an automated system. Also be careful about claims in your own marketing: consumer protection law applies to claims about AI just as it does to any other advertising claim.

6. Ownership, questions and review

Name who owns the policy, who to ask when something isn't covered, and how to report a mistake, such as sensitive data entered into the wrong tool. Make reporting blame-free so people actually do it. Commit to reviewing the policy on a regular schedule, because tools and risks change quickly.

What to leave out

  • Blanket bans. Banning AI entirely tends to push use onto personal accounts where you have no visibility.
  • Tool-specific instructions. Keep how-to guides separate so the policy doesn't go stale every time a product changes.
  • Vague principles without examples. "Use AI responsibly" doesn't help someone decide what to do on a Tuesday afternoon.

Rolling it out

A policy only works if people know about it and understand it. When you launch:

  1. Walk through it in a short team session with real examples from your business.
  2. Make the approved tools easy to access, so following the policy is the easy path.
  3. Ask people which AI tools they already use, without judgment, so you know what to approve or replace.
  4. Include it in onboarding for new hires.
  5. Revisit it on a set schedule, and whenever you adopt a significant new tool.

Regulated industry? If you handle health information, consumer financial data or client confidences, have counsel or your compliance lead review the data rules section. Industry rules may require more than a general policy provides.

A starting outline

Here's a skeleton you can adapt. Each section can be a few sentences.

  1. Purpose and who this applies to
  2. Approved AI tools and how to request new ones
  3. Data categories, with examples of what can and can't be entered
  4. When human review is required, and who is accountable
  5. When to disclose AI use to customers or clients
  6. Reporting mistakes and asking questions
  7. Policy owner and review schedule

For a broader framework, the NIST AI Risk Management Framework is a free, voluntary resource many organizations use to structure their thinking about AI risk.1 If you'd like help drafting a policy that fits your business, it's a standard part of our AI training and readiness assessment work.

Free 30-minute call

Find out where AI can help your business.

Tell us how your team works today. We'll tell you plainly where technology can save time, where it can't, and what a sensible first step would be.

Book a free call

Prefer the phone? Call (949) 691-0086