Before writing the rules, look at what is already happening
This is the most common sequencing mistake: the policy gets written, filed, and nobody discovers that half the company was already using artificial intelligence in ways that policy had not anticipated.
In almost every company we visit somebody has already started on their own. There was no decision: there is a person with a long document to summarise, or a text to rewrite, and they used the free tool everybody knows. With a client’s contract inside it, or a list of employees.
It is not disobedience. It is a real need the company has not yet answered. But it means company data is already leaving without anyone knowing, and no policy written blind will catch it.
So the first step is not to write: it is to ask. A round of conversations, not a technical audit. People say so readily, if the question is not framed as an accusation.
The four things it has to say
None of them requires legal language, and that is the point: a policy written in legalese gets filed, not read.
Which tools may be used. By name. “Tools approved by the company” means nothing to somebody deciding right now whether to open a web page.
What must never leave, ever. Client data, confidential information, documents covered by professional privilege, health data, credentials. A short, concrete list beats a general principle.
Who checks before the output gets used. AI produces plausible text even when it is wrong — non-existent legal references, believable numbers, invented citations. The check is not a formality: it is where the damage gets avoided.
Who to ask when in doubt. This is the part almost always missing and it avoids half the problems. Somebody who does not know whether they are allowed to do something, with nobody to ask, decides on their own.
Why one page and not twenty
A long policy gets approved, signed and never reopened. One page somebody reads in three minutes over a coffee changes behaviour.
If a longer document is needed for contractual or compliance reasons, keep the two separate: the page that circulates and the full annex. Confusing them means having neither.
A ban without an alternative does not hold
It is management’s instinctive reaction and it is understandable: if we cannot control it, ban it.
It does not work, for a practical reason. The need that pushed that person to use the tool is still there the day after the ban. If there is no official way to summarise a long document, whoever has that document will carry on doing it — just without saying so, and without anybody able to help them do it properly.
The method that works has three stages: census what is in use, replace it with an official tool that does the same job with guarantees about the data, and only then close the alternative.
What the regulation says, briefly
The European regulation on artificial intelligence does not require a policy by that name. It does require organisations using these systems to know which they are and to ensure the people operating them have competence appropriate to the context. A written policy plus a training session is the simplest way to demonstrate both.
To that is added the GDPR, which applies whenever the content entered contains personal data — which is to say almost always. We cover it under AI Act, GDPR and AI governance.
The rest
See also AI literacy training, which is the other half of the work, the DPIA for AI systems where the processing requires one, and AI consulting for the adoption side.
The first step
A round of conversations to establish which tools are already in use, and a draft of the page of rules. Free and without obligation.