Vai al contenuto

Company AI usage policy

One page people genuinely read is worth more than twenty nobody opens. And banning without offering an alternative does not work.

In breve

A policy on the use of artificial intelligence exists to say what may be entered into these tools and what may not, who checks the output, and who to ask when in doubt. It should be written after taking a census of what is already in use in the company — because somebody is already using it — and it should fit on one page: a long document nobody opens protects nobody.

Census first, then write

In almost every company somebody is already using AI on their own initiative. Writing rules without knowing what is in use is pointless.

Banning without replacing does not work

That use came from a real need. If no official tool is offered, it simply moves out of sight.

One page, not twenty

A policy people genuinely read protects the company; one sitting in a shared folder does not.

Before writing the rules, look at what is already happening

This is the most common sequencing mistake: the policy gets written, filed, and nobody discovers that half the company was already using artificial intelligence in ways that policy had not anticipated.

In almost every company we visit somebody has already started on their own. There was no decision: there is a person with a long document to summarise, or a text to rewrite, and they used the free tool everybody knows. With a client’s contract inside it, or a list of employees.

It is not disobedience. It is a real need the company has not yet answered. But it means company data is already leaving without anyone knowing, and no policy written blind will catch it.

So the first step is not to write: it is to ask. A round of conversations, not a technical audit. People say so readily, if the question is not framed as an accusation.

The four things it has to say

None of them requires legal language, and that is the point: a policy written in legalese gets filed, not read.

Which tools may be used. By name. “Tools approved by the company” means nothing to somebody deciding right now whether to open a web page.

What must never leave, ever. Client data, confidential information, documents covered by professional privilege, health data, credentials. A short, concrete list beats a general principle.

Who checks before the output gets used. AI produces plausible text even when it is wrong — non-existent legal references, believable numbers, invented citations. The check is not a formality: it is where the damage gets avoided.

Who to ask when in doubt. This is the part almost always missing and it avoids half the problems. Somebody who does not know whether they are allowed to do something, with nobody to ask, decides on their own.

Why one page and not twenty

A long policy gets approved, signed and never reopened. One page somebody reads in three minutes over a coffee changes behaviour.

If a longer document is needed for contractual or compliance reasons, keep the two separate: the page that circulates and the full annex. Confusing them means having neither.

A ban without an alternative does not hold

It is management’s instinctive reaction and it is understandable: if we cannot control it, ban it.

It does not work, for a practical reason. The need that pushed that person to use the tool is still there the day after the ban. If there is no official way to summarise a long document, whoever has that document will carry on doing it — just without saying so, and without anybody able to help them do it properly.

The method that works has three stages: census what is in use, replace it with an official tool that does the same job with guarantees about the data, and only then close the alternative.

What the regulation says, briefly

The European regulation on artificial intelligence does not require a policy by that name. It does require organisations using these systems to know which they are and to ensure the people operating them have competence appropriate to the context. A written policy plus a training session is the simplest way to demonstrate both.

To that is added the GDPR, which applies whenever the content entered contains personal data — which is to say almost always. We cover it under AI Act, GDPR and AI governance.

The rest

See also AI literacy training, which is the other half of the work, the DPIA for AI systems where the processing requires one, and AI consulting for the adoption side.

The first step

A round of conversations to establish which tools are already in use, and a draft of the page of rules. Free and without obligation.

Frequently asked questions

What should a company AI policy contain?

Four things, and none of them requires legal language. Which tools are permitted and which are not. What may be entered and what must never leave the company under any circumstances - client data, confidential information, documents covered by professional privilege. Who checks the output before it is used. And who to go to when in doubt, which is the part almost always missing and the one that avoids half the problems.

Do we need one if we do not use AI?

The better question is a different one: are you sure nobody is using it? In almost every company we visit somebody has already started on their own, pasting documents into a free service to have them summarised. It is not disobedience, it is a real need the company has not yet answered - but it means company data is already leaving without anyone knowing.

Would it not be simpler to ban it?

It does not work, and it is the most common reaction. A ban without an alternative moves the behaviour instead of removing it: whoever has a file to summarise will carry on doing it, just without saying so. The method that works is to census what is in use, offer an official tool that does the same job without data leaving, and only then close the alternative.

Is it a legal requirement?

The European regulation on artificial intelligence does not require a policy by that name, but it does require organisations using these systems to know which they are and to ensure the people operating them have adequate competence. A written policy is the simplest way to demonstrate both. On top of that sits the GDPR, which applies whenever the content entered contains personal data.

How long does it take to produce?

The census of tools in use takes a few days and is done by talking to people rather than with a technical tool. Drafting is quick because the document is deliberately short. The part that takes longest is the third, making the rules known to the people doing the work - and without that the document achieves nothing.

A written rule, before you need one

Without a policy everyone uses AI their own way, and data leaves without anyone noticing. We start from how you work today, not from a downloaded template.