How to Build an AI Policy for Your Company

If you have not told employees how to use AI, they are probably using it anyway, often with personal accounts and sensitive data. A good AI policy is short, practical and updated regularly. It sets safe boundaries instead of banning everything.
What to include
- Approved tools: which services staff may use and how to request new ones.
- Data rules: what can never be entered, such as customer data, credentials and trade secrets.
- Human review: outputs affecting customers, money or legal matters need a person to check them.
- Disclosure: when to tell clients or the public that AI was used.
- Intellectual property: ownership and licensing of generated content.
- Accountability: who owns decisions and who to contact with questions.
Classify your data
Create three simple levels: public, internal and confidential. Public information can go into approved tools freely, internal needs approved tools only, and confidential stays out unless a contract and technical controls allow it.
Rollout plan
- Draft a one-to-two page policy with plain language.
- Review it with legal, IT and a few frontline staff.
- Train teams with real examples of good and bad prompts.
- Provide approved tools so people have a safe option.
- Review the policy every quarter as tools change.
Handling incidents
Make reporting easy and blame-free. If sensitive data was pasted into an unapproved tool, quick reporting lets you delete it, notify affected parties if required and adjust training.
Common mistakes
Writing a policy no one can understand, banning tools without offering alternatives and never revisiting it as the technology evolves.


