Playbook · 8 min read
Writing a one-page AI usage policy
A policy people read, remember and follow, written in a week with the people who'd otherwise block it.
In 60 seconds
- Build the page around the six questions people actually ask, from which tools they can use to who to ask when they're not sure.
- Get red lines from legal, security or IT, and HR before you write, by asking each what worries them most, what's fine freely and what needs a conversation first.
- Use examples rather than categories, lead with what's encouraged, and include a line saying people won't be in trouble for reporting a mistake.
- Push additions to the linked detailed documents unless a typical employee needs them to make a decision this week.
- Launch it from a senior person, walk through it in every live session for a month, and put a quarterly review date on it.
By the end you'll have a one-page policy answering the six questions, written agreement from legal, security and HR, a launch message from your sponsor, and a review date.
Most people aren't using AI on their real work because nobody has told them what's allowed. This playbook walks you through drafting a one-page usage policy, getting legal, IT and HR to agree to it, and launching it so people actually change what they do.
In almost every organisation, one of the biggest blockers to AI use isn't skill or interest. It's uncertainty. People aren't sure what they're allowed to put into the tool, so the careful ones don't use it on anything real and the careless ones paste in whatever they like. Both are problems, and a long policy document fixes neither, because nobody reads it.
What works is a single page that answers the questions people actually have, in language they'd use themselves, backed by whatever longer documents legal and security need. This playbook is how to write that page and get it agreed in about a week.
Day 1
find out what already exists.
Day 2
ask legal, security or IT, and HR three questions each.
Day 3
draft the page.
Day 4
review with the same three people.
Day 5
launch it properly.
What the page has to answer
Before drafting anything, list the questions people have asked you, or would ask if they felt they could. In most organisations they come down to six:
- Which tools can I use? And does that include the free version on my phone?
- What can I put in? Customer names? Contracts? Code? Last quarter's numbers?
- What can't I put in? Usually the more important list.
- Do I need to check the output? And whose problem is it if it's wrong?
- Do I have to say I used AI? To my manager, to a client, in a document?
- Who do I ask when I'm not sure?
If your page answers those six clearly, it's done its job. Everything else is detail that can live in a linked document.
Day 1: find out what already exists
You're rarely starting from nothing. Collect:
- Any existing acceptable use, data protection or information security policy. Your AI policy should point to these rather than repeat them.
- Your data classification scheme, if there is one. "Public, internal, confidential, restricted" or similar. This saves you inventing categories.
- Whatever has already been said about AI: an all-staff email, a slide from a town hall, a line in the IT policy. You'll need to replace or align with it.
- The terms your organisation has agreed with your AI vendor. You don't need to interpret them yourself, but security or legal will want to check the policy against them.
Then book thirty minutes each with someone from legal, security or IT, and HR. Tell them you're drafting a one-page plain-English version and want their red lines before you write, not after.
Day 2: ask each of them three questions
In each conversation, ask:
- What's the one thing you're most worried someone will do? - What would you be comfortable with people doing freely? - What needs a conversation with you first?
Those three answers map directly onto the three lists in the template below: off limits, fine to do, and ask first. Write down their words. Using their language in the draft makes sign-off much easier.
Day 3: draft the page
Use this structure. Keep each section short. If it doesn't fit on one page at a normal font size, cut.
Using AI at [Organisation] Why this exists. We want you to use AI to do your work better and faster. This page tells you how to do that safely. If something isn't covered, ask [contact]. Tools you can use for work. [Named approved tools, with the accounts people should use.] Don't use personal or free accounts for work content, because we don't control what happens to the data. Fine to use freely. [Examples: public information; your own drafts and notes; internal documents classed as [level]; rewriting, summarising and brainstorming.] Never put in. [Examples: customer or employee personal data beyond [rule]; anything classed [level]; passwords, keys or credentials; information under NDA or client restriction; unreleased financial results.] Ask first. [Examples: new use cases involving customer data; anything that will be sent to a client unedited; anything feeding a decision about a person, such as hiring or performance.] You own the output. AI gets things wrong, confidently. Check facts, figures, names and anything you'd be embarrassed to get wrong. If you send it, it's yours. Being open about it. [Your rule, e.g. tell your manager if a deliverable was mostly AI-drafted; follow client contracts on disclosure.] If something goes wrong. If you think you've put something in that you shouldn't have, tell [contact] straight away. You won't be in trouble for reporting it. More detail. [Links to the full policies.]
The AI policy builder produces a first draft in this shape from your answers, which saves an hour of formatting.
Do this nowGenerate a first draft of your policyA few drafting rules that make a real difference:
- Use examples, not categories alone. "Confidential information" means nothing to most people. "A client's contract, a salary, a draft board paper" does.
- Say yes first. A page that opens with prohibitions reads as "don't use this". Lead with what's encouraged.
- Name a person or channel, not a department. "Ask the AI channel in Teams" gets questions. "Contact Information Governance" gets silence.
- Include the "you won't be in trouble" line. People hide mistakes they think will be punished, and a hidden mistake is worse than a reported one.
Day 4: review with the same three people
Send the draft to legal, security and HR together, so they see each other's comments. Ask for comments within two working days, and be specific: "Is anything here wrong or missing? Please don't add length unless it's essential."
Expect two kinds of feedback. Corrections, which you should take. And additions, which you should push to the linked detailed documents wherever you can.
Day 5: launch it properly
A policy posted on the intranet is a policy nobody reads. Launch it like something you want people to use:
- Send it from a senior person, ideally your sponsor, with one line on why: "We want you using AI on real work. Here's how to do it safely."
- Walk through it in every live session for the next month. Two minutes at the start, using examples relevant to that team.
- Turn it into a quick reference. A short version pinned in your AI channel, and a line in each workflow guide: "What not to paste in for this workflow."
- Collect the questions it doesn't answer. Every question you get in the first month is a candidate for the next version.
Mistakes to skip
- Writing it alone and presenting it for approval. You'll get a round of rewrites that triples its length. Get red lines first.
- Copying another organisation's policy. Their tools, contracts and risks aren't yours. Use a template for structure, not content.
- Banning everything to be safe. A ban on the approved tool's core use pushes people to unapproved ones. That's the worst outcome for everyone, including security.
- Treating it as finished. Tools and terms change. Put a review date on it, quarterly to start with.
- Making disclosure rules nobody will follow. "Label every use of AI" sounds responsible and gets ignored. Pick a rule people can actually keep.
At the end of the week you should have
If you want a head start on the draft, the AI policy builder is free. The Role Book has a lesson on the policy as part of the 90-day plan, including how to adapt it per team and how to handle the "ask first" requests without becoming a bottleneck.
Read the full playbook free
Enter your email to unlock it here and get a copy in your inbox. You'll also get the weekly newsletter.
Already subscribed? Sign in, or enter your email again.