Enablement Lead

Free tool · 5 minutes

A one-page AI policy people will actually read

Most people aren't sure what they're allowed to put into AI tools, so they either avoid them or guess. Answer ten short questions and get a plain-English policy covering what's fine, what isn't, and who to ask.

The wording comes from fixed templates, not AI, so it's predictable. It's a starting point, not legal advice.

What's the company called?

Step 1 of 10

What's the company called?

It appears throughout the policy, so use the name people know.

Which AI tools are approved?

Step 2 of 10

Which AI tools are approved?

The tools your company has agreed to, usually business accounts with data protections. One per line.

Leave it blank if nothing's approved yet. The policy will tell people to ask first.

Who can use them?

Step 3 of 10

Who can use them?

What can go into approved tools?

Step 4 of 10

What can go into approved tools?

Approved tools usually don't train on your data, but that doesn't make everything fine. Personal and client data often have their own rules.

Public information

Anything already published: our website, press releases, public reports

Internal information

Everyday internal material: meeting notes, process docs, internal emails that aren't sensitive

Confidential business information

Strategy, financials, pricing, contracts, unreleased plans

Personal data

Anything about an identifiable person: HR records, contact lists, customer records

Client data

Anything a client has shared with us, or that we hold for them

Regulated data

Health or payment card data, legally privileged material, anything under a specific regulation or contract restriction

What can go into public AI tools?

Step 5 of 10

What can go into public AI tools?

Free chatbots, consumer apps, browser extensions and personal accounts. Assume anything typed in could be stored or seen.

Public information

Anything already published: our website, press releases, public reports

Internal information

Everyday internal material: meeting notes, process docs, internal emails that aren't sensitive

Confidential business information

Strategy, financials, pricing, contracts, unreleased plans

Personal data

Anything about an identifiable person: HR records, contact lists, customer records

Client data

Anything a client has shared with us, or that we hold for them

Regulated data

Health or payment card data, legally privileged material, anything under a specific regulation or contract restriction

How should AI output be checked?

Step 6 of 10

How should AI output be checked?

AI tools sound confident even when they're wrong. Who checks, and what for?

Always

When should people say AI was used?

Step 7 of 10

When should people say AI was used?

With clients

With colleagues

What's not allowed?

Step 8 of 10

What's not allowed?

Tick the ones that apply, and add your own.

Where should people ask questions?

Step 9 of 10

Where should people ask questions?

A person, a team inbox or a chat channel. The policy points here whenever someone's unsure, or something's gone wrong.

When will you review it?

Step 10 of 10

When will you review it?

AI tools change fast. Six months is a sensible default.

Your policy will have eight short sections:

Why we have this · Approved tools · What you can put in · What you must never put in · Checking AI output · Being open about AI use · Not allowed · Questions