Practical guide · AI policy

How to build an internal AI policy people can actually use

A useful internal AI policy turns real tool usage into clear rules for data, human verification, approval and incident handling.

Start with observed use, not legal phrasing

A credible policy does not assume management already knows every AI tool in use. Begin with a candid inventory: who uses AI, for which outcome, with which data categories and who checks the result.

The inventory is not a blame exercise. It lets the company distinguish useful practices from cases that need limits, additional approval or a stop decision.

Write rules for everyday decisions

An employee should be able to answer four questions quickly: may I use this tool, may I enter this data, who verifies the output and where do I report a problem? If the policy does not provide that route, people will improvise.

  • approved, conditional and non-approved tools
  • public, internal, confidential and personal data
  • human verification proportionate to impact
  • an owner and escalation route for each exception

Connect the policy to two different workflows

Approving a new tool and reporting an incident are different jobs. Approval evaluates purpose, data, provider and ownership. Incident handling limits harm, preserves facts and brings in the right roles.

Forms can be brief, but every request needs an owner and a visible decision.

Publish with training and a review date

The policy, employee guide, tool matrix and training material must agree. A session built around the company’s own use cases is more useful than reading a long policy aloud.

Schedule a 30-day review after launch. Real questions, approval requests and minor incidents show where the rules need clarification.

General educational material. It is not legal advice and does not replace legal, DPO, HR or security review appropriate to your organisation.