An AI policy that works answers four questions and fits on one page: who approves a new AI tool, what data must never go into a prompt, what output a human has to check before a customer sees it, and who owns it when something goes wrong. Everything else is padding. The full template is below, free, no form.

Here is the thing nobody says out loud in the meeting where this gets discussed: your team is already using AI. They started months ago, they used whatever was free, and they did not ask because asking looked like it would take six weeks and produce a no.

So the choice was never whether to allow AI. It was whether to know about it. A policy is how you find out.

Why most AI policies fail

They are written to survive a legal review rather than to be followed. Six pages, forty defined terms, a section on "responsible innovation", and nothing a person can act on at 4pm when they want to paste a customer email into a chatbot.

The test is simple. Can somebody who has never read the policy work out, in under a minute, whether the thing they are about to do is allowed? If not, it is not a policy, it is a document.

The four questions

1. Who approves a new AI tool?

Name a person, not a committee. Committees are how shadow AI happens: the wait is long enough that going around it is rational.

Give them a short, published list of what they check, so the answer is predictable rather than a mood. Business plan or personal? Does it train on our inputs? What data would go into it? Is there something we already pay for that does this? A good approver says yes most of the time, quickly, and that is what keeps the process honest.

2. What never goes in a prompt?

Be specific. "Confidential information" means nothing to anyone. List the categories in your language:

  • Customer personal information, unless the tool is on the approved list
  • Anything covered by an NDA with a named client
  • Employee records, health information, anything about someone's performance or pay
  • Credentials, keys, tokens. Ever. In anything.
  • Unreleased financials and anything price sensitive

Then give the alternative in the same breath, because a rule with no path just gets ignored. "Do not paste the contract. Describe the clause you are asking about."

3. What has to be checked by a human?

Draw the line at reach. Anything that leaves the building or changes a record gets checked. Internal drafts, brainstorming, summarising a document you already have, all fine unchecked.

Name who checks. "Someone should review it" means nobody does.

4. Who owns it when it goes wrong?

One named owner for AI in the business. Not for approving things, for the moment something is wrong and somebody needs to decide whether to switch it off. If nobody is named, the answer defaults to whoever notices, which is the worst possible answer.

The template

Copy it, fill the grey fields, publish it where people actually look. The grey is the only work this asks of you.

AI use at [your company]

The short version. AI is approved for use here. Use the tools on the approved list, do not put the restricted data below into any of them, and check anything before it reaches a customer.

Approved tools. [list them, with the plan type] Review this list quarterly, or it becomes a lie and people stop reading the page.

Getting a new tool approved. Ask [name]. They will answer within two business days. They check: business plan, whether it trains on our data, what data would go into it, and whether we already pay for something that does the job.

Never put into any AI tool: customer personal information unless the tool is approved for it, anything under a client NDA, employee records, health information, credentials or keys, unreleased financials.

A human checks it before: it goes to a customer, it changes a CRM record, it goes on the website, or it informs a decision about a person.

If something goes wrong, tell [name] the same day. You will not be in trouble for reporting it. You will be in trouble for hiding it.

Reviewed: [date]. Next review [date, six months on].

That is the whole thing. If yours is longer than that, ask what the extra pages are for and who reads them.

The three mistakes we see

Banning it. A ban does not stop usage, it stops reporting. You end up with the same risk and no visibility, which is strictly worse than where you started.

Writing it once. The tools change every quarter. A policy naming a product that no longer exists teaches people the document is decorative, and once they learn that, they stop checking it for the parts that matter.

Skipping the training. Most breaches are not malice, they are a person who genuinely did not know that pasting a customer list somewhere counted. Twenty minutes in an all-hands, once a year, with three real examples of what not to do. That is the whole training programme and it works better than the policy does.

Where this sits

If you want the formal scaffolding, Australia's AI Ethics Principles give you the language a board expects, and the NIST AI Risk Management Framework is the reference most enterprise procurement teams now use. Both are useful and neither is a policy. They are what you point at when someone asks what your one page is based on.

Write the page first. Map it to the frameworks later, if anyone asks.

Not sure what your team is already pasting into a chatbot?

Most businesses are surprised. We help work out what is actually in use, what to approve, and what to shut down, then leave you with a page people will actually follow.

We are Neighbourhood. We build the AI and the revenue system it runs on. AI and RevOps engineering for Australian teams. Diamond HubSpot Partner, 17 HubSpot Impact Awards.

Give us a shout and tell us what's broken.