Practical Guide

What belongs in an AI use policy

Most organisations discover they need one the week a client asks for it. This sets out what an AI use policy should actually contain, the mistakes that make one worthless, and where it fits inside real AI governance.

What to include Common mistakes

Last reviewed July 2026 · Bcom — ISO/IEC 42001 specialists, Australia

What the policy is actually for

An AI use policy exists to let your people use AI confidently rather than quietly. In most organisations AI adoption has already happened — informally, tool by tool, without anyone deciding it was allowed. Staff use what helps them and hope nobody minds.

That is the real risk position: not reckless use, but unmanaged use, where nobody can say what is running, on what data, informing which decisions.

A policy that only says no is a policy that gets bypassed

Prohibition drives AI use underground, where you can neither see nor govern it. The policies that work state clearly what is permitted, so the sanctioned path is the easy one.

What an AI use policy should contain

Not a template — the substance any credible policy has to address, whatever structure you put it in.

1. Scope: who and what it covers

Which people (employees, contractors, third parties) and which systems. Be explicit that it covers AI features embedded in tools you already use, not only obvious standalone chatbots — that is where most unexamined AI use hides.

2. Permitted and prohibited use

Which tools are approved, for what purposes. State the hard lines plainly: what must never be entered into a public AI tool, and which decisions may never be made by AI without a human accountable for the outcome.

3. Data handling rules

The clause staff will actually consult. What categories of information may go into which tools — client data, personal information, commercially sensitive material, anything under a confidentiality obligation. Write it so someone can check in ten seconds.

4. Human oversight and accountability

Where a human must review AI output before it is relied upon, and who is accountable for AI-assisted decisions. Accountability sits with people; it is never transferred to a tool.

5. Named ownership

Who owns this policy, who approves exceptions, and who a staff member asks when a situation is not covered. A name and a role — not a department.

6. Disclosure and transparency

When AI involvement must be disclosed — to clients, in deliverables, or to individuals affected by an AI-informed decision. Increasingly a contractual and procurement question, not merely an ethical one.

7. Incident reporting

What counts as an AI-related incident and how to report it. Make reporting safe and low-friction: if staff fear blame, you will hear about problems only once they have become client-visible.

8. Review cycle

How often the policy is reviewed, by whom, and what triggers an off-cycle review. Date it and version it, so its currency is provable.

Five mistakes that make a policy worthless

It was never read

Issued once by email, never referenced again. If staff cannot recall its existence, it governs nothing — and an auditor will establish that in a single interview.

It bans everything

A blanket prohibition nobody follows is worse than a permissive policy people actually observe, because it creates a documented gap between stated and real practice.

Nobody owns it

No named owner means no one maintains it, no one handles exceptions, and no one can answer questions about it.

It describes tools, not behaviour

Policies written around specific products expire the moment the product changes. Write rules about conduct and data, and they survive the tooling.

It stands alone

A policy with no inventory, no risk assessment and no review behind it is a statement of intent. Asked for evidence that it operates, there is nothing to show.

Where the policy fits in real governance

The policy is the visible artefact. It is a small part of what makes AI governance defensible.

ComponentQuestion it answers
AI use policyWhat are the rules?
AI inventory / use-case registerWhere is AI actually being used?
AI risk & impact assessmentWhat could go wrong, and who would it affect?
Accountability modelWho is answerable when it does?
Human oversight arrangementsWhere must a person stay in the loop?
Monitoring & reviewHow do we know the rules are still followed?

ISO/IEC 42001 is the international standard that ties these together into a management system. You can build them without certifying — but the components still have to exist, because it is the whole set, not the policy alone, that answers a procurement officer's questions.

Frequently asked questions

Can we just download an AI policy template?

You can, and it will get you a document. What it will not get you is governance. A template cannot know which AI tools your people are actually using, what data those tools touch, which decisions they influence, or who in your organisation is accountable when one gets it wrong.

Templates are a reasonable starting structure. They become a liability when they are adopted unchanged and then presented as evidence of governance to a client or auditor who asks one question past the cover page.

How long should an AI use policy be?

Short enough that people read it. A policy that runs to thirty pages will be acknowledged and never opened again.

The practical pattern is a concise policy stating the rules and who owns them, supported by separate, more detailed procedures for the people who need them. Keep the thing everyone must read genuinely readable.

Who should own the AI policy?

A named individual with enough authority to enforce it — not "the IT team" or "management" in the abstract. Diffuse ownership is the most reliable predictor of a policy that quietly stops being followed.

Ownership means someone is answerable for keeping the policy current, handling exceptions, and being the person a staff member can actually ask when a situation is not covered.

Does an AI use policy satisfy ISO/IEC 42001?

No. A policy is one required component of an AI management system, not the system itself. ISO/IEC 42001 also expects an inventory of where AI is used, AI risk and impact assessment, defined accountability, human oversight, competence, internal audit and management review.

Put plainly: the policy states your intent. The management system is what demonstrates you act on it.

How often should it be reviewed?

At least annually, and additionally whenever something material changes — a new AI tool adopted, a significant incident, a change in what you have committed to clients, or a shift in regulatory expectations.

Record the review even when nothing changes. "Reviewed, no change required, approved by [name], [date]" is evidence. An undated policy of unknown vintage is not.

Have a policy, but nothing behind it?

That is the most common position we find, and it is a fixable one. A gap assessment shows where your AI use actually sits, what governance you already have, and the shortest defensible path to the rest — in plain language.

Book a gap assessment See our governance framework