Most organisations discover they need one the week a client asks for it. This sets out what an AI use policy should actually contain, the mistakes that make one worthless, and where it fits inside real AI governance.
An AI use policy exists to let your people use AI confidently rather than quietly. In most organisations AI adoption has already happened — informally, tool by tool, without anyone deciding it was allowed. Staff use what helps them and hope nobody minds.
That is the real risk position: not reckless use, but unmanaged use, where nobody can say what is running, on what data, informing which decisions.
Prohibition drives AI use underground, where you can neither see nor govern it. The policies that work state clearly what is permitted, so the sanctioned path is the easy one.
Not a template — the substance any credible policy has to address, whatever structure you put it in.
Which people (employees, contractors, third parties) and which systems. Be explicit that it covers AI features embedded in tools you already use, not only obvious standalone chatbots — that is where most unexamined AI use hides.
Which tools are approved, for what purposes. State the hard lines plainly: what must never be entered into a public AI tool, and which decisions may never be made by AI without a human accountable for the outcome.
The clause staff will actually consult. What categories of information may go into which tools — client data, personal information, commercially sensitive material, anything under a confidentiality obligation. Write it so someone can check in ten seconds.
Where a human must review AI output before it is relied upon, and who is accountable for AI-assisted decisions. Accountability sits with people; it is never transferred to a tool.
Who owns this policy, who approves exceptions, and who a staff member asks when a situation is not covered. A name and a role — not a department.
When AI involvement must be disclosed — to clients, in deliverables, or to individuals affected by an AI-informed decision. Increasingly a contractual and procurement question, not merely an ethical one.
What counts as an AI-related incident and how to report it. Make reporting safe and low-friction: if staff fear blame, you will hear about problems only once they have become client-visible.
How often the policy is reviewed, by whom, and what triggers an off-cycle review. Date it and version it, so its currency is provable.
Issued once by email, never referenced again. If staff cannot recall its existence, it governs nothing — and an auditor will establish that in a single interview.
A blanket prohibition nobody follows is worse than a permissive policy people actually observe, because it creates a documented gap between stated and real practice.
No named owner means no one maintains it, no one handles exceptions, and no one can answer questions about it.
Policies written around specific products expire the moment the product changes. Write rules about conduct and data, and they survive the tooling.
A policy with no inventory, no risk assessment and no review behind it is a statement of intent. Asked for evidence that it operates, there is nothing to show.
The policy is the visible artefact. It is a small part of what makes AI governance defensible.
| Component | Question it answers |
|---|---|
| AI use policy | What are the rules? |
| AI inventory / use-case register | Where is AI actually being used? |
| AI risk & impact assessment | What could go wrong, and who would it affect? |
| Accountability model | Who is answerable when it does? |
| Human oversight arrangements | Where must a person stay in the loop? |
| Monitoring & review | How do we know the rules are still followed? |
ISO/IEC 42001 is the international standard that ties these together into a management system. You can build them without certifying — but the components still have to exist, because it is the whole set, not the policy alone, that answers a procurement officer's questions.
You can, and it will get you a document. What it will not get you is governance. A template cannot know which AI tools your people are actually using, what data those tools touch, which decisions they influence, or who in your organisation is accountable when one gets it wrong.
Templates are a reasonable starting structure. They become a liability when they are adopted unchanged and then presented as evidence of governance to a client or auditor who asks one question past the cover page.
Short enough that people read it. A policy that runs to thirty pages will be acknowledged and never opened again.
The practical pattern is a concise policy stating the rules and who owns them, supported by separate, more detailed procedures for the people who need them. Keep the thing everyone must read genuinely readable.
A named individual with enough authority to enforce it — not "the IT team" or "management" in the abstract. Diffuse ownership is the most reliable predictor of a policy that quietly stops being followed.
Ownership means someone is answerable for keeping the policy current, handling exceptions, and being the person a staff member can actually ask when a situation is not covered.
No. A policy is one required component of an AI management system, not the system itself. ISO/IEC 42001 also expects an inventory of where AI is used, AI risk and impact assessment, defined accountability, human oversight, competence, internal audit and management review.
Put plainly: the policy states your intent. The management system is what demonstrates you act on it.
At least annually, and additionally whenever something material changes — a new AI tool adopted, a significant incident, a change in what you have committed to clients, or a shift in regulatory expectations.
Record the review even when nothing changes. "Reviewed, no change required, approved by [name], [date]" is evidence. An undated policy of unknown vintage is not.
That is the most common position we find, and it is a fixable one. A gap assessment shows where your AI use actually sits, what governance you already have, and the shortest defensible path to the rest — in plain language.