How to write a company AI use policy people will actually follow
By TechlyUpUpdated 2 min readLeaders, HR, legal, and IT
Quick answer
A usable AI policy is short and specific: which tools are approved, what data may and may not be used, when human review is required, when AI use must be disclosed, who is accountable, and how to ask questions or report problems. Pair it with training and examples — a policy nobody understands won't be followed.
Core sections
Cover these, in plain language.
- Purpose and scope: who and what the policy covers.
- Approved tools and how to request new ones.
- Data rules: prohibited data types and conditions for sensitive data.
- Human review: which outputs must be checked and by whom.
- Disclosure: when to tell customers or colleagues AI was used.
- Accountability: the person using AI remains responsible for the work.
- Reporting: how to raise concerns or incidents.
Make it practical
Add examples for each rule: “You may summarise internal meeting notes with [approved tool]. You may not paste customer phone numbers into consumer AI apps.”
Align with law and ethics
Check the policy against data protection obligations such as India's DPDP Act, sector regulations, and recognised principles like the OECD AI Principles.
Review regularly
Tools and risks change quickly. Review the policy every six to twelve months and after incidents.
Policy mistakes
These make policies ignored or harmful.
- Writing in legal language employees can't apply.
- Listing prohibitions without approved alternatives.
- Never communicating the policy beyond an intranet page.
- Failing to update it as tools change.
A one-page policy structure
Many organisations start with something this short.
AI Use Policy (v1) 1. Approved tools: [list] — request others via [link] 2. Never share: personal data, credentials, confidential client info (unless tool approved for it) 3. Always review AI output before it leaves your team 4. Disclose AI use to customers when [criteria] 5. You remain responsible for your work 6. Questions/incidents: [contact] Reviewed: [date]
Try it yourself
Draft the data-rules section of your policy with three allowed and three prohibited examples relevant to your business.
Frequently asked questions
Do small businesses need an AI policy?
Even a one-page policy helps staff use AI safely and consistently.
Should we ban consumer AI tools?
Many organisations restrict them for sensitive data while providing approved alternatives.
Who should own the AI policy?
Usually a cross-functional group including IT/security, legal/compliance, HR, and business leaders.
Want a suggested next step for your situation?
Share a few details and someone from TechlyUp will get back to you. No automated sequences.
Sources and further reading
Examples are authored practice material, not measured learner outcomes. Tool behavior can change. Found an error? Contact TechlyUp with the page URL and correction.