How to write a one-page AI use policy

A single one-page policy document with a checklist and a pen resting beside it, representing a short editable AI use policy template

Most AI policies fail for a boring reason. They are too long to read. A twelve-page document written to satisfy a compliance checklist gets skimmed once during onboarding and never opened again. Meanwhile the person who actually needed guidance is sitting in front of a chatbot at four in the afternoon with a customer email in their clipboard, and the policy that would have helped them is buried in a shared drive folder nobody can find.

So here is a one-page version you can copy, fill in, and hand out this week. The full text is below, and there is an editable file at the end if you would rather not retype it.

What an AI use policy actually needs to cover

Three things. Everything past these three is refinement, and refinement is what pushes a policy past the length anyone will read.

  1. Which AI tools people are allowed to use for work
  2. What information never gets pasted into them
  3. Who to ask when something is not covered

That is the whole structure. Everything else is optional. A policy answering those three questions clearly prevents more problems than a long one answering forty questions vaguely, because people remember what it says.

The template, in full

Replace anything in brackets. Cut anything that does not apply to your business. If it grows past one page, something on it is not earning its place.

Section 1: Approved AI tools

These are the AI tools approved for company work at [Company name]. If a tool is not on this list, ask before using it for anything work related.

List each approved tool with what it is approved for and which account to use. For example: ChatGPT, approved for drafting and summarizing, using the company business account. Microsoft Copilot, approved for document and email drafting, using your company login.

Keep this list short at first. Two or three tools you have actually looked at will serve you better than a dozen you have not, and adding to the list later is easy.

Section 2: Never paste this into an AI tool

The following never goes into any AI tool, approved or not:

  • Customer personal information
  • Payroll and HR records
  • Anything covered by a nondisclosure agreement
  • Passwords, keys, and access codes
  • Unreleased financial information
  • Regulated data, including health, legal, and financial records

If you are not sure whether something belongs on this list, assume it does and ask.

Section 3: Ground rules

Use the company account, not your personal one. Business AI accounts keep company data out of model training and give us administrative controls. Personal accounts do neither, and we cannot revoke access to an account we do not own.

If our IT provider did not give you the tool, company information does not go into it. Inexpensive AI sites are often built on someone else’s model, and the data flowing through them can be part of how they make money.

A person signs off on anything that leaves the company. Nothing goes to a customer, a regulator, a bank, or an insurer without a named person reviewing it first. AI drafts, a human owns the result.

Section 4: Who to ask

Questions about AI tools, requests to add a tool to the approved list, and anything along the lines of “I think I pasted something I should not have” go to [Name], at [email] or [phone].

Ask early. Nobody is in trouble for asking, and the questions we get before something happens are far easier to answer than the ones that come after.

How to fill in each section without overthinking it

The approved tools list is where most people stall, because it feels like it requires an evaluation process. It does not. Start with what your team already uses and what you already pay for, then confirm two things about each one: whether a business tier exists, and whether you are on it.

The never list is worth real time, because it is the section that changes by industry. The six items in the template are the baseline. They apply to almost everyone. What you add on top depends on what your business handles.

If your business isAdd to the never list
Healthcare or dentalAnything identifying a patient, including scheduling notes and insurance details
LegalClient matter details, filings before they are public, anything privileged
Financial services or accountingAccount numbers, tax identifiers, client portfolio detail
Engineering or architectureDrawings and specifications under client contract, bid pricing
ManufacturingProcess documentation, supplier pricing, anything covered by a customer agreement
NonprofitDonor records, beneficiary information, grant material before award

The ground rules generally transfer as written. The one worth adapting is the sign-off rule. “Leaves the company” means something different in a firm where every deliverable already gets reviewed than it does in a business where a salesperson can email a proposal without anyone else seeing it.

For the last section, put a real name on it. A policy that routes questions to a department, an inbox, or a document tends to route them nowhere, and the first unanswered question is usually the last one anybody bothers to ask.

What to leave out

A few things commonly appear in AI policies and earn their space only in larger organizations.

Skip the definitions section. Your team does not need a paragraph explaining what a large language model is in order to know not to paste payroll data into one. Save the vocabulary lesson for people who asked for it.

Skip the approval workflow. A form and a review queue sound responsible, but in a business of twenty to two hundred people they mostly guarantee that people stop asking and start guessing. A named person who answers quickly does the same job better.

Skip the disciplinary language, at least in version one. The goal of this document is that people tell you things. Opening with consequences works against that. You can always add teeth later if you find you need them.

Skip the list of banned tools. It will be out of date within a month, and maintaining it becomes somebody’s recurring chore for no real gain. Approve a short list instead and let everything else fall outside it by default.

Rolling it out in about twenty minutes

Send the page before the meeting, not during it. People read a one-page document if it arrives on its own and takes ninety seconds, and they stop reading the moment it becomes an attachment inside a longer message.

Then use a few minutes of an existing meeting rather than scheduling something new. Walk the three sections, say plainly that nobody is in trouble for what they have already done, and ask what tools people are using that are not on the list. That last question is the one that makes the document accurate, and you will usually get at least one answer that surprises you.

Collect acknowledgments if your industry expects it. Skip that step if it does not. Chasing signatures on a document people have already read adds friction without adding safety.

Then set a review date six months out and put it on the calendar. This space moves fast enough that a policy written today needs another look before the year ends. A date on the page is what keeps it from going stale.

Common questions

What should an AI use policy include?

At minimum: the AI tools approved for company use, the categories of information that must never be entered into them, and a named person to contact with questions. Larger organizations add data classification schemes, vendor review procedures, and audit requirements. Most small and midsize businesses do not need those. The three basics carry most of the benefit.

Is an AI acceptable use policy the same as an AI governance framework?

No, though the terms get used interchangeably. A governance framework is an organizational program covering risk assessment, model oversight, documentation, and accountability structures, and it is generally aimed at companies building or deploying AI systems at scale. An acceptable use policy is a set of rules for employees using AI tools in their daily work. If you are a business with employees using chatbots, the policy is what you need.

Do we need a separate policy for AI, or can we add it to our existing IT policy?

Either works. A standalone page tends to get read more often, since it is short and its purpose is obvious. If you add it to an existing acceptable use policy, put it in its own clearly labeled section rather than distributing it through the document, so people can find it when they have a specific question.

What if employees are already using AI tools we never approved?

Assume they are, because they almost certainly are. That situation has a name and a set of specific risks, and we covered it in our guide to shadow AI. The short version is that a policy works better when it starts by asking what people already use rather than declaring what they may not.

How often should the policy be updated?

Every six months is a reasonable default, plus any time you add a tool or change account tiers. The approved tools list ages fastest, since products and pricing tiers shift constantly. The never list rarely changes.

Take the template

The editable version is below. It is a one-page Word document with the tool table, the never list, the ground rules, and a signature line. Change it however you like. It is yours.

If you would rather have someone check your work first, our team can look at which AI features are already turned on in the software you pay for, whether your accounts are on the right tier, and what belongs on your never list given the kind of information your business handles. That conversation usually takes half an hour and it costs nothing.

Either way, write the page. An hour of work now is cheaper than the conversation that starts with an employee saying they think they pasted something they should not have. That conversation happens eventually. The page decides how bad it is.