How to write a one-page AI use policy
Most AI policies fail for a boring reason. They are too long to read. A twelve-page document written to satisfy a compliance checklist gets skimmed once during onboarding and never opened again. Meanwhile the person who actually needed guidance is sitting in front of a chatbot at four in the afternoon with a customer email in their clipboard, and the policy that would have helped them is buried in a shared drive folder nobody can find.
So here is a one-page version you can copy, fill in, and hand out this week. The full text is below, and there is an editable file at the end if you would rather not retype it.
What an AI use policy actually needs to cover
Three things. Everything past these three is refinement, and refinement is what pushes a policy past the length anyone will read.
- Which AI tools people are allowed to use for work
- What information never gets pasted into them
- Who to ask when something is not covered
That is the whole structure. Everything else is optional. A policy answering those three questions clearly prevents more problems than a long one answering forty questions vaguely, because people remember what it says.
The template, in full
Replace anything in brackets. Cut anything that does not apply to your business. If it grows past one page, something on it is not earning its place.
Section 1: Approved AI tools
These are the AI tools approved for company work at [Company name]. If a tool is not on this list, ask before using it for anything work related.
List each approved tool with what it is approved for and which account to use. For example: ChatGPT, approved for drafting and summarizing, using the company business account. Microsoft Copilot, approved for document and email drafting, using your company login.
Keep this list short at first. Two or three tools you have actually looked at will serve you better than a dozen you have not, and adding to the list later is easy.
Section 2: Never paste this into an AI tool
The following never goes into any AI tool, approved or not:
- Customer personal information
- Payroll and HR records
- Anything covered by a nondisclosure agreement
- Passwords, keys, and access codes
- Unreleased financial information
- Regulated data, including health, legal, and financial records
If you are not sure whether something belongs on this list, assume it does and ask.
Section 3: Ground rules
Use the company account, not your personal one. Business AI accounts keep company data out of model training and give us administrative controls. Personal accounts do neither, and we cannot revoke access to an account we do not own.
If our IT provider did not give you the tool, company information does not go into it. Inexpensive AI sites are often built on someone else’s model, and the data flowing through them can be part of how they make money.
A person signs off on anything that leaves the company. Nothing goes to a customer, a regulator, a bank, or an insurer without a named person reviewing it first. AI drafts, a human owns the result.
Section 4: Who to ask
Questions about AI tools, requests to add a tool to the approved list, and anything along the lines of “I think I pasted something I should not have” go to [Name], at [email] or [phone].
Ask early. Nobody is in trouble for asking, and the questions we get before something happens are far easier to answer than the ones that come after.
How to fill in each section without overthinking it
The approved tools list is where most people stall, because it feels like it requires an evaluation process. It does not. Start with what your team already uses and what you already pay for, then confirm two things about each one: whether a business tier exists, and whether you are on it.
The never list is worth real time, because it is the section that changes by industry. The six items in the template are the baseline. They apply to almost everyone. What you add on top depends on what your business handles.
| If your business is | Add to the never list |
|---|---|
| Healthcare or dental | Anything identifying a patient, including scheduling notes and insurance details |
| Legal | Client matter details, filings before they are public, anything privileged |
| Financial services or accounting | Account numbers, tax identifiers, client portfolio detail |
| Engineering or architecture | Drawings and specifications under client contract, bid pricing |
| Manufacturing | Process documentation, supplier pricing, anything covered by a customer agreement |
| Nonprofit | Donor records, beneficiary information, grant material before award |
The ground rules generally transfer as written. The one worth adapting is the sign-off rule. “Leaves the company” means something different in a firm where every deliverable already gets reviewed than it does in a business where a salesperson can email a proposal without anyone else seeing it.
For the last section, put a real name on it. A policy that routes questions to a department, an inbox, or a document tends to route them nowhere, and the first unanswered question is usually the last one anybody bothers to ask.
What to leave out
A few things commonly appear in AI policies and earn their space only in larger organizations.
Skip the definitions section. Your team does not need a paragraph explaining what a large language model is in order to know not to paste payroll data into one. Save the vocabulary lesson for people who asked for it.
Skip the approval workflow. A form and a review queue sound responsible, but in a business of twenty to two hundred people they mostly guarantee that people stop asking and start guessing. A named person who answers quickly does the same job better.
Skip the disciplinary language, at least in version one. The goal of this document is that people tell you things. Opening with consequences works against that. You can always add teeth later if you find you need them.
Skip the list of banned tools. It will be out of date within a month, and maintaining it becomes somebody’s recurring chore for no real gain. Approve a short list instead and let everything else fall outside it by default.
Rolling it out in about twenty minutes
Send the page before the meeting, not during it. People read a one-page document if it arrives on its own and takes ninety seconds, and they stop reading the moment it becomes an attachment inside a longer message.
Then use a few minutes of an existing meeting rather than scheduling something new. Walk the three sections, say plainly that nobody is in trouble for what they have already done, and ask what tools people are using that are not on the list. That last question is the one that makes the document accurate, and you will usually get at least one answer that surprises you.
Collect acknowledgments if your industry expects it. Skip that step if it does not. Chasing signatures on a document people have already read adds friction without adding safety.
Then set a review date six months out and put it on the calendar. This space moves fast enough that a policy written today needs another look before the year ends. A date on the page is what keeps it from going stale.
Common questions
At minimum: the AI tools approved for company use, the categories of information that must never be entered into them, and a named person to contact with questions. Larger organizations add data classification schemes, vendor review procedures, and audit requirements. Most small and midsize businesses do not need those. The three basics carry most of the benefit.
No, though the terms get used interchangeably. A governance framework is an organizational program covering risk assessment, model oversight, documentation, and accountability structures, and it is generally aimed at companies building or deploying AI systems at scale. An acceptable use policy is a set of rules for employees using AI tools in their daily work. If you are a business with employees using chatbots, the policy is what you need.
Either works. A standalone page tends to get read more often, since it is short and its purpose is obvious. If you add it to an existing acceptable use policy, put it in its own clearly labeled section rather than distributing it through the document, so people can find it when they have a specific question.
Assume they are, because they almost certainly are. That situation has a name and a set of specific risks, and we covered it in our guide to shadow AI. The short version is that a policy works better when it starts by asking what people already use rather than declaring what they may not.
Every six months is a reasonable default, plus any time you add a tool or change account tiers. The approved tools list ages fastest, since products and pricing tiers shift constantly. The never list rarely changes.
Take the template
The editable version is below. It is a one-page Word document with the tool table, the never list, the ground rules, and a signature line. Change it however you like. It is yours.
If you would rather have someone check your work first, our team can look at which AI features are already turned on in the software you pay for, whether your accounts are on the right tier, and what belongs on your never list given the kind of information your business handles. That conversation usually takes half an hour and it costs nothing.
Either way, write the page. An hour of work now is cheaper than the conversation that starts with an employee saying they think they pasted something they should not have. That conversation happens eventually. The page decides how bad it is.