How to write an AI usage policy

Most AI policies fail the same way. Someone finds a template, adapts twelve pages of it, circulates it once, and it's never read again. Meanwhile the actual decisions — can I paste this client email in? — keep getting made by whoever has the deadline.

A policy that works is short enough to remember and specific enough to act on. Four questions do most of the work.

1. Which tools are approved?

Name them. Not "approved AI tools" — the actual products, and which account people should use.

This is the highest-value line in the document, because it's the one that removes the excuse. Staff reach for free consumer tools mainly when nothing else has been provided. Approving a business-tier account and saying so eliminates most unsanctioned use at a stroke.

Say what to do about anything not on the list, too: usually "ask before using", not silence.

2. What may and may not go in?

Three buckets are enough, and examples beat definitions. Use your own work, not generic categories:

Add one habit that carries a lot of weight: refer to clients as "Client A" rather than by name. It costs nothing and moves a great deal of work from the second bucket into the first.

3. When must a human check the output?

The rule that matters: anything that leaves the business, or that someone will rely on, gets read by a person first.

Worth spelling out where checking is non-negotiable:

AI output is confident regardless of whether it's right, which is precisely why the checking step can't be left to judgement in a hurry.

4. Who do I ask?

Name a person. The most common reason a policy gets breached isn't disagreement — it's an edge case at 4:45pm with nobody obvious to ask.

One named person, and an explicit line that asking is always the right call, converts most of your risk into a thirty-second conversation.

An Australian small-business example

A 15-person Adelaide engineering consultancy wrote a two-page policy, got it signed, and saw no change in behaviour — staff couldn't recall what it said.

They replaced it with a single page: the approved tool and login, the three buckets using their own project examples, the four must-check situations, and the operations manager's name.

It went on the wall by the printer and into the induction pack. Six months on, people quote it in conversation — which is the only test that matters. Same obligations, a fraction of the words, and it's actually operating.

What to leave out

The test

Hand it to someone who wasn't involved in writing it and ask: can I put this client email into AI to draft a reply?

If they can answer from the page in under thirty seconds, it's a working policy. If they have to search, interpret or guess, it's a document — and documents don't change what happens at 4:45pm on a Friday.

Frequently asked questions

Do we really need a policy? We're only ten people.
Ten people is exactly where it pays off, because informal norms don't survive a busy week. It needn't be formal — one page pinned where people work is a policy. The alternative isn't 'no policy', it's ten different personal ones.
Should we just ban AI to be safe?
Bans reliably move usage somewhere you can't see rather than stopping it, because the productivity gain is real and staff are under pressure. You end up with the same risk minus any visibility. Approving a tool and setting limits is the safer position.
Who should write it?
Someone who understands the work, with input from whoever owns risk. It shouldn't be drafted by a person who has never used the tools — that's how you get rules that are impossible to follow and get ignored on day one.
How often should we update it?
Look at it every six months, and whenever you add a tool or something surprises you. The tools change quickly; the principles in a good policy change slowly.
Does this satisfy our legal obligations?
A policy is a control, not a substitute for advice. If you handle health, financial, government or other regulated information, get advice specific to your obligations. This guide is general information only.

Put this to work

Ad On Group runs AI training and enablement for Australian teams through Ad On AI — a three-month, self-paced program that takes non-technical staff from their first prompts to working AI agents.

Talk to us →

Keep reading

← All resources