Here is an uncomfortable truth for many leaders: your team is already using AI. They are drafting emails, summarizing documents, and brainstorming with tools you may not have approved, and some of them are pasting in information that should never leave your organization.

The answer is not to ban AI. Bans are hard to enforce and leave real productivity gains on the table. The answer is a short, clear policy that tells people how to use AI well.

You do not need a legal department to write one. You need a few pages covering the sections below.

1. Purpose and principles

Open with why. Explain that the organization supports responsible AI use to improve work, and state the principles that guide it. For example:

  • AI supports human judgment; it does not replace accountability.
  • We protect the privacy and dignity of the people whose data we hold.
  • We are honest about when and how AI is used.
  • We check AI output before we rely on it.

Principles help people make good decisions in situations the policy did not anticipate.

2. Approved tools

List which AI tools staff may use for work, and under which accounts. Prefer business or enterprise plans with clear terms around data retention and model training. Explain how someone can request a new tool, so people have a path other than working around the policy.

3. Data rules

This is the most important section. Be concrete about what may and may not be entered into AI tools. A simple tiered approach works well:

  • Green (okay): public information, general questions, your own drafts with no sensitive details.
  • Yellow (approved tools only): internal documents, non-sensitive business information.
  • Red (never, unless a specific system has been approved for it): personal information about clients, donors, patients, students, or employees; financial account details; passwords and credentials; confidential legal or HR matters; anything covered by contracts or regulations.

Give examples relevant to your work. “Do not paste case notes into a chatbot” is clearer than “protect PII.”

4. Human review and accountability

Make it explicit that people are responsible for anything they produce with AI assistance. AI can generate confident, plausible, and completely wrong content, including made-up facts, citations, and figures. Require review before AI-assisted work is published, sent externally, or used in decisions.

Identify high-stakes uses that need extra care or are off-limits entirely, such as decisions about hiring, eligibility for services, or anything affecting someone’s safety or rights.

5. Transparency

Decide when AI use should be disclosed. Common approaches include disclosing when content is substantially AI-generated, when people interact directly with an AI system (for example, a chatbot), and when funders, clients, or publications have their own disclosure requirements.

6. Intellectual property and quality

Remind staff to respect copyright, avoid passing off others’ work as their own, and to be cautious about using AI output in materials where ownership matters. Encourage people to keep their own voice and your brand voice. AI is a draft partner, not an author.

7. Bias and fairness

Ask staff to watch for outputs that stereotype, exclude, or treat groups unfairly, especially in content about the communities you serve. Provide a simple way to report concerns.

8. Training, ownership, and review

Name who owns the policy, how staff will be trained, and how often it will be revisited. AI capabilities change quickly, so review at least annually, and preferably every six months.


Keep it short, and make it real

The best AI policies are short enough to read in ten minutes and specific enough to act on. Pair yours with a hands-on training session and a few examples drawn from your team’s actual work.

A policy is also a starting point, not the finish line. Once you have guardrails in place, you can confidently explore the use cases that will make the biggest difference, whether that’s a knowledge assistant grounded in your own documents or automation for your most time-consuming workflows.

If you would like help drafting a policy tailored to your organization, or training your team to use AI responsibly, our AI & predictive analytics practice can help.