Quick takeaways
- A good policy is short enough that people can actually follow it.
- Start with approved use cases, data rules, and review expectations.
- Policy should protect the company without blocking useful work.
How to write an AI policy
Tandem, LLC walks through how to write a practical AI policy for your organization.
Policy sections
Approved tools
List the tools and model types the team may use.
Data handling
Define what cannot be entered into external systems.
Human review
Set where outputs need approval before use.
External sharing
Clarify what can be sent to customers or published.
Sample rules
- Do not upload confidential customer, financial, or legal data unless the tool is approved for that purpose.
- Do not publish AI-generated content without human review.
- Use AI to draft code changes only when code review and tests are part of the workflow.
- Escalate any output that appears inaccurate, unsafe, or off-brand.
Fill-in-the-blanks template
Copy the sections below into your own document and fill in the blanks with your team's specifics.
1. Purpose and scope
This policy applies to [team/company] employees and contractors using AI tools for [list of work types]. The goal is to enable useful AI adoption while protecting [customer data / intellectual property / legal and financial information].
2. Approved tools
The following tools are approved for general use: [list tools]. Other tools may be used only after [approval process]. Employees may not use unapproved tools for [specific high-risk work].
3. Data handling rules
Do not enter the following into AI tools unless explicitly approved: customer personal data, financial records, legal documents, proprietary source code, unreleased product information, and confidential third-party data. When in doubt, ask [contact/team].
4. Review requirements
All AI-generated outputs must be reviewed before [external sharing / publishing / use in customer-facing materials]. Code changes require [code review and tests]. Marketing content requires [editorial and legal review].
5. Employee training
Employees must complete [training name or link] before using AI tools on company work. Training covers approved tools, data rules, review expectations, and how to report problems.
6. Incident response
If sensitive data is entered into an unapproved tool, or if an AI output causes harm, report it to [contact] within [timeframe]. Do not try to hide the mistake.
How to adapt the template
Keep the policy short, concrete, and aligned with the workflows your team actually uses. The goal is not to create a legal document nobody reads. The goal is to define clear usage boundaries and reduce risk.
- Replace bracketed placeholders with your team's real rules.
- Run the draft past legal, security, and operations leads.
- Publish the policy where employees can find it easily.
- Review it quarterly or whenever a new tool category becomes relevant.
Policy is a living document. If it does not reflect how people actually work, they will ignore it. Update it when workflows, tools, or risks change.
Without AI vs. with AI
| Task | Without AI | With AI |
|---|---|---|
| Policy drafting | Teams stare at a blank page and copy generic language from the internet. | AI structures policy sections from your approved tools, data classes, and review owners. |
| Approved tools list | A scattered spreadsheet that is outdated before it is shared. | AI-assisted inventory captures tool name, owner, data tier, and review status in one place. |
| Data rules | Legal language employees skim but do not understand. | AI drafts concrete examples of what can and cannot enter AI tools for your industry. |
| Review workflows | Ad-hoc approvals over email with no clear record. | AI drafts routing rules, checklists, and escalation paths tied to risk tiers. |
| Employee Q&A | Repeated explanations from HR and legal. | AI answers common policy questions consistently and points people to the right owner. |
FAQ
Does every team need an AI policy?
If the team uses AI on company work, yes. The policy can be short, but it should exist.
What should be in the first version?
Approved tools, data rules, review expectations, and responsibilities.
How often should the policy be updated?
At least quarterly, or whenever new tools, regulations, or incidents change the risk picture.
Who should approve the policy?
At minimum, legal, security, and operations. For small teams, the founder or CEO can own the first version.
What if someone breaks the policy?
Make escalation easy and non-punitive for honest mistakes. Repeated or intentional violations need clearer consequences.
Can this template be used for clients?
Yes, but adapt it to the client's industry, regulations, and risk profile.
Can AI write our entire AI policy?
AI can draft structure and first-pass language, but the final rules, risk appetite, and approvals must come from legal, security, and leadership.
How do we keep the policy from being too restrictive?
Focus on high-risk data and decisions; allow approved tools for low-risk work, and make the request process fast so people do not bypass it.
What is the minimum viable AI policy?
Scope, approved tools, prohibited data, review requirements, and a clear escalation path are enough for a first version.
How do we enforce the policy without blocking productivity?
Pair clear rules with useful approved tools, fast exception requests, and monitoring that catches mistakes rather than punishing exploration.