The one-page AI policy template.
An AI usage policy your team will actually read: approved tools, plain-language data rules, clear review lines, and a named owner. Copy it below or download it, adapt the brackets, and ship it this week — the full reasoning behind each section lives in the AI governance guide.
[Company Name] — AI Usage Policy
Version 1.0 · Effective [Date] · Owner: [Name, Title] · Applies to all employees and contractors
1. Purpose
AI tools make us faster and better at our work, and we encourage their use — within the rules below. This policy exists so that everyone knows what is allowed, what is not, and who to ask. It is one page on purpose. Read it once; follow it always.
2. Approved tools
Use AI tools from the approved list only, with your company account. List each tool, what it's approved for, and the account type — for example: ChatGPT Team — drafting, research — company workspace.
To request a new tool, send the owner the tool name, what you'd use it for, and what data it would touch, with an answer promised within five business days. Until approved, it isn't used for company work — including free trials on personal accounts.
3. Data rules
Know your data class before you paste:
- Public (website copy, published material): any approved tool.
- Internal (drafts, plans, non-identifying business data): approved tools on company accounts only.
- Restricted (customer PII, financials, contracts, credentials, health or payment data, anything under NDA): never enters any AI tool unless the owner has approved that specific tool for that specific use in writing.
If you are unsure which class something is, treat it as Restricted and ask.
4. Output review
AI output that reaches a customer, a contract, a financial decision, or a public channel must be reviewed and approved by a human before it goes out. The reviewer is accountable for what ships — “the AI wrote it” is not a defense.
Internal drafts, brainstorming, and research need no formal review. Never present AI output as fact without checking it — AI tools state wrong things confidently.
5. Accountability & incidents
A named owner holds this policy: approvals, questions, and enforcement. If AI use goes wrong — data pasted somewhere it shouldn't be, a wrong AI-generated answer reaching a customer — the owner hears about it the same day. Fast reporting of honest mistakes is never punished; hiding them is.
This policy is reviewed quarterly.
The policy is step one of five.
A policy without ownership, tool approval, review rhythm, and incident response is a document, not governance. The five-pillar framework covers the rest — and the readiness assessment will show you which pillar needs attention first.
Read the Governance Guide