The one-page AI policy template.
Go from “no AI policy” to a policy your whole team can recite in about an hour, without a lawyer or a forty-page document. Approved tools, plain-language data rules, clear review lines, a named owner: the five sections that every AI incident I have seen this year broke one of. Copy it below or download it, fill the brackets, ship it this week. The reasoning behind each section lives in the AI governance guide.
[Company Name] — AI Usage Policy
Version 1.0 · Effective [Date] · Owner: [Name, Title] · Applies to all employees and contractors
1. Purpose
AI tools make us faster and better at our work, and we encourage their use — within the rules below. This policy exists so that everyone knows what is allowed, what is not, and who to ask. It is one page on purpose. Read it once; follow it always.
2. Approved tools
Use AI tools from the approved list only, with your company account. List each tool, what it's approved for, and the account type — for example: ChatGPT Team — drafting, research — company workspace.
To request a new tool, send the owner the tool name, what you'd use it for, and what data it would touch, with an answer promised within five business days. Until approved, it isn't used for company work — including free trials on personal accounts.
3. Data rules
Know your data class before you paste:
- Public (website copy, published material): any approved tool.
- Internal (drafts, plans, non-identifying business data): approved tools on company accounts only.
- Restricted (customer PII, financials, contracts, credentials, health or payment data, anything under NDA): never enters any AI tool unless the owner has approved that specific tool for that specific use in writing.
If you are unsure which class something is, treat it as Restricted and ask.
4. Output review
AI output that reaches a customer, a contract, a financial decision, or a public channel must be reviewed and approved by a human before it goes out. The reviewer is accountable for what ships — “the AI wrote it” is not a defense.
Internal drafts, brainstorming, and research need no formal review. Never present AI output as fact without checking it — AI tools state wrong things confidently.
5. Accountability & incidents
A named owner holds this policy: approvals, questions, and enforcement. If AI use goes wrong — data pasted somewhere it shouldn't be, a wrong AI-generated answer reaching a customer — the owner hears about it the same day. Fast reporting of honest mistakes is never punished; hiding them is.
This policy is reviewed quarterly.
Want it in your inbox?
I'll send the template plus a short note on the three decisions it forces (approved tools, data classes, review lines), and the governance guide when it's updated.
The policy is step one of five.
A policy without ownership, tool approval, review rhythm, and incident response is a document, not governance. The five-pillar framework covers the rest, the 90-Day AI Playbook sequences all seven steps, and the readiness assessment will show you which pillar needs attention first.
Read the Governance GuideCommon questions
- What does the AI policy template cover?
- The minimum a small or mid-sized business needs in writing: which tools are approved, what data may never be entered into them, who approves new tools, what happens when someone uses an unapproved one, and how the policy gets reviewed. It is deliberately one page.
- Why is it only one page?
- Because a policy nobody reads governs nothing. Long AI policies tend to be copied from enterprise templates, filed, and ignored. One page that staff actually read prevents more incidents than twenty pages that sit in a drive.
- Do I need a lawyer to review it?
- It is a starting point, not legal advice. If you operate in a regulated industry or handle personal data at scale, have counsel review it before adoption. Most businesses can adopt the substance and adjust the specifics.
- Is it free and can I edit it?
- Yes to both. It is on the page in full and downloadable, with no email required. It is meant to be edited — replace the tool names and approvers with your own.