Scope
Which teams, tools and kinds of work the policy applies to.
Staff check it when they need to know what's allowed, and it's your record of what you agreed. The generator turns six answers into a first draft you can edit, and eight more make it specific to you.
An AI policy exists so the same question does not get answered five different ways across the business. It writes down which tools are approved and what has to happen before AI-assisted work reaches a customer, so a decision made once actually holds.
Without one, people make their own calls tool by tool and nobody can see the pattern. An AI policy template gets the common sections down quickly, so the only work left is the decisions that belong to your organisation. If you are not yet sure one is worth writing, do we actually need an AI policy? sets out the test that settles it.
Most people arrive here holding something: a supplier questionnaire with a new section on AI, an insurance renewal that has started to ask, a tender that wants the policy attached, or a board minute asking whether one exists. It is the same document in every case, and the AI policy template is the quickest way to have one that describes you rather than a generic firm.
A workable policy covers the same handful of areas. The detail is yours; the headings are common across organisations.
Which teams, tools and kinds of work the policy applies to.
What staff may use, and who signs off a new one.
How AI may and may not be used in your work.
What has to be checked before AI-assisted work goes out.
What can and cannot be put into a tool.
Who maintains the policy and when it is revisited.
An AI policy needs a named owner, usually whoever already owns risk or security, with sign-off from leadership. Someone has to be answerable for keeping it current and for the calls it forces.
A template can only get you so far. It can't know which tools you actually trust your team with, or where the line sits for the kind of work you do, or how someone should flag it when a tool gets something wrong. Those are the owner's to settle, and settling them is what turns a generic template into a policy that fits you.
Give it a review date, and revisit it whenever your tools or your obligations move. A policy written once and left alone stops matching what people are actually doing within months.
Shadow AI is the usual cause: staff adopt a new tool without telling anyone, and the policy no longer describes reality. Keeping the approved-tools list and the approval route live is most of the maintenance.
The guides on the AI literacy requirement and transparency requirements set out two of the duties a policy commonly has to reflect.
The ones that work are short enough that people actually read them, and specific enough that nobody has to guess: they name the tools you have approved, and who signs off a new one.
What it needs to cover shifts with your sector. A clinic handling patient data, a firm giving regulated advice and a school teaching minors each carry obligations a generic template cannot know, so yours has to reflect the ones that apply to you.
The generator asks about your AI activity and the parts of the business that use AI, and marks the decisions it cannot make for you, which you settle before the policy is issued.
The generator needs six answers to draft a policy and offers eight more that make it specific, then assembles a Word document you can edit and circulate, with every decision still yours marked in the text. It's a starting point for internal review, not a finished policy.
Want the bare headings instead? Download the AI policy skeleton as a Word document.