AI POLICY TEMPLATE

Build an AI policy starting draft

Answer eight questions and you'll leave with a draft policy that marks every decision still waiting on you.

The result is a starting draft for internal review. It is not legal advice and does not establish compliance with any law or standard.

Your staff need one place to check what's allowed

An AI use policy is where you write down which tools people may use and who signs off a new one, and what has to happen before anything an AI helped write goes to a customer. Staff get somewhere to look instead of asking, and you get a record of what was actually agreed.

The draft leaves the decisions only you can make marked in the text, so you can see what still needs settling before you issue it.

The draft comes with eleven sections

Three of them link out to the guide behind the duty they cover.

  1. Purpose and scope
  2. What is covered
  3. Roles and responsibilities
  4. Approved tools and new-tool approval
  5. How AI may and may not be used
  6. Human review before anything goes out
  7. Personal data and confidentiality
  8. Transparency to people affected
  9. Training and awareness
  10. Reporting a problem
  11. Review date and owner

Some of the policy only you can write

The draft won't invent an owner or an approver

It leaves the review date open too. You'll still need to name your approved tools and the uses that are off limits, and add the route staff use to report a problem.

Read it against what you've actually decided

Before you approve it or issue it to staff, have the policy owner and whoever is responsible for the systems and functions in scope check every statement against the decisions your organisation has really made, and settle each marked placeholder.

Read the duty before settling the wording

Each guide sets out what one duty asks of an organisation. The draft doesn't reach a legal conclusion for you, so the wording stays yours to settle.