An AI Policy You Can Write in One Afternoon

Photo: Shixart1985, via Wikimedia Commons · CC BY 2.0
If you run a company of fifty people, it is a safe bet that some of them already use AI tools at work. Some with a company account, some with a personal one, and some without really thinking of it as "using AI" at all. That is not a crisis. But it does mean the question is no longer whether to allow it. It is whether anyone has written down how.
Large companies produce governance frameworks with committees and risk matrices. For most SMEs that is overkill, and it tends to produce a document nobody opens. What works better is one page, in plain language, that people can actually remember.
What goes on the page
Here is the structure I suggest. Each part should fit in a sentence or two.
- Approved tools. List them by name and say which account to use. If a tool is not on the list, ask before using it for work.
- What never goes in. Personal data about customers or colleagues, unless the tool is approved for it. Prices and margins. Anything under an NDA. Customer drawings.
- You own the output. Whatever an AI tool drafts, the person who sends or uses it is responsible for it. Check it the way you would check a colleague’s work.
- Say so when it matters. If AI played a real part in something that goes to a customer, and they would reasonably want to know, tell them.
- Decisions about people stay with people. No AI-only decisions about hiring, evaluations or anything similar.
- Report problems. If a tool produced something wrong that nearly went out, or you pasted something you should not have, tell a named person. No blame, just so it can be fixed.
- Who to ask. One name, with an email address.
Write it with the people who use the tools
The quickest way to write a policy nobody follows is to write it alone. Invite two or three colleagues who use these tools every day. They know which ones are in use, where the useful shortcuts are, and which rules would be ignored within a week. An hour of that conversation beats a day of reading templates.
Keep it alive
Put a date on the page and look at it again in six months. Tools change quickly, and a policy that lists last year's products quietly loses its authority.
Why one page is enough, for now
A short policy does three things. It gives people permission to use useful tools without guessing. It draws a clear line around the data that should not leave the company. And it makes one person responsible for keeping an eye on it, which is often exactly what was missing.
It also makes a reasonable foundation for the AI literacy expectations in the EU AI Act. Pair it with a short session where you walk through the page and show a few examples of AI tools getting things wrong, note who attended, and you are in better shape than most companies your size.
It does not have to be perfect. It has to exist, and it has to be short enough that people actually read it.