Policy

The one-page AI policy: a template your staff will actually read

Most AI policies are either a 20-page legal document nobody opens or a single line saying 'use responsibly'. Neither changes behaviour. Here is a one-page structure that does, with wording you can adapt.

· 4 min read

Ask a room of employees what their organisation’s AI policy says, and you will usually get one of three answers: “I don’t think we have one”, “something about not using ChatGPT”, or a shrug.

That is a problem in two directions. Staff who are unsure what is allowed tend to avoid AI, so the organisation gets none of the benefit. Others use it anyway, without guidance, so the organisation carries all of the risk. A good policy fixes both. It should make people more confident to use AI, not less.

What a useful AI policy does

A policy that changes behaviour does four things:

  1. Tells people which tools they can use. Named tools, not categories.
  2. Draws a clear line around data. What can go in, what must never go in.
  3. Sets the standard for outputs. Who is responsible for checking, and when AI use must be disclosed.
  4. Says who to ask. A named person or channel, not “the relevant department”.

Everything else (principles, ethics statements, regulatory references) belongs in a longer governance document that sits behind the one-pager, for the people who need it.

The template

Adapt the wording below. Square brackets are yours to fill in.


Using AI at [Organisation]

Why we use AI. We want everyone to use AI tools to save time on routine work and do better work on everything else. This page explains how to do that safely. If something is not covered here, ask [name or channel].

Approved tools. You can use [tool names, e.g. Microsoft Copilot through your work account, ChatGPT Enterprise]. These are configured so our data is not used to train public models. Do not use personal accounts or other AI tools for work without approval from [name].

What you can put in.

  • Your own drafts, notes and internal documents classified as [internal / general].
  • Publicly available information.
  • Client or personal data only in [approved tool], and only when [condition, e.g. the task needs it and the client contract allows it].

What you must never put in.

  • Passwords, access keys or security information.
  • [Special category personal data: health, ethnicity, etc.] unless an approved process says otherwise.
  • Information marked [confidential / restricted], or anything covered by a client confidentiality clause that does not permit it.

Checking outputs. AI tools make confident mistakes. You are responsible for anything you send, publish or decide, whether or not AI helped. Check facts, figures, names and references against a source before using them.

Decisions about people. Do not use AI to make or recommend decisions about hiring, performance, pay or discipline without approval from [HR lead]. AI may help draft documents in these processes; a person makes the decision.

Telling people. Tell clients and colleagues when AI has generated substantial parts of a deliverable, if [rule, e.g. the client has asked, or the content is presented as expert opinion].

Getting better. Training is available at [link]. Share prompts that work in [channel]. If you find a task where AI saves real time, tell [name]; we want to hear about it.

Questions or mistakes. If you are unsure, ask [name or channel] before you act. If you think data went somewhere it should not, report it to [contact] the same day. Honest reporting will not be treated as misconduct.

Owner: [name]. Last reviewed: [date]. Next review: [date].


Three choices you need to make first

The template is the easy part. The real work is agreeing three decisions with leadership before anyone writes a word.

1. Which tools, on which terms?

The single biggest risk lever is whether staff use enterprise accounts (where the vendor contractually does not train on your data) or consumer accounts. If budget does not allow enterprise licences for everyone, say which tasks are allowed on free tools and which are not.

2. Where exactly is the data line?

“No confidential data” is meaningless if staff do not know what counts as confidential. Tie the policy to your existing data classification. If you do not have one, three levels (public, internal, restricted) is enough to start. For Luxembourg firms, particularly in financial services, check professional secrecy obligations carefully: they may be stricter than GDPR alone.

3. Who owns this?

A policy without an owner goes stale within months, and AI tools change faster than most policy cycles. Name a person, give them the authority to approve new tools, and schedule a review every six months.

How to launch it

Do not just email it out. A policy lands best when:

  • Leaders go first. A short note from the managing director or CEO explaining why you want people using AI sets the tone.
  • It comes with training. The policy answers “am I allowed?”; training answers “how do I do this well?”. Launch them together.
  • People can ask questions. A 30-minute open session in the first week clears up most of the confusion.

Policy and regulation

A short, clear AI policy also does a lot of the groundwork for regulation. In the EU, Article 4 of the AI Act expects organisations using AI to take measures supporting their staff’s AI literacy, and a policy plus training is the most natural evidence of that. In the UK, regulators such as the ICO expect organisations to be able to show how they manage the risks of the AI tools they use. In both cases, a one-page policy people actually follow beats a long one nobody reads.

This template is a starting point, not legal advice. Have your legal or compliance lead review the final version, especially in regulated sectors.