An AI policy is a short written document that tells your team which AI tools are approved, what data they can and can't paste into a prompt, and who has to review AI-assisted work before it goes out. Most companies still don't have one written down, which is why employees end up using whatever tool they found first, with no rules at all.
Short answer: A working AI policy lists your approved tools, states what data can never enter a prompt (customer PII, unreleased financials, source code under NDA), sets a disclosure rule for AI-assisted work, and names who signs off before high-risk output ships. Draft it in an afternoon using a plain-language template, not a 20-page legal document nobody reads.

I've helped draft this exact structure for three small teams over the past year — a 12-person marketing agency, a 40-person software shop, and a solo consultant who just wanted something to hand new contractors. In my testing, the version that actually got read and followed was always the shortest one: two pages, plain language, a table instead of paragraphs. Here's the process that produced it, the prompts I used to draft it fast, and the mistakes that make a policy get ignored.
What you'll need
You don't need a lawyer to start, though one should review the final draft if your company handles regulated data (health records, financial accounts, anything under NDA). Before you write anything, gather three things: a list of every AI tool your team is already using, even the free ones nobody asked permission for; a rough sense of what data counts as sensitive at your company (customer records, contracts, unreleased pricing); and either a template or a general-purpose AI tool like ChatGPT or Claude to help you draft the language. If you have an IT or legal contact, loop them in at the review stage, not the drafting stage — a policy written by committee from page one usually takes months and still reads like a committee wrote it.
Step-by-step: how to write an AI policy
1. Audit what your team is already using
Ask around, don't guess. In most companies, employees are already using ChatGPT, Gemini, or a writing tool like Jasper for parts of their job whether or not it's sanctioned — this is often called "shadow AI." You can't write a useful policy without knowing what's actually happening; a policy that only names the tool IT bought and ignores the four tools marketing already uses will be ignored the same way.
2. Set your data rules before anything else
Decide what can never go into a prompt: customer personal data, health or financial records, unreleased financials, source code covered by an NDA, anything a client contract restricts. This is the one section a lawyer should actually look at if you're in a regulated industry — everything else in the policy can be adjusted later without much risk.
3. Decide on disclosure and human review
Set a simple rule: does AI-assisted work need to be labeled as such, and does someone have to check it before it goes external? A reasonable default is no review needed for internal drafts and brainstorming, but a named reviewer for anything customer-facing, financial, or legal.
4. Draft the document with an AI tool
This is the fastest part. Paste your notes from steps 1–3 into ChatGPT or Claude and ask it to structure them into a short policy (prompts below). In my testing, this cut drafting time from a couple of hours to about twenty minutes, and the output needed light editing, not a rewrite.
5. Get one round of sign-off
Send the draft to whoever owns risk at your company — a manager, a co-founder, outside counsel if you have one — for a single round of edits. Looping in more than one reviewer at a time is how a two-page policy turns into a six-week email thread.
6. Publish it somewhere people actually look, and set a review date
Put it in the employee handbook or wherever onboarding docs already live, not a buried wiki page. Set a review date six to twelve months out; AI tools and their data-handling terms change often enough that a policy written in 2025 can already be out of date.
Example prompts you can copy
Paste these into ChatGPT, Claude, or Gemini along with your own notes from the audit and data-rules steps:
- "I run a [size] [industry] company. Employees currently use [list of tools]. Draft a one-page AI usage policy covering: approved tools, data that can't be entered into prompts, a disclosure rule for AI-assisted work, and who reviews high-risk output. Plain language, no legal jargon."
- "Rewrite this AI policy draft so a new employee could read it in two minutes and know exactly what they're allowed to do: [paste draft]."
- "Given this list of tasks my team does — [list], sort them into low, medium, and high risk for AI use, and tell me which ones need human review before anything ships."
- "Turn this AI policy into a short onboarding checklist with a place for a new hire's signature."
These work because each one gives the model a real constraint — length, audience, or a specific output shape — instead of just asking for "an AI policy," which tends to produce generic filler.
Common mistakes to avoid
The biggest one I keep seeing: banning AI outright instead of setting rules for it. It doesn't work — people use it anyway, just without telling anyone, which is worse than having no policy at all. Second, writing a data-rules section so vague ("use good judgment") that it gives employees nothing to actually check against; name the specific categories that are off-limits. Third, treating the policy as an IT document instead of an everyone document — if marketing, sales, and support never see it, it only governs the one team that helped write it. Fourth, skipping the review date entirely; a policy that doesn't get revisited quietly goes stale as tools change their data-training defaults. And fifth, making it long. Nobody reads a 15-page AI governance document; a two-page policy that gets read beats a thorough one that doesn't.
Tools that make this easier
You don't need special software to write the policy itself — a general chat assistant does the drafting, as covered in how to use ChatGPT at work and how to use Claude AI, both of which walk through the account setup if you're starting from zero. The harder part is usually agreeing on which tools are approved in the first place; my best AI tool for small business roundup and the AI tool reviews methodology page cover how to evaluate a tool before you put it on the approved list, including what to check in a vendor's data-use terms. If your team's shadow-AI problem is mostly writing tools, my hands-on Jasper review and the ranked best AI writing tools guide are useful references for what "approved" might actually look like, since blessing one clear option tends to reduce shadow use of five unapproved ones.
AI use case risk tiers
Sorting tasks into risk tiers makes the review-and-disclosure section much easier to write, since you can point to a row instead of describing every scenario from scratch.
| Risk tier | Example tasks | Data allowed in prompts | Review before use |
|---|---|---|---|
| Low | Brainstorming, meeting notes, internal memos | Public or already-internal info | Spot-check only, no sign-off |
| Medium | Marketing copy, code snippets, first-draft emails | No customer PII, no unreleased financials | Manager review before it goes external |
| High | Contracts, HR decisions, financial or medical advice | No regulated data (health, payment, PII) without legal sign-off | Named reviewer required, human makes the final call |
Why this matters now
AI adoption inside companies has outrun the paperwork. According to ISACA’s 2026 AI Pulse Poll of more than 3,400 digital trust professionals, 90% say employees are using AI at work, but only 38% of organizations have a formal, comprehensive AI policy — up from 28% in 2025, so the gap is closing, just slowly. If you want a more formal structure to build from once the basic policy is working, NIST's AI Risk Management Framework is the closest thing to a public standard for how organizations should categorize and manage AI risk, though it's written for larger organizations layering on governance, not a first draft.
My take
Start with the two-page version, not the comprehensive one. In my testing, every team that tried to write a complete AI governance document on the first pass either never finished it or produced something nobody read. The short version — approved tools, data rules, a disclosure line, a named reviewer for high-risk work — covers the actual risk in most small and mid-size companies, and you can always add sections later once you know which ones people are actually asking about.
Frequently Asked Questions
Is writing an AI policy free?
Yes. You don't need to buy software — a general AI assistant like ChatGPT or Claude can help you structure one from your own notes in about twenty minutes, and legal review (if your data is regulated) is the only cost most small companies need to budget for.
How long does it take to write an AI policy?
A first draft takes about an hour if you've already done the tool audit; the audit itself — figuring out what your team is actually using — usually takes longer than the writing.
What is the easiest way to write an AI policy?
List every AI tool your team already uses, decide what data can't go into a prompt, then paste both lists into ChatGPT or Claude and ask it to structure a one-page policy from them. Edit, don't start from a blank page.
Do I need a lawyer to write an AI policy?
Not for a first draft. You should get legal review before publishing if your company handles health records, payment data, or anything under an NDA — for most other companies, one round of review from whoever owns risk is enough.
Should a small business have a different AI policy than a large company?
The structure is the same, but a small business needs less of it. A five-person team doesn't need a dedicated AI governance committee; it needs the same four sections — approved tools, data rules, disclosure, review — written in plain language and actually read by everyone.