AI for Business How-to Intermediate Updated

Write an AI usage policy your team will actually follow

Short, specific and permissive by default — because the alternative is a policy people route around.

2 min read 23 min to complete 4 steps Last updated 27 Jul 2026

Before you start

  • Knowing which tools your team already uses
  • Someone who can approve exceptions

What you will be able to do

  • Write a policy that fits on one page
  • Draw the data line where it is actually enforceable
  • Give people a route to ask instead of a reason to hide

Most AI policies are written defensively, run to several pages, and are read once during onboarding.

The result is predictable: people use the tools anyway, on personal accounts, without asking. A shorter policy that says yes to most things gets followed and gives you visibility.

Find out what is already being used

6 min

Ask without consequences first. The answer shapes everything else.

Before writing anything, ask the team what they use, anonymously if that helps. You will find more tools than you expected, several of them on personal accounts.

That is the actual situation your policy has to address. Writing rules for the situation you assumed produces a document that is wrong on its first day.

Three lists, and make the green one long

8 min

Always fine · ask first · never. Most work belongs in the first list.

Structure the whole policy as three lists of concrete activities. Always fine: drafting internal text, summarising public material, code you will review. Ask first: anything customer-facing, anything with personal data, anything contractual. Never: credentials, unreleased financials, anything covered by an NDA.

If the green list is short, people will conclude the policy is anti-AI and stop consulting it. It should cover the majority of daily work.

Tips
  • Write the lists as activities people recognise from their own week, not as categories of data. "Pasting a customer email" lands; "PII" does not.

Name the tools and the accounts

5 min

A policy that says "approved tools" without naming them is not a policy.

List the specific tools people may use, and say which account — the company workspace rather than a personal login. This one line does most of the real data-protection work in the document, because business tiers generally do not train on your inputs and consumer tiers may.

Keep the list somewhere editable and say who updates it, or it will be stale within a quarter and quietly ignored.

Say who to ask, by name

4 min

The unlisted case is the whole point of having a policy.

End with a person and a channel: "not sure? ask in #ai-help". Every policy has gaps, and the difference between a good one and a bad one is whether someone hitting a gap asks or guesses.

Commit to answering quickly. A route that takes three days to produce an answer is a route people stop using after the second time.

Watch out for
  • Routing every question to legal. It is correct, it is slow, and it converts a question into a decision to proceed without asking.

One page, three lists, named tools, and a person to ask. If it does not fit on a page, it will not be followed.

Common questions

Ban them for work data and provide a company account so there is a legitimate path. A ban without a provided alternative is the exact condition that produces shadow usage.

Was this guide useful?

90% of readers found this useful

S

Sabir Verified

Founder & AI Enthusiast · AIToolsay

Founder of AIToolsay and a passionate AI enthusiast dedicated to building practical, user-friendly AI tools that simplify everyday tasks.

Read next