A 140-person fintech firm in Pune found out its own employees were pasting customer account details into a free consumer chatbot to draft support replies. Not out of malice. It was faster. The discovery came during a routine security review, and by then it had been happening for four months across at least eleven people. There was no rule against it, because there was no rule about AI at all. The company had spent zero minutes writing one, on the theory that they would "deal with AI later."
Later arrived as an incident.
If your company does not have an AI policy yet, your employees have already written one for you through their daily habits, and you have no idea what it says. Here is how to write a real one, with a template you can adapt in an afternoon.
Why You Need an AI Policy Now, Not Eventually
The instinct to wait feels responsible. The technology is moving fast, so why commit to rules that will be outdated in six months?
Because the absence of a policy is itself a policy, and it is the worst one. "No rules" means every employee makes their own call about what customer data is safe to paste where, which tools are trustworthy, and whether the AI-generated contract clause they just copied is something legal needs to see. Some of those calls will be fine. Some will be the fintech firm's calls.
A good ai policy does not need to predict the future. It needs to establish principles that hold regardless of which tool is popular next quarter: what data can go where, what a human has to check, and who is accountable when something goes wrong. Those principles age well even when specific tools do not.
The Three Pillars Every AI Policy Needs
Strip away the legalese and every workable AI policy rests on three things: governance, acceptable use, and human review. Get these three right and the rest is detail.
Pillar 1: Governance (Who Decides and Who Owns It)
Governance answers the question "who is actually responsible for this?" Without a named owner, an AI policy is a document nobody enforces.
At minimum, your governance section should name:
- An accountable owner for the policy itself, usually someone senior enough to say no to a business unit that wants to cut a corner
- An approval path for adopting new AI tools, so nobody plugs a random plugin into your CRM on a Tuesday
- A data classification that says plainly which categories of information (public, internal, confidential, regulated) can touch AI tools and which cannot
- A review cadence, because the policy has to be revisited as the technology and your usage change (quarterly is sensible for most companies right now)
Governance is the pillar most companies skip, and it is why so many policies read well and do nothing.
Pillar 2: Acceptable Use (What People Can and Cannot Do)
This is the part employees will actually read, so make it concrete and readable. Vague principles ("use AI responsibly") give no one guidance. Specific rules do.
A strong acceptable-use section spells out:
- Approved tools: the specific AI tools the company has vetted and permits, and a clear statement that unlisted tools are not approved by default
- Prohibited data: an explicit list of what must never be entered into a general-purpose AI tool. Customer PII, financial account details, health records, source code, unreleased financials, anything under NDA
- Permitted use cases: the things people are actively encouraged to use AI for (drafting, summarizing public information, brainstorming, code assistance within approved environments)
- Disclosure rules: when AI-generated content must be labeled, both internally and to customers
- Consequences: what happens if the rules are broken, stated plainly and applied consistently
The tone matters. A policy written purely as prohibitions drives usage underground, which is exactly what happened at the fintech firm. Pair every "you must not" with a "here is the approved way to do that thing," and adoption of the safe path goes up.
Pillar 3: Human Review (Where a Person Must Sign Off)
AI produces confident, fluent, and occasionally completely wrong output. The human-review pillar defines where a person is required to check the work before it has consequences.
Tie the level of review to the level of risk:
- High-stakes, mandatory review: anything customer-facing with legal, financial, or safety implications. Contracts, medical or financial advice, public statements, pricing. A qualified human approves before it goes out, every time.
- Medium-stakes, spot-check review: internal documents, first drafts, routine communications. Review a sample, not every item.
- Low-stakes, no mandatory review: brainstorming, personal productivity, throwaway drafts that a human will heavily rewrite anyway.
The key principle: the human is accountable for the output, not the AI. "The AI wrote it" is never a defense. Write that sentence into the policy in exactly those words, because it changes how people treat the tool.
A Copy-and-Adapt AI Policy Template
Here is a skeleton you can lift directly and fill in. Keep it short. A policy nobody reads protects nobody.
1. Purpose and Scope
This policy governs the use of artificial intelligence tools by all employees, contractors, and vendors of [Company]. It applies to all AI tools, whether company-provided or third-party.
2. Governance
- Policy owner: [Name / Role]
- New-tool approval: submit requests to [owner/committee]; no AI tool may be connected to company systems without approval.
- Data classification: [Public / Internal / Confidential / Regulated] with rules for each.
- Review cadence: this policy is reviewed every [quarter].
3. Acceptable Use
- Approved tools: [list]. Tools not on this list are not approved.
- Never enter into general-purpose AI tools: customer PII, financial account data, health data, credentials, source code, unreleased financials, NDA-covered material.
- Encouraged uses: [drafting, summarizing public info, brainstorming, code assistance in approved environments].
- Disclosure: AI-generated content that is [customer-facing / published] must be labeled and reviewed.
4. Human Review
- High-stakes output requires named human approval before release.
- Medium-stakes output requires sample review.
- The employee, not the AI, is accountable for all output.
5. Consequences and Reporting
- Violations are handled under [existing conduct policy].
- Report suspected misuse or data exposure to [contact] within [timeframe].
6. Acknowledgement
- All staff sign to confirm they have read and understood this policy.
That is a working policy. It fits on two pages, and two pages that people read beats twenty that they do not.
Rolling It Out Without It Gathering Dust
Writing the policy is 30% of the work. The other 70% is making it live.
- Involve the people who use AI most before you finalize it. They know the real workflows and will tell you which rules are unworkable, which prevents the underground-usage problem.
- Train, do not just circulate. A 30-minute session with real examples ("here is what you can paste, here is what you cannot") beats an all-staff email that gets archived unread.
- Give people the approved path. If you ban a consumer tool, provide a sanctioned alternative the same day. Otherwise people revert to the fast, unsafe habit.
- Review on the calendar, not on incident. Put the quarterly review in the calendar now. Policies that only get revisited after something breaks are always one step behind.
Most companies do not have the internal experience to know which rules are load-bearing and which are theater, especially in regulated industries. A focused AI consulting engagement can compress this from a multi-month internal debate into a couple of weeks, and more importantly can pressure-test the policy against the actual regulatory obligations in your sector.
The fintech firm in Pune now has a two-page policy, a single approved AI assistant that never sees customer PII, and a mandatory-review rule for anything client-facing. It took them nine days to write and roll out. The incident that prompted it cost them a great deal more than nine days.
Frequently Asked Questions
What should an AI policy include at a minimum?
Three things: governance (who owns the policy and approves new tools), acceptable use (which tools are allowed and what data can never be entered into them), and human review (where a person must sign off before AI output has consequences). If your policy covers those three pillars clearly, it is doing its core job. Everything else is refinement.
How long should a company AI policy be?
Short enough that employees actually read it, which usually means one to three pages. A concise, specific policy that staff understand and follow protects you far more than a comprehensive twenty-page document that sits unread in a shared drive. Save the exhaustive detail for internal governance documents, not the staff-facing policy.
Can we just ban AI tools instead of writing a policy?
You can try, but bans without approved alternatives drive usage underground, which is more dangerous than governed usage because you lose all visibility. Employees will use AI because it makes them faster; a policy channels that toward safe tools and safe data rather than pretending it is not happening. Provide a sanctioned path alongside any prohibition.
Who should own the AI policy in our company?
Someone senior enough to say no to a business unit that wants to cut a corner, typically in legal, security, or operations, with input from IT and the teams that use AI most. The critical point is that a single named person is accountable, because a policy owned by "everyone" is enforced by no one.
How often should we update our AI policy?
Quarterly is sensible for most companies given how fast the tools change, plus an immediate review after any incident or major new tool adoption. Put the review date in the calendar rather than waiting for something to break, because a policy that only gets revisited reactively is always a step behind how your people are actually using AI.