What to put in writing.
WHAT TO COVER
Which tools are approved What may be sent to them What must never be sent When output must be reviewed, and by whom Who is accountable for AI-assisted work Whether AI use must be disclosed, and where
WHAT TO PROHIBIT
Customer personal data, unless specifically permitted Confidential business information Credentials Anything covered by a confidentiality obligation
WHAT TO REQUIRE
Verification of factual claims Human review of anything customer-facing Disclosure where a client or regulation requires it
KEEP IT SHORT
One page. A long policy is not read, and an unread policy prevents nothing.
WHY BANNING IT FAILS
Staff use it anyway, on personal accounts, with no oversight and no record.
A permissive policy with clear limits produces better control than a prohibition.
REVIEWING IT
Annually, and when tools change.
FOR REGULATED SECTORS
Check what your regulator says before writing your own.
FOR SPECIFICS
Take proper advice where obligations are significant.