Your people are already using AI. Free tools sit one browser tab away, and nobody needs a purchase order to open one. An AI use policy doesn’t decide whether AI enters your business, because it already has. It decides what people do with it, and it has to be readable in about a minute.

Why an AI use policy exists at all

The document has one job: to answer the questions somebody has while their hand is on the keyboard.

That timing shapes everything about it. A person about to paste a supplier contract into a chatbot won’t open a 12-page document first. They will make a decision in a few seconds. Your policy either reaches them in that moment, or it plays no part at all.

So write it as an answer sheet rather than a rulebook. Four questions matter, and a good policy answers each one plainly.

The four questions to answer

Every line you write should serve one of these four questions, and anything that serves none of them can go.

Am I allowed to use AI for this? What can I put into it? Who checks the result before it counts as finished work? Who do I ask when the answer isn’t obvious?

People ask those four questions in roughly that order, so run the policy in the same order. Then resist the urge to open with background, because background is the part nobody reads.

Name the jobs you approve

Start with the first question, because a clear yes is more useful than a long list of noes.

Name approved jobs as tasks, not as categories. Drafting a first reply to an inbound enquiry. Summarising a long supplier document. Tidying up meeting notes. Writing a first version of a job advert. Each of those names something a person recognises in their own working day.

An approved list also settles arguments quickly, because people can point at it. Then name what needs a conversation first. Anything that goes to a customer without a person reading it. Anything involving an individual’s pay, performance or health. Anything that sets a final price or accepts a contract term. Naming them doesn’t forbid them forever. People simply need to know which side of the line their job sits on today.

The information rule

The second question, about what people can put in, tends to cause more anxiety than the rest of the policy put together.

One line handles most of it. Nothing that identifies a person, nothing a customer contract calls confidential, and nothing you would hesitate to email outside the business. Most people can apply that test in seconds, which is exactly why it works.

Add one route for the exceptions. When somebody isn’t sure, they ask before they paste, and nobody gets criticised for asking. Personal data deserves its own sentence, since the rules there come from law rather than from you. The ICO guidance on artificial intelligence explains what your duties look like in practice. Read it before you finalise this section. If you want the plain version of what happens to a document once somebody pastes it in, the security question covers it.

Write the review step as a comparison

Once people know what they can use and what they can put in, they need to know when the output becomes work.

Vague wording fails here. A policy that only tells someone to review the output gives them nothing to look at. So they skim it and move on. Write the step as a comparison instead.

Name what the reviewer holds side by side. The figures in the draft against the figures in the source document. The customer’s name in the letter against the name on the record. The dates against the diary. A comparison a person can complete in seconds happens every time. A general instruction to check carefully quietly stops happening.

One person to ask

The fourth question needs a name, and this is the part that is easiest to leave vague.

Put one person in the document, by name and role, and say what they will do. They answer within a working day. They decide the cases the policy doesn’t cover. They keep a note of every question they receive, because repeated questions show you exactly where your wording is unclear.

A shared mailbox is not a substitute, since it belongs to nobody in particular. If you have not yet settled who holds this kind of responsibility, who owns the AI job sets out what the role involves.

What should you leave out?

Those four answers are the whole document, so treat everything else as a candidate for cutting. Every extra page costs you readers.

Leave out how the technology works. A list of banned product names can go too, since new products appear faster than you will update the list. Long quotations from legislation belong somewhere else. Discipline makes a poor opening message, because people follow guidance more readily than threats.

Nothing in the document should ask the reader to make a legal judgement alone. If a decision needs legal input, point them towards the named person instead.

Where it lives and how it stays current

Once it is down to a page, the next question is where that page lives, because a document nobody opens changes nothing.

Put it where people already look. That usually means the staff handbook, the intranet page they use for expenses, or a pinned message in the team channel. Add it to induction. One page, one place, one version, with the date and version number at the top.

Then give it a review date every 6 months, and treat any new tool as a reason to look at it early. The named person brings the question log to that review. Questions that came up more than once become new lines in the policy, and lines nobody has needed for a year come out. Your AI use policy stays accurate through small regular edits rather than a rewrite every other year.

The test of a good policy

That upkeep keeps the page current. One test tells you whether it is usable: can somebody who has never read it find their answer in under a minute?

Hand it to a colleague who wasn’t involved in writing it. Ask them what they can put into a chatbot, then watch how long they take. Their answer tells you more about your AI use policy than any amount of redrafting will. Once people can follow it without asking, turn your attention to making AI part of everyday work. That is where the value shows up.