Writing an AI Policy: 7 Simple Steps to Tackle the Biggest Risk
Your staff are already using AI, even without any rules. Here is how to write a short, clear AI policy for your team in seven steps.

Want to write an AI policy, but not sure where to start? One colleague pastes a client email into ChatGPT, another uploads a quote to a free tool, and nobody knows what is allowed. A short set of rules fixes that in an afternoon.
Why do you need to write an AI policy?
Because your staff are already using AI, with or without your permission. Without agreed rules, nobody knows where the line is, and that leads to mistakes and data breaches.
The Autoriteit Persoonsgegevens (AP, the Dutch privacy regulator) reported dozens of data breaches caused by employees uploading personal data to AI chatbots. A data breach is any moment when personal data ends up with the wrong party.
There is something else to consider. Since 2 February 2025, the European AI Act requires organisations that use AI to work on AI literacy. That means staff need enough knowledge to use AI responsibly. A clear policy helps with that. This is not legal advice; if in doubt, check with a specialist.
There is a positive reason too. With clear rules, people actually dare to use AI. They know what is safe, and your team saves time on writing, summaries and preparation, without you having to worry about unnecessary risks.
What goes into a good AI policy?
A good AI policy is short and answers four questions: which tools, which data, which tasks and who is responsible. The shorter it is, the more likely people are to read it.
- Approved tools: name what people may use, for example the business version of Copilot or ChatGPT.
- Forbidden data: client names, medical data, passwords, contracts and anything confidential.
- Duty to check: you check every text, calculation or source from AI yourself before you share it.
- Openness: you tell your manager or client when AI did a significant part of the work.
- Point of contact: one person who answers questions and assesses new tools.
Keep the language simple. Write sentences like: you never paste a client’s name into a free chatbot. Avoid legal jargon, because you want an intern to understand it the first time.
How do you write an AI policy in 7 steps?
You can write your AI policy in seven steps, without a lawyer or an IT department. Allow a few hours for the first version.
- Find out what is already happening. Ask your team, anonymously, which AI tools they use and what for. You will often find surprises.
- Choose the approved tools. Two good business tools are better than ten free ones you have no view of.
- Make a red list. Write down which data must never go into a chatbot. See also our 7 rules for using AI safely.
- Make a green list. Name tasks where AI is perfectly fine, such as writing a draft, summarising or brainstorming.
- Set down the checks. A person reads everything that goes outside the company.
- Give training. An hour of explanation with real examples works better than a PDF.
- Plan a review. Put a date in the diary, for example six months from now.
Are you still at the start of using AI at work yourself? Then first read how to start using AI safely and smartly at work.
A practical example for step one: send a short anonymous survey with three questions. Which AI tool do you use? What for? What data do you put into it? Within a day you get an honest picture, and you can base your red list directly on what really happens.
What is the difference between a red and a green list for AI?
The green list says what is allowed and the red list says what never is. Together they form the core of any AI policy, because in busy moments people want to know quickly where they stand.
| Situation | Green or red? | Why |
|---|---|---|
| Having a general newsletter written | Green | No sensitive data needed |
| Summarising a team meeting | It depends | Only with an approved tool and without sensitive content |
| Uploading a client file | Red | Personal data does not belong in a free chatbot |
| Improving your own work prompt | Green | You are not sharing trade secrets |
| Having a staff appraisal written | Red | Sensitive and potentially high-risk under the AI Act |
We have already written a separate guide on meetings: summarising a meeting with AI. Look at the privacy tips there before you label anything green.
Does a situation not appear in the table? Then give your team a simple rule of thumb: would you dare to write this on a postcard? If not, it does not belong in a free chatbot. Add that rule at the end of your policy as a safety net for everything you did not foresee.
What is a smart tip for writing an AI policy that hardly anyone follows?
When writing an AI policy, add an example of a real situation from your own company to every rule. A rule like protect client data is vague, but an example with a client email and a free chatbot sticks in the mind.
A second tip: build a small folder of good prompts (the instructions you give to AI). That way everyone uses the same safe approach. You could start with our 25 handy prompts for your work and remove anything that asks for personal data.
A third tip: reward reporting. If someone says they pasted something by accident, you can act quickly. A data breach involving personal data may have to be reported to the AP (or your local privacy regulator), so speed matters.
What mistakes do people often make when writing an AI policy?
The biggest mistakes when writing an AI policy are: making it too long, banning everything and never updating it afterwards. All three lead to the policy disappearing into a drawer.
- A twenty-page policy. Nobody reads that. Keep it to one or two pages.
- Banning everything. People will then use AI on the sly on their phones, and you have less oversight than before.
- No owner. Without a point of contact, questions go unanswered.
- Forgetting to update it. AI tools change fast. Terms and features can be different after an update.
- No attention to errors. AI can talk confident nonsense. Without checks, that ends up with your clients.
Costs count too. Business subscriptions cost money per user; check the provider for current prices and work out whether it fits your budget.
Who is responsible when you write an AI policy?
One person is ultimately responsible, but everyone is responsible for their own use. Put that in your policy in so many words, so that nobody can say later that it was someone else’s job.
In a small business that is often the owner or office manager. In a larger organisation it could be someone from IT, privacy or HR. More important than the job title is that people know who they can call. So give a name and an email address.
Also set down what the point of contact does. For example: assess new tools before they are used, answer questions, collect reports of mistakes and have the policy reviewed every six months. That is not much work, but it stops decisions from being left hanging.
Does your team also use AI for decisions about people, such as job applicants or appraisals? Then be extra careful. Such uses can fall under the stricter rules of the AI Act. Have a specialist check this, and use AI here at most as an aid, never as the sole decision-maker.
How do you make your AI policy a success in your team?
Your team will only follow your rules if they understand them and find them useful. So involve people from the start when you write your AI policy.
Ask colleagues which tasks they would like AI to handle. That builds support and also uncovers risks you cannot see yourself. Someone in customer service sees different dangers from someone in administration.
Discuss the policy briefly in a team meeting and repeat the most important rules after a month. Also share an example of something that went well, so that AI does not only feel like a danger.
An example: writing an AI policy for a small team
Say you are the office manager at an accountancy firm with eight employees. You choose one business AI tool, ban the uploading of client files and agree that a person reads every client email.
You put the rules on one page and discuss them in a half-hour team meeting. Everyone names a task where AI helps. That way it is not a ban, but a tool with clear limits.
After three months you ask the team what works and what does not. Perhaps it turns out that an employee is using a handy tool that is not on the list yet. Together with the point of contact you assess it and add it, or explain why not. That keeps the policy alive.
Self-employed or running your own business? Then writing an AI policy works mainly as a cheat sheet for yourself and any freelancers you hire. You will find more advice on getting started in 5 first steps with AI for freelancers and small businesses.
Note: the result is a draft. Have it read by someone who knows about privacy, and adapt it to your situation.
Frequently asked questions
Is my company legally required to write an AI policy?
A separate AI policy document is not required as such. However, since 2 February 2025 the AI Act requires organisations to ensure sufficient AI literacy. A policy is a practical way to do that.
How long should an AI policy be?
One to two pages is enough for most teams. A short policy gets read and used; a long one does not.
Can employees use free AI tools?
That is for you to decide in your policy. Bear in mind that free versions can have different terms from business versions. Read the provider’s terms and never enter personal data without proper agreements.
How often should you update an AI policy?
Plan a short review at least once every six months. Also update it when you introduce a new tool or when the rules change.
Your next step in writing an AI policy: go through the step-by-step plan and write your red list today. Want to make it understandable for your team too? Then read AI literacy for business owners.
Was this article helpful?




