Most AI policies are three pages of principles that nobody could act on. Four straight answers are worth more than all of it, and you can write them in an afternoon.
If your business is regulated, you have probably been told you need an AI policy. What you have probably been shown is a template full of words like responsible, transparent and human-centred — all of which are true, none of which tell anybody what to do on a Tuesday.
A policy earns its place if somebody can read it and know whether what they are about to do is allowed. That is the whole test. Four questions get you there.
Not what AI can do in general. What it is used for in this business, named specifically. Drafting first versions of these documents. Pulling dates and figures out of these files. Summarising this kind of correspondence.
Being specific does two things. It tells anybody reading it what is normal, so they are not guessing. And it means anything not on the list is a conversation before it happens rather than a discovery afterwards.
This is the more important half and it is the one templates skip, because it takes an actual decision rather than a paragraph.
Write down the things AI does not touch here. Final advice. Anything that goes out without being read. Anything involving money moving. Whatever the equivalent is in your sector. If somebody asks “could we just use it for this?”, the answer should already be on the page.
A policy that only says what you may do leaves every hard question open. The list of what you do not do is the part that protects people.
For every use on your first list, there should be an identified point where a named role checks and approves, before the thing counts as anything. Not “output should be reviewed” — reviewed by whom, at what point, and before what.
This is the question a regulator is most likely to actually ask, and it is the one businesses most often cannot answer, because in practice the checking is happening informally and nobody has written down where.
Which tools are approved, what may be put into them, and what may not. Whether what you put in can be used to train somebody’s model. Whether there is an agreement behind the tool or whether somebody signed up with a work email one afternoon.
That last one is worth an honest look before you write anything. The gap between the policy and what is actually happening is usually here, and it is nearly always innocent — somebody trying to get their work done faster with the tool that was easiest to reach.
The awkward version of this conversation is the one that happens after somebody has asked. The comfortable version is having a page you can hand over that says exactly what you do, what you do not, who checks, and where the information goes.
It is genuinely an afternoon’s work if you know the answers, and the four questions above are how you find out whether you do.
This sits inside the wider approach set out under doing it safely, alongside the one rule worth having before any others and what actually determines whether client information is safe to put into AI.
This is general information written to be useful, not legal or compliance advice, and your own regulator’s requirements come first. We write a policy along these lines as part of every audit, rather than selling it back afterwards.
Twenty minutes on the phone, free, no obligation. Talk us through how AI is being used in the business today and we will tell you which of the four you can already answer — and which need a decision.