If you only ever write down one thing about AI, write down which tools work is allowed to go into, and which it is not. It takes an afternoon, it fits on one side of paper, and it covers more real risk than a long policy nobody reads. Here is how to word it and how to make it stick.
Most AI policies fail in the same quiet way. They are written carefully, circulated once, read properly by some of the people they apply to, and then never thought about again. Not because anyone is careless. Because a long document about a fast-moving subject is hard to remember at the moment you actually need it — which is usually a Tuesday afternoon with something due.
So start with one rule instead. A single sentence, naming the tools that are approved, and saying plainly that work does not go into anything else.
Three reasons, and they all come down to the same thing: a rule only counts if it is in someone’s head when they need it.
It is easy to remember. Anyone can hold a list of two or three named tools in their mind. Nobody can hold ten pages of principles.
It is easy to follow. There is no judgement call. You do not have to decide whether this particular document counts as sensitive, or whether this particular use is high risk. You look at the tool. It is on the list or it is not.
And it is easy to check. You can ask anyone, at any point, which tools they are using, and you will get a straight answer in a few seconds. Try that with a policy built on principles and you get a shrug, quite reasonably.
Here is the thing the one rule is aimed at, said plainly.
Someone has a job to finish. There is a tool on their phone that will do the next part of it in ten seconds, and it is free, and it is already logged in. The approved route involves a different login they cannot remember, on a laptop that is upstairs. So they use the phone. The job gets done well and on time, and nobody thinks about it again.
That is not a discipline problem. That is somebody trying hard to do their work, taking the route that was available to them. It is the same instinct that makes people good at their jobs in every other respect, and treating it as misbehaviour gets you nowhere — you just push it out of sight, which is worse, because then you genuinely do not know what is being used.
What it actually is, is a signal. If people are reaching for something that is not on the list, the list has a gap in it, or the approved option is too far away.
That last point is the one that makes the difference between a rule that holds and a rule that quietly stops being true. A closed list with no route to add anything is a list people will start working around within a month, and they will be right to.
A rule that asks people to take the slower path will lose, every time, to the tool that is already open. So the work is not in writing the rule. It is in making sure the approved option is genuinely the quickest thing to hand.
In practice that means it is paid for and set up properly, everyone who needs it is already logged in, it works on a phone as well as a desk, and nobody has to request access for it. If reaching the approved tool takes three taps and reaching the free one takes one, you have written a rule that depends on willpower. If it is the other way round, the rule mostly enforces itself.
This is also the honest reason a lot of AI rules do not work. They were an instruction, when what was needed was a tool.
A rule only holds when following it is the easiest thing to do.
The one rule is a starting point, not the whole of it. Once it is in place and holding, there is more worth writing down — and by then you will have a much better idea of what your version needs to say, because you will have watched how the tools actually get used.
The usual next pieces are: what kinds of information can go in at all, and what gets taken out first; who checks AI-drafted work before it goes to anyone outside; keeping a short record of what is used and why, which is often the thing a regulator or a larger customer will ask to see; what happens if something goes in that should not have, so that the answer is a process rather than a panic; and a date in the diary to look at the whole thing again, because the tools will have changed.
None of that is urgent on day one. The one rule is. Doing it safely is where the fuller version lives, and it is worth doing properly once the basics are holding.
Two of those next pieces are worth reading when you get there: the four questions a proper policy needs to answer, and what actually determines whether client information is safe to put into AI in the first place. If you would rather have that written for you properly, it comes as part of the audit, not sold back afterwards.
And to be straight with you: the one rule is not something you need help with. It is a short conversation about which tools are in use, a decision about which ones stay, and a paragraph in writing. You can have it done by Friday without paying anyone. Where it gets harder is checking the terms behind each tool, working out what the approved option should be, and getting it into people’s hands so smoothly that nobody wants the other one. That part is worth having a hand with.
Every business has different obligations, so treat this as a sensible starting point rather than a finished policy — the fuller picture is under doing it safely.
Twenty minutes on the phone, free, no obligation. We will go through the tools already in use and help you word a rule that people will actually follow.