Skip to content
Go to homepageDrova logo

The AI policyyour business actually needs

The full template is on this page. Free, no form.

Every business suddenly needs an AI policy, and most of the templates on offer were written for a different company than yours. This page gives you the whole thing to copy, and shows you how to make it yours.

Simple feature visual

TL;DR

  • An AI policy is the set of rules for how your people use AI at work: which tools, with what data, checked by whom. The full template is below, free and ungated.
  • You need one even if you have adopted nothing. Your people are already using AI, and a policy that pretends otherwise governs a company that does not exist.
  • An acceptable use policy is usually one section of an AI policy, not a separate document.
  • Generic templates fail because the policy should follow from the risks AI is actually driving in your business, and those differ by business.
  • Adapt the template to your circumstances. It is a starting point, not legal advice.

What is an AI policy?

An AI policy is the document that tells your people how AI is used in your business: which tools are approved, what information can and cannot go into them, who checks the output before it matters, and what happens when something goes wrong. It is one of the first safeguards most businesses put in place, and one of the cheapest.

Two neighbouring things share the name and are not this page. Government AI policy is regulation, not something you write. And if you build AI products, you will also need development and deployment standards beyond an internal use policy.

One page in our series on the real risks of AI for a business: the policy exists because AI is not a new risk on your register, it is a driver of the risks already there, and several of them run straight through how your people use these tools day to day.

Before you download another one

Why most AI policies fail

Most AI policies fail in one of two ways, and both failures are decided on day one.

The first is the blanket ban. It reads as safe and it governs nothing, because your people are already using AI, and a ban simply moves that use somewhere you cannot see it. The policy that says no to everything is how shadow use becomes the norm.

The second is the downloaded template, adopted whole. It names risks you do not have, misses the ones you do, and everyone can tell nobody wrote it. It gets signed, filed and never read again.

What works is smaller and harder: a short policy written from the risks AI actually drives in your business, owned by someone real, and revisited often enough to stay true. That is what the template below is shaped for.

The four things it must cover

Tools and access

Which AI tools are approved, who can use them, and how someone proposes a new one. The list will change; the route for changing it should not.

Data in

What must never be pasted or uploaded: customer records, credentials, unreleased financials, anything under NDA. The single most breached rule in practice.

Judgement out

AI output that reaches a customer, a regulator or a decision gets checked by a named human first. Accountability stays with people, not tools.

Ownership and review

One named owner, a review cycle measured in months not years, and a way for anyone to ask questions or report a problem without ceremony.

Copy it from here

The template

How to use this: copy it, delete what does not apply, and fill the bracketed parts. Keep it under two pages. It is a starting point to adapt to your circumstances, not legal advice.

1. Purpose and scope. This policy sets out how [Company] uses AI tools in our work. It applies to everyone who works for us, including contractors, on any device used for work.

2. Approved tools. The approved AI tools are listed at [location of the list]. Anyone may propose a new tool to [owner]; tools are approved before first use, not after. Using an unapproved tool for work is a policy breach even when the result is good.

3. What never goes in. The following are never entered into any AI tool unless that tool has been approved for exactly this use: customer or employee personal information; credentials and keys; unreleased financial information; anything covered by an NDA; and [the specific information your business most needs to protect].

4. Checking what comes out. AI output is a draft, not an answer. Anything that will reach a customer, a regulator, a court or a business decision is verified by a named person who takes responsibility for it as if they had written it. AI is never cited internally as the reason a decision was right.

5. What AI may not be used for. At [Company], AI tools are not used to: make final decisions about people, including hiring and performance; generate content we present as human-made where that matters to the recipient; or [uses specific to your obligations, for example regulated advice].

6. Openness. When AI has materially produced something a customer or partner receives, we say so if asked, and proactively where it is material to what they are relying on.

7. When something goes wrong. Anyone who realises AI has been misused, or that wrong AI output has gone out, reports it to [owner] straight away. The response follows our incident process; reporting honestly is never punished.

8. Ownership and review. This policy is owned by [name, role]. It is reviewed every [three/six] months, because the tools change faster than an annual cycle. Questions go to the owner directly.

The step most skip

Making it yours

The bracketed parts are not filler; they are the policy. What your business most needs to protect, and what AI must never be used for in your work, are decided by the risks AI is actually driving against your objectives, and those are different for a lender, a manufacturer and an agency.

So the honest order of work is: know your risks first, then write the rules. If you have already run an AI risk assessment, sections 3 and 5 write themselves from its results. If you have not, Drova’s AI Disruption Index maps the risks AI is driving against your objectives, free, in about ten minutes, and it is ours, so weigh that as you read this page.

Record the finished policy as a safeguard against the risks it addresses in your risk register, so it gets reviewed when they do. And if the underlying term is unfamiliar, what is AI disruption? is the short version.

Vocabulary

AI policy or acceptable use policy?

You will meet both names, often for the same document. In practice, an acceptable use policy is the part that tells individuals what they may and may not do, roughly sections 2, 3 and 5 of the template above. The AI policy is the whole thing, including ownership, review, openness and what happens when something goes wrong.

Small businesses rarely need them as separate documents. Keep one short policy people actually read. If you want an external cross-check, the Australian Cyber Security Centre publishes plain guidance on using AI systems securely, including an edition written for small business and a paper on AI data security. Worth a read alongside this page.

AI policy FAQs

Do we need an AI policy if we have not adopted AI?

Yes, and arguably sooner. Your people are already using AI tools, whether or not anything was approved. A policy is how unmanaged use becomes managed use. Writing one is also the fastest way to discover what is already happening.

What is the difference between an AI policy and an acceptable use policy?

The acceptable use policy is usually one part of the AI policy: the rules for individuals about tools, data and prohibited uses. The full policy adds ownership, review, openness with customers and incident handling. Most businesses should keep them as one short document.

How long should an AI policy be?

Under two pages. Past that, it stops being read, and a policy nobody reads governs nothing. Length is usually a sign the policy is trying to solve problems that belong to other documents.

Who should own it?

One named person with the standing to say no: often whoever owns risk, security or operations. The worst owner is a committee, because a policy that belongs to everyone is reviewed by no one.

How often should it be reviewed?

Every three to six months. The tools and what they can do change on that timescale, so an annual cycle guarantees the policy describes a world that has already moved.

Is the template above legal advice?

No. It is a practical starting point in plain English. Adapt it to your circumstances, and if you operate under sector regulation or handle sensitive data at scale, have your adviser read the result before you adopt it.

Drova's AI Disruption Index maps the risks AI is driving against your objectives, with a safeguard drafted for each. Free, in about ten minutes.

The policy follows the risks. See yours first.