What goes in an AI use policy? A one-page template
A good AI use policy fits on one page and answers seven questions: why you use AI, which tools are approved, what data never goes in, who reviews the output, when you disclose AI use, how vendors are checked, and who to ask.
Why your AI policy should fit on one page
A policy only works if people read it. A 30-page policy nobody has opened protects no one, and neither does no policy at all while staff paste sensitive data into free tools.
Keep it to one page. Fill in the blanks for your organization, have counsel review anything involving regulated data, then adopt it. Of everything a new AI officer does, this is the fastest risk you can retire.
The one-page AI use policy template
Copy this structure and fill in each blank. The bracketed text is what you replace.
- Purpose. We use AI to save time on routine work and improve service. A person is always responsible for anything AI helps produce.
- Approved tools. Staff may use: [list of tools], set up through the organization's accounts. Personal or free accounts may not be used for work.
- Never put into any AI tool: [list of data types, for example: student or patient records, financial account details, passwords, personnel files, anything covered by a confidentiality agreement].
- Always review. AI output is a draft. A person checks facts, tone, and names before anything is sent, published, or decided.
- Say when it matters. We disclose AI use when [conditions].
- Vendors. Before adopting a tool, we confirm how it handles our data and whether it trains on it. Owner of that check: [name or role].
- Questions and new tools. Ask [name or role]. New tools are approved by [name or role].
- Adopted on [date]. Review date [date].
Purpose: who is responsible
The purpose line does two jobs. It tells staff AI is allowed and expected for routine work, which brings shadow use into the open. And it puts responsibility on a person, not a tool. “The AI wrote it” is never an excuse once this line is adopted.
Approved tools: organization accounts only
Name the specific tools. Then require that they be set up through the organization, not through personal or free accounts. Organization accounts are where you can control settings, see who has access, and close access when someone leaves.
Before you write this list, find out what staff already use. No blame. If the policy bans the tool everyone depends on without offering an approved alternative, people will quietly ignore it.
Data that never goes into an AI tool
This is the most important line on the page. Be concrete. “Sensitive data” is too vague for anyone to act on. List the actual categories your organization handles: records about students, patients, or clients, financial account details, passwords, personnel files, and anything covered by a confidentiality agreement.
If you handle student, patient, or financial data, check your legal obligations with counsel. This guide is general information, not legal advice.
Always review: AI output is a draft
Every output is a draft until a person checks facts, tone, and names. This rule is what makes low-risk deployments low-risk. It is also why your first deployments should be work where a wrong draft hurts no one, because a person catches it before it goes out.
Disclosure: say when it matters
You do not need to label every email a tool helped draft. You do need to decide, in advance, when disclosure matters for your organization and your audience. Write the condition down so staff are not guessing case by case.
Vendors: check how they handle your data
Many tools you already pay for have added AI features. Before adopting any tool, confirm how it handles your data and whether it trains on it. Name an owner for that check, so it actually happens.
As part of your first 30 days, list which vendors already use AI on your organization's data. That list often surprises leadership.
Questions, new tools, and the review date
Name one person to ask and one person or role who approves new tools. Without that line, every question becomes a hallway debate.
Finally, record the date the policy was adopted and the date it will be reviewed. Tools change every month. A review date keeps the policy honest without rewriting it every time something new launches.
How to get the policy adopted
Writing the page is the easy part. Getting it adopted takes a few deliberate steps:
- Draft it with input from the people who do the work, so it reflects how they actually use AI.
- Have counsel review anything involving regulated data.
- Get leadership to adopt it formally, with a date.
- Walk staff through it in a short session, and show them the approved tools.
- Put the review date on the calendar.
Frequently asked questions
How long should an AI use policy be?
One page. The goal is a policy staff actually read: approved tools, data that must never go in, review rules, disclosure, vendor checks, and who to ask. A long policy nobody opens protects no one.
Is this AI policy template legal advice?
No. It is general information and a starting structure. If you handle student, patient, or financial data, or anything else regulated, have counsel review the policy before you adopt it.
Should we ban free AI tools?
For work, yes: require approved tools set up through organization accounts, and offer a real alternative. First find out what staff already use, without blame, so the policy replaces shadow tools instead of being ignored.
How often should an AI policy be reviewed?
Set a review date when you adopt it and put it on the calendar. The structure should survive tool changes, so the review is about updating the approved tools list and anything still open, not rewriting the page.
Related guides
What should a Chief AI Officer do in the first 90 days?
Read the guideWhat does a Chief AI Officer do?
Read the guideHow do you measure AI ROI?
Read the guideThe CAIO Field Guide
Everything in these guides in one place, with five fill-in worksheets: a repeated-work inventory, a one-page AI use policy, a one-win scorecard, a 90-day readout, and a role proposal.