Generative AI policy template: sections, owners and review cycle

Generative AI policy template: sections, owners and review cycle

A generative AI policy has two audiences who want different things. Staff want to know what they can do today. Leadership, legal and IT want to know how tools get approved, who is accountable and what gets reported. Most templates serve one and ignore the other.

This structure covers both in eight sections. The first four are for everyone. The last four are governance, and most staff never need to read them.

The eight sections

# Section Audience Owner
1 Purpose and scope Everyone Policy owner
2 Approved tools Everyone IT
3 Data rules Everyone Data protection lead
4 Review and accountability Everyone Policy owner
5 Tool approval process Managers, IT IT and legal
6 High-risk uses Managers, HR Legal
7 Incidents Managers, IT IT security
8 Review cycle Policy owner Policy owner

Sections 1 to 4: what staff read

1. PURPOSE AND SCOPE
This policy covers any use of generative AI tools for company
work, on any device or account.

2. APPROVED TOOLS
[Tool A] and [Tool B] with your work account. Anything else
needs IT approval before you use it with work content.

3. DATA RULES
Never enter: customer personal data, credentials, unannounced
financials, or anything a contract marks confidential.

4. REVIEW AND ACCOUNTABILITY
A person reviews AI-assisted work before it goes external or
feeds a decision about a person. Whoever sends it owns it.

Keep these four on one page. If staff have to scroll, they will not.

Sections 5 to 8: governance

5. Tool approval

Requests go to IT with: the tool, the use case, the data involved,
and the vendor's data terms. IT and legal respond within ten
working days. Approved tools are added to section 2.

6. High-risk uses

These need written sign-off from legal before any AI is used:
- hiring, promotion, pay or disciplinary decisions
- anything producing legal, medical or financial advice
- automated decisions about customers

7. Incidents

If restricted data goes into an unapproved tool, or AI output
causes harm, report it to IT security the same day. Reporting
quickly is expected and will not count against you.

That last line matters. If people fear blame, incidents go unreported and you find out months later.

8. Review cycle

Reviewed every six months, and whenever a tool is added or
removed or relevant law changes. Changes are announced in
[channel] with a one-paragraph summary.

A note on regulation

Depending on where you operate and what you use AI for, specific laws may apply, particularly for uses in hiring or automated decisions about individuals. A template gives you structure; it does not replace advice from someone who knows your jurisdiction.

Questions people ask

What is the difference between a generative AI policy and an AI governance policy?

Many companies combine them, as above. Split them if your governance section grows beyond a couple of pages, and keep the staff rules short.

Who should own the policy?

One named person, usually in operations, IT or legal. A committee can advise, but a committee cannot answer a question on a Thursday afternoon.

How do we make people actually follow it?

Keep the staff part to one page, name the tools, and give people a place to ask. We cover rollout in company AI policy rollout.

Where to take this next

The free AI policy template has the full staff-facing wording ready to edit. The House Rules goes a step further and turns your policy into instructions every AI assistant in the company follows automatically.

Leave a comment: