A generative AI policy has two audiences who want different things. Staff want to know what they can do today. Leadership, legal and IT want to know how tools get approved, who is accountable and what gets reported. Most templates serve one and ignore the other.
This structure covers both in eight sections. The first four are for everyone. The last four are governance, and most staff never need to read them.
The eight sections
| # | Section | Audience | Owner |
|---|---|---|---|
| 1 | Purpose and scope | Everyone | Policy owner |
| 2 | Approved tools | Everyone | IT |
| 3 | Data rules | Everyone | Data protection lead |
| 4 | Review and accountability | Everyone | Policy owner |
| 5 | Tool approval process | Managers, IT | IT and legal |
| 6 | High-risk uses | Managers, HR | Legal |
| 7 | Incidents | Managers, IT | IT security |
| 8 | Review cycle | Policy owner | Policy owner |
Sections 1 to 4: what staff read
1. PURPOSE AND SCOPE
This policy covers any use of generative AI tools for company
work, on any device or account.
2. APPROVED TOOLS
[Tool A] and [Tool B] with your work account. Anything else
needs IT approval before you use it with work content.
3. DATA RULES
Never enter: customer personal data, credentials, unannounced
financials, or anything a contract marks confidential.
4. REVIEW AND ACCOUNTABILITY
A person reviews AI-assisted work before it goes external or
feeds a decision about a person. Whoever sends it owns it.
Keep these four on one page. If staff have to scroll, they will not.
Sections 5 to 8: governance
5. Tool approval
Requests go to IT with: the tool, the use case, the data involved,
and the vendor's data terms. IT and legal respond within ten
working days. Approved tools are added to section 2.
6. High-risk uses
These need written sign-off from legal before any AI is used:
- hiring, promotion, pay or disciplinary decisions
- anything producing legal, medical or financial advice
- automated decisions about customers
7. Incidents
If restricted data goes into an unapproved tool, or AI output
causes harm, report it to IT security the same day. Reporting
quickly is expected and will not count against you.
That last line matters. If people fear blame, incidents go unreported and you find out months later.
8. Review cycle
Reviewed every six months, and whenever a tool is added or
removed or relevant law changes. Changes are announced in
[channel] with a one-paragraph summary.
A note on regulation
Depending on where you operate and what you use AI for, specific laws may apply, particularly for uses in hiring or automated decisions about individuals. A template gives you structure; it does not replace advice from someone who knows your jurisdiction.
Questions people ask
What is the difference between a generative AI policy and an AI governance policy?
Many companies combine them, as above. Split them if your governance section grows beyond a couple of pages, and keep the staff rules short.
Who should own the policy?
One named person, usually in operations, IT or legal. A committee can advise, but a committee cannot answer a question on a Thursday afternoon.
How do we make people actually follow it?
Keep the staff part to one page, name the tools, and give people a place to ask. We cover rollout in company AI policy rollout.
Where to take this next
The free AI policy template has the full staff-facing wording ready to edit. The House Rules goes a step further and turns your policy into instructions every AI assistant in the company follows automatically.
Leave a comment: