A simple AI policy for growing teams

A good AI policy does not need to be long. It should tell your team what AI is for, what needs review, and what must never go into a tool.

By Kyle Hornberg, Rising Tide Consulting

Illustrated AI policy board with guardrail cards, approval marks, privacy toggles, and sage wave lines.

Quick answer

A practical AI policy should explain approved uses, sensitive data rules, human review requirements, banned uses, and who to ask when the team is unsure.

The policy should be short enough that people actually read it.

Published: 27 June 2026.

Best for: owners, managers, and teams where staff are already experimenting with AI.

Time needed: 45 to 60 minutes for a practical first version.

Why you need a policy

If your team is using AI without a policy, you already have an AI policy. It is just unwritten.

That usually means every person makes their own call about what is safe, what is allowed, and what needs checking.

A practical policy gives people permission to use AI well, while making the boundaries clear.

The goal is not to scare people. The goal is to avoid three problems:

  • Private information being pasted into the wrong place.
  • AI output being sent without review.
  • Different team members using different standards.

Keep it to one page

Start with a one-page policy.

Long policies often fail because they sound like legal theatre. A useful first policy should be clear enough to read in five minutes and specific enough to use in daily work.

Use plain headings:

  • What we use AI for.
  • What information is not allowed.
  • What must be checked by a person.
  • What AI must never do.
  • Who approves new use cases.

That is enough for most growing teams to begin.

Section 1: approved uses

Tell the team what AI is encouraged for.

Good approved uses include:

  • Drafting internal notes.
  • Summarising meetings.
  • Turning rough ideas into outlines.
  • Creating first drafts of emails.
  • Preparing checklists.
  • Rewriting content in plain English.
  • Comparing options before a human decides.
  • Finding gaps in a document.

Be clear that AI is a drafting and thinking tool, not a final authority.

Section 2: sensitive data

This section matters.

List the information that should not be pasted into public or unapproved AI tools.

Examples include:

  • Client personal information.
  • Financial records.
  • Medical or legal information.
  • Passwords and access codes.
  • Staff performance details.
  • Confidential contracts.
  • Proprietary business information.
  • Anything a client would not expect to be shared.

Then explain the approved path. If your business has a paid team account with appropriate settings, name it. If not, say that sensitive work needs approval first.

Section 3: human review

Set a simple review rule:

AI can draft. A person is responsible for checking.

That means a human checks:

  • Facts.
  • Tone.
  • Pricing.
  • Client names.
  • Commitments.
  • Compliance requirements.
  • Whether the output should be sent at all.

This protects both the business and the staff member.

Section 4: banned uses

Every policy needs a short “do not use AI for this” list.

For most business teams, AI should not:

  • Make final hiring or firing decisions.
  • Give final financial, legal, medical, or compliance advice.
  • Approve refunds, discounts, or pricing without authority.
  • Send messages to clients without review.
  • Change business records without a person checking.
  • Create fake testimonials, fake reviews, or misleading claims.
  • Replace professional judgment where the business owes a duty of care.

The list should be specific to your industry.

Section 5: escalation

People need to know what to do when the answer is unclear.

Write one line:

If you are unsure whether a use is allowed, ask [name or role] before using AI.

That one line prevents a lot of awkward guesswork.

A simple policy starter

Use this as a starting point:

We use AI to help draft, summarise, organise, and improve work.

We do not paste sensitive client, staff, financial, legal, medical, password, or confidential business information into unapproved AI tools.

AI output must be checked by a person before it is sent, published, relied on, or added to a business system.

AI must not make final decisions about clients, staff, pricing, compliance, refunds, or professional advice.

If unsure, ask before using AI.

Next step

Write the one-page version first. Then review it after the team has used AI for two weeks.

The best policy is not the longest one. It is the one your team can remember while they are working.