← All posts
AI Policy & GovernanceFeb 10, 2026 · 9 min read

How to Build an AI Policy Your Employees Will Actually Follow

Most AI policies are written to protect the company and ignored by the people they govern. Here's how to write one that's short, human, and actually shapes behavior — with a template you can adapt.

AKAryan Kapoor

There are two kinds of AI policy. The first is a fourteen-page PDF full of the word 'shall', written by someone who has never used the tools, approved by legal, and read by no one. The second is a page your team can recall from memory when they're staring at a chatbot deciding whether to paste in a customer contract. Only the second kind changes what people do.

If your employees are using AI at work — and they are, whether you've blessed it or not — the question isn't whether to have a policy. It's whether to have one people follow. This guide is about writing the second kind.

Start from reality, not fear

The instinct after the first AI scare story is to ban everything. Bans don't stop usage; they push it into personal accounts on personal laptops where you have zero visibility. That's the worst outcome: same risk, no oversight. A good policy assumes people will use AI and channels it, rather than pretending they won't.

A rule people can't follow isn't a rule. It's a liability with a signature page.

The four questions your policy must answer

Employees don't need philosophy. When they're mid-task, they need fast answers to four questions:

  • What can I put into these tools? (And more importantly, what can't I?)
  • Which tools are approved?
  • When do I have to tell someone a human didn't write this?
  • Who do I ask when I'm not sure?

If your document answers those four things clearly on a single screen, you're ahead of most enterprises.

Draw the data line in plain language

The single most important rule is what data may enter an AI tool. Skip the legalese and use categories people recognize:

text
NEVER paste into any AI tool:
  - Customer personal data (names + details, IDs, health, payment info)
  - Unreleased financials, M&A, or legal matters
  - Passwords, keys, or anything from a credentials manager
  - Source code from private repos (unless using an approved, walled tool)

FINE to use freely:
  - Public information
  - Drafts you'd be comfortable emailing a colleague
  - Anonymized or clearly hypothetical examples

ASK FIRST if you're unsure — that's what #ai-help is for.

Notice the third column: 'ask first.' A policy that only says yes and no forces people to guess at the edges, and they'll guess in whichever direction is faster. Give them a door.

Approve tools, don't just forbid them

A list of banned tools ages badly and reads as hostile. Instead, publish a short list of approved tools for the common jobs — writing, coding, transcription, research — and a simple path to request a new one. When people have a sanctioned option that actually works, shadow usage drops on its own.

Be specific about disclosure

Vague rules like 'use AI responsibly' mean nothing. Spell out the few moments disclosure matters: AI-assisted content that goes to customers or the public, AI used in hiring decisions, and code generated by an assistant that needs review before merge. Everywhere else, let people work.

Make it a page, and make it kind

Tone is a feature. A policy written as a series of threats gets complied with grudgingly and worked around cheerfully. One written as 'here's how to use these tools well and stay out of trouble' gets internalized. Keep it to a page, use examples, and name a real human or channel as the place to ask questions.

Roll it out like you mean it

  1. 01Draft it with an actual user of the tools in the room, not just legal.
  2. 02Pressure-test it against three real scenarios your team hit last month.
  3. 03Launch it in a 20-minute session with examples, not an email no one opens.
  4. 04Revisit it every quarter — this field moves, and a stale policy loses authority fast.

The measure of an AI policy isn't how thoroughly it covers the company legally. It's whether the person about to paste something risky pauses, remembers the rule, and makes a better call. Write for that moment. If you're standing up governance across a growing team, our view on doing it without strangling the work is here.