Your team is already using AI. Surveys keep finding half of employees using it without telling anyone, and the untold half is the risk: client data pasted into free chatbots, confident wrong answers shipped unreviewed. A policy doesn't create AI use; it makes the existing use safe and visible. One page is enough. Longer policies get skimmed once and forgotten. Here's the one-pager, section by section.
Section 1: approved tools
Name them specifically: which assistants, which accounts. The load-bearing distinction is company business accounts versus personal free accounts, because the business tiers carry the no-training-on-your-data terms and admin controls that free tiers don't (see the tool tiers). The sentence that matters: work happens in company AI accounts only. If you don't provide one, this section is where you start providing one, because the alternative isn't abstinence, it's shadow use.
Section 2: what never gets pasted
The data rules, concrete enough to act on:
- Client names, files, and identifying details, unless in an approved tool and the engagement allows it
- Employee personal data: SSNs, pay, health, reviews
- Passwords, keys, and account numbers, ever, anywhere
- Anything under NDA, and anything regulated (HIPAA, card data) outside a tool explicitly configured for it
Teach the redaction habit: strip identifiers, use placeholders, review AI output for a while, then decide. Most tasks work exactly as well on "Client A" as on the client's name.
Section 3: when a human reviews
The tiering that keeps quality incidents from becoming policy funerals: internal drafts and summaries, light review. Anything leaving the building with your name on it, full human review, no exceptions. Numbers, legal language, and commitments, verified against source, because AI states wrong figures with the same confidence as right ones. One clarifying rule: the person who sends it owns it. "The AI wrote it" is not a defense; it's an admission the review step got skipped.
Section 4: disclosure and the gray areas
Decide your stance on disclosure once, so nobody improvises: whether client deliverables mention AI assistance, and what to answer when a customer asks. Then name a person for gray-area questions. New tool someone wants to try, weird edge case, vendor pitching an "AI feature" that wants data access: route to that person instead of to guesswork. This is also the enforcement valve: the policy stays one page precisely because the edge cases have a human instead of a paragraph.
Rolling it out
Introduce it as permission, not prohibition: here are the tools, here's the paid account, here's the one meeting where we walk through it. Pair the policy with training on what AI is actually good at, because people follow rules they see the sense in. Revisit every six months; this field moves. And read the security risks alongside, because sections 1 and 2 are the direct countermeasures to the two most common incidents.
Want this handled instead of homeworked? That's the job.
Email us →