AI policy template: the structure, and why a downloaded one usually fails
Templates are a reasonable starting point and a poor finishing point. Knowing which parts you can borrow and which you must write yourself is most of the job.
What an AI policy is
It sits above the acceptable use policy. The AI policy says what the company believes and who owns it. The acceptable use policy says what an individual may do on a Tuesday afternoon. Small companies often merge them, which is fine, as long as both jobs actually get done.
The eight sections
- Purpose and scope. Why this exists and which parts of the business it covers. Name the exclusions too, because unstated exclusions read as oversights.
- Principles. The commitments you are prepared to be held to. Keep this short. Four principles you honour beat ten you recite.
- Accountability. Who owns AI risk, by role. One name, not a committee, if you want it to mean anything.
- Approval. How a new AI tool or use gets assessed and approved, and by whom.
- Human oversight. Where a person must remain in the loop, and what they are responsible for checking.
- Data. What may be used with AI tools and what may not. Cross-reference your existing data policies rather than restating them.
- Incidents. What counts as an AI incident, who to tell, and how quickly.
- Review. Who reviews this, how often, and the date it was last approved.
Why a downloaded template usually fails
Three parts cannot be borrowed from anyone.
The scope depends on what you actually use, which means the inventory has to exist first. A policy scoped to systems you have never listed is scoped to nothing.
The accountability section needs a real role in your real structure. A template that says "the AI Governance Committee shall" describes an organisation with an AI governance committee. If you are eleven people, that sentence is a lie the moment you sign it.
The approval process has to match how decisions genuinely get made at your size. If in practice the founder decides in a Slack message, write that down as the process. A documented process nobody follows is worse evidence than an informal one you describe honestly.
The signature test
Before adopting any policy, read it as if a customer has asked you to demonstrate each sentence. Every claim you could not evidence within a day should be cut or softened until it is true.
This is the single most useful pass you can make, and it usually shortens the document by a third.
Length
Two to four pages for a small company. Policies that run to twenty pages do not get read, and an unread policy changes no behaviour, which is the only thing a policy is for.
After it is written
Approve it with a date and a named approver. Communicate it and keep evidence that you did. Then diary the review. A policy written once and never revisited describes a world that has already moved, and AI tooling moves faster than most policy cycles were designed for.
Find out what else you are missing
A policy is one of eleven documents. The check tells you which of the others you have, in about three minutes.
Start the check