AI policy template: the structure, and why a downloaded one usually fails
Templates are a reasonable starting point and a poor finishing point. Knowing which parts you can borrow and which you must write yourself is most of the job.
What an AI policy is
It sits above the acceptable use policy. The AI policy says what the company believes and who owns it, while the acceptable use policy says what an individual may do on a Tuesday afternoon. Small companies often merge the two, which is fine as long as both jobs still get done.
The 8 sections
- Purpose and scope. Why this exists and which parts of the business it covers. Name the exclusions too, because unstated exclusions read as oversights.
- Principles. The commitments you are prepared to be held to. Keep this short. Four principles you honour beat ten you recite.
- Accountability. Who owns AI risk, by role. One name, not a committee, if you want it to mean anything.
- Approval. How a new AI tool or use gets assessed and approved, and by whom.
- Human oversight. Where a person must remain in the loop, and what they are responsible for checking.
- Data. What may be used with AI tools and what may not. Cross-reference your existing data policies rather than restating them.
- Incidents. What counts as an AI incident, who to tell, and how quickly.
- Review. Who reviews this, how often, and the date it was last approved.
Why a downloaded template usually fails
Three parts cannot be borrowed from anyone.
The scope depends on what you actually use, which means the inventory has to exist first. A policy scoped to systems you have never listed is scoped to nothing.
The accountability section needs a real role in your real structure. A template that says "the AI Governance Committee shall" describes an organisation with an AI governance committee. If you are 11 people, that sentence is a lie the moment you sign it.
The approval process has to match how decisions genuinely get made at your size. If the founder decides in a Slack message, write that down as the process. A documented process nobody follows is worse evidence than an informal one you describe honestly.
The signature test
It is the single most useful pass you can make on a policy, and it almost always makes the document shorter.
Two to four pages, because a policy nobody reads changes nothing
Two to four pages for a small company. Policies that run to twenty pages do not get read, and an unread policy changes no behaviour, which is the only thing a policy is for.
Approving it is not the last step
Approve it with a date and a named approver. Communicate it and keep evidence that you did. Then diary the review. A policy written once and never revisited describes a world that has already moved, and AI tooling moves faster than most policy cycles were designed for.
Find out what else you are missing
A policy is one of 11 documents. The check tells you which of the others you have, in about 3 minutes.
Start the 3-minute check