This template is a starting structure, not legal advice. Adapt it to your industry, jurisdictions, data-classification standard, contractual obligations, and risk appetite. The most important step is to connect every statement to an owner and a working process.
Policy template
1. Purpose
This policy establishes requirements for the responsible selection, development, procurement, use, monitoring, and retirement of AI systems used for company work.
2. Scope
The policy applies to employees, contractors, vendors, AI-enabled software, standalone models, embedded features, agents, APIs, and internally developed systems. It applies whether access uses a company or personal account.
3. Core rules
- Use only approved tools and account types for company work.
- Enter data only when the environment is approved for that data classification.
- Keep a named human accountable for every material output or action.
- Do not use AI as the sole decision-maker for consequential decisions unless expressly approved.
- Review outputs for accuracy, bias, confidentiality, intellectual-property risk, and fit for purpose.
- Report incidents, unexpected behavior, or suspected data exposure promptly.
4. Risk tiers
Define three or four tiers using impact, sensitivity, autonomy, scale, reversibility, and affected people. Specify which tiers require a documented assessment, legal or security review, executive approval, independent testing, or continuous monitoring.
5. Use-case intake
Require the owner to document purpose, users, data, system access, output audience, success measures, failure modes, controls, and accountable reviewer. Publish a target response time so teams do not route around the process.
6. Testing and approval
Testing should reflect the real workflow and known failure modes. Record acceptance criteria, test data, results, limitations, approvers, and the conditions of approval. A successful demonstration is not production evidence.
7. Human oversight
Define the review point, reviewer qualifications, information available to the reviewer, and action when confidence is low. Avoid ceremonial approval where the human cannot meaningfully challenge the output.
8. Monitoring and incidents
Name the measures, thresholds, review frequency, escalation path, and authority to pause use. Preserve enough evidence to understand what happened without collecting unnecessary personal data.
9. Roles
Assign policy ownership, technical ownership, business ownership, risk review, training, monitoring, incident response, and final decision authority.
10. Exceptions and review
Document exception scope, compensating controls, approver, expiration date, and review date. Review the policy at least annually and after significant changes.
Rollout checklist
Before publication, confirm that the approved-tool register exists, data examples are clear, the intake form works, review bodies have capacity, managers have scenario training, employees have a help channel, and enforcement is proportionate. After launch, measure questions, review time, disclosed uses, migration to approved tools, and incidents.
The policy succeeds when people can make safer decisions quickly and governance can produce evidence of how those decisions were made.