Writing the policy is now the easy part. Writing one that is still correct in six months, and that your team does not quietly route around, is the job almost nobody has done.
Adoption of AI policies jumped sharply in a year, and the result is a pile of documents that name ChatGPT by brand and will be wrong by the next release. A policy that works answers two questions and nothing else: what class of data may be entered into an AI tool, and what class of decision requires a named human. Everything else is detail. This guide gives you the seven clauses that carry the weight, the reason strict policies make your risk invisible rather than smaller, the training obligation most companies have inverted, and an honest read on enforcement, which is thinner than the compliance webinars suggest. It ends with a five-day rollout you can actually run.
Something genuinely changed in the last twelve months, and it is worth naming before we get into the mechanics. Littler’s annual employer survey, based on 306 US C-suite, in-house counsel and HR respondents, found 68% now report a formal policy governing workplace AI use. A year earlier, 38% had a specific policy and a further 13% had developed guidelines.[1] Allowing for a self-selected panel, that is still a fast and real shift.
ISACA’s survey of digital trust professionals puts the number lower, at 38% with a formal comprehensive policy, with another 30% running something limited.[2] The two surveys ask slightly different people slightly different questions, which is normal, and I would not spend much time reconciling them. The direction is the same either way. Most organisations have written something.
So the policy gap is closing. Here is the problem nobody put on the slide.
SHRM asked organisations that have an AI policy how well it is working. Only about a quarter felt their policy was clear and future-proof. 54% said their policy was too restrictive and too specific to the AI tools that happen to exist right now. Another 23% said theirs was too broad to be useful.[3] However those categories overlap, that is a lot of policies their own owners consider wrong in one direction or the other.
I have read a lot of these policies now, in workshops and in consulting work, and the failure is almost always the same. Someone in legal wrote a careful document about products. What they needed to write was a short document about data and decisions.
Strip away the preamble and an acceptable use policy exists to answer two questions. Everything else in the document is either detail hanging off one of them, or filler.
Question one: what class of data may be entered into an AI tool?
This is the question most policies skip, which is remarkable given it is the one with a documented body count. Littler found that while 68% of employers have an AI policy, only 54% restrict what information can be entered into AI tools, and only 55% have a formal review or approval process for new AI tools at all.[1] Littler reports those two figures separately rather than as a subset, so treat the subtraction loosely. But a 14-point gap between having a policy and restricting what goes into the tools is hard to read as anything other than a lot of documents that govern AI use without governing the actual failure mode.
And the failure mode is real. Cisco’s privacy benchmark found 64% of privacy and security professionals worry about inadvertently sharing sensitive information publicly or with competitors, while nearly half admitted entering personal employee data or non-public information into generative AI tools.[4] The people most alert to the risk are also doing the thing. That is not hypocrisy, it is what happens when a tool is useful and the rules are vague.
The canonical example is Samsung, which reportedly banned generative AI chatbots on company devices in 2023 after engineers were reported to have pasted proprietary source code into ChatGPT.[5] Samsung never published incident detail, so treat it as reported rather than confirmed. It still made the point that no policy memo has managed to make since: the risk is not that AI writes something silly. The risk is that somebody helpful pastes the wrong thing into a box.
Answer the data question with tiers, not prose. Here is the structure I use, which you can adapt in an afternoon.
| Tier | Examples | Rule |
|---|---|---|
| Open | Published marketing copy, public pricing, job adverts, policy text, anything already on your website | Any approved tool. No permission needed. |
| Internal | Draft strategy, internal process docs, anonymised or aggregated numbers, meeting notes with no named individuals | Approved enterprise tools only, where training on your data is off. |
| Restricted | Named employee or candidate data, salary and performance records, health information, customer records, unreleased financials, third-party confidential material, anything under NDA | Never entered into a general-purpose AI tool. Approved systems with a contract only, and only where a named owner has signed off. |
A three-tier data classification for AI use. The structure is the author’s, informed by the Littler 2026 finding that only 54% of employers restrict what information may be entered into AI tools.[1]
Three tiers, one page, no product names. This survives model releases because it describes your information, and your information does not change every quarter.
Question two: what class of decision requires a named human?
This is the accountability half, and it is where the legal exposure concentrates. The EEOC alleged that iTutorGroup programmed its tutor application software to automatically reject female applicants aged 55 and over and male applicants aged 60 and over, affecting more than 200 people. The company settled for $365,000 under a consent decree.[6] Be precise about this one, because it is routinely miscited as an artificial intelligence case: the EEOC describes software programmed to apply an age cut-off, and its release never mentions AI or machine learning at all. It is still the right case to put in front of your leadership team, because what it establishes is the ordinary and unglamorous principle underneath all of this. A company owns what its software does to people.
So write a second short table. Decisions that affect someone’s employment, pay, credit, access to a service or legal standing require a named human who owns the outcome and can explain the reasoning without reference to the tool. Decisions about what to name a campaign do not. Most of the middle ground resolves itself once you have written the two ends down.
If your organisation is still working out what safe AI use looks like in practice, our guide on using AI without leaking company data covers the operational side of the first question in more depth.
A good acceptable use policy is short. Two to four pages. If yours is fifteen, most of it is not being read and therefore is not doing anything except creating the impression of control. Here are the seven clauses that earn their space.
Scope is where policies quietly fail, because people write “generative AI tools” and mean chatbots. Your scope needs to cover AI notetakers joining meetings, assistants embedded in software you already pay for, browser extensions, personal accounts used for work tasks, and AI features switched on by a vendor without asking you. Write it as a description of behaviour, not a list of apps: any system that processes company information to generate content, summaries, recommendations or decisions.
An approved list without a request route is just a ban with extra steps. Littler found only 55% of employers have a formal review or approval process for AI tools.[1] That missing 45% is the single biggest cause of shadow use I see. Name the list, name the owner, and commit to a response time. Two weeks is fine. Silence is not.
As above. This is the clause that would have prevented most of the incidents anyone can actually name.
The person who uses the output owns the output. Facts, figures, quotes and citations are verified before use. No exceptions and no shared blame with the tool. This clause is short and it does more work than any other sentence in the document.
Making or materially influencing hiring, promotion, discipline or termination decisions without meaningful human review. Generating content that impersonates a real person. Entering restricted data. Using AI to produce anything presented as independently verified when it was not. Keep this list short enough that people remember it.
When AI involvement must be flagged, and to whom. Customer-facing content, candidate communications and anything going to a regulator are the usual triggers. Crucially, pair this with an explicit statement that good-faith disclosure of AI use will not be held against anyone. I will explain in a moment why that sentence matters more than the rest of the clause.
Not “this policy will be reviewed periodically.” A name and a date, written into the document. A policy with no named owner will not get updated, and an AI system with no named owner is one nobody is confident they can switch off. Ownership is the thing that stops a document becoming an artefact.
This is the part I would most like leaders to sit with, because it runs against instinct.
KPMG and the University of Melbourne surveyed more than 48,000 people across 47 countries. Among employed respondents, 44% admitted using AI in ways that contravene organisational policies, including uploading sensitive company information to public tools. More than half said they avoid revealing when they use AI, and present AI-generated content as their own. Only 34% reported that their organisation had any policy or guidance on generative AI use at all.[9]
Microsoft’s Work Trend Index found the same pattern from the other side back in 2024: 78% of AI users were bringing their own tools to work, rising to 80% at small and medium-sized companies, and 52% of people using AI at work were reluctant to admit using it for their most important tasks.[10] That data is now two years old and I would expect the direction to have continued rather than reversed.
Read those findings together and the conclusion is uncomfortable. A restrictive policy does not reduce AI use. It relocates it. The work moves to personal accounts on personal devices, where you have no visibility, no data controls, no logs and no ability to help. You have converted a visible risk into an invisible one and called it compliance.
Gallup’s mid-2025 numbers show the size of the vacuum people are filling on their own: 44% of US employees said their organisation had begun integrating AI, but only 22% said it had communicated a clear plan, and only 30% said there were general guidelines or formal policies for using AI at work.[11]
So the design goal for your policy is not maximum restriction. It is making it professionally safe to say “I used AI for this.” Three things do that work:
Honestly, if you only implement one of the seven clauses this quarter, make it that third one. Everything else in your governance depends on people telling you the truth about what they are doing, and right now most of them are not.
If your organisation touches the EU in any way, there is an obligation here that a lot of companies have quietly got backwards.
Article 4 of the EU AI Act, the AI literacy provision, entered application on 2 February 2025. It obliges providers and deployers of AI systems to take measures aimed at a sufficient level of AI literacy among staff and other people dealing with the operation and use of AI systems on their behalf.[12] It reaches every deployer regardless of risk tier, and it prescribes no particular curriculum. The Act is being actively amended as part of the EU’s digital simplification work, so check the current consolidated text before relying on the precise wording.
Notice what that is. It is a training obligation, not a paperwork obligation. And most organisations have responded by producing a document and no training, which is precisely the inverse of what the text asks for. If you want the wider picture on what the Act means for an ordinary business, we have a fuller guide to EU AI Act compliance.
There is a practical argument here too, separate from the legal one. A policy that people have not been trained on is a policy people will interpret. SHRM found that 57% of HR professionals working in the 19 US states it identifies as regulating employer AI use were not aware those laws existed, and only 12% had implemented compliant policies.[3] If the people writing and enforcing the rules do not know the landscape, the rules will be either too tight or accidentally illegal.
SHRM’s other finding explains a great deal about why so many policies land badly: 52% of organisations do not involve HR in AI strategy at all, and legal and compliance functions lead AI governance in 37% of cases.[3] The document gets written by the function furthest from the daily work, nobody who does that work pressure-tests it, and it fails on first contact. That is the whole mechanism behind SHRM’s “too restrictive and too tool-specific” finding.
A lot of the advice you will read on this topic is sold on fear of regulatory penalties. I want to be straight with you: the enforcement is thinner than the marketing suggests, and building your internal case on it will make you look uninformed the first time someone checks.
New York City’s Local Law 144, the automated employment decision tool rule that generated an enormous amount of compliance content, has barely been enforced. A New York State Comptroller audit published in December 2025, covering July 2023 to June 2025, found the enforcing agency had received just two complaints in two years. The agency reviewed 32 companies and identified a single instance of non-compliance. The Comptroller’s own auditors reviewed the same 32 companies and identified at least 17 instances of potential non-compliance.[13]
Colorado’s landmark AI Act, meanwhile, was never enforced at all. SB 24-205 was delayed, then repealed and replaced by SB 26-189 in May 2026, effective January 2027. The replacement strips out the duty of care, the algorithmic impact assessments and the rebuttable presumption of compliance for following the NIST framework, leaving notice and disclosure obligations enforced by the Attorney General.[14]
This does not mean regulation is irrelevant. Littler found 84% of employers expect AI policy and regulatory changes to affect their business in the next twelve months, double the 42% who said so a year earlier, and 79% are concerned about AI-related litigation, led by data privacy, discrimination and bias, and state and local AI law compliance.[1] SHRM identifies 19 US states as now regulating employer AI use.[3] The direction of travel is clear.
But the honest argument for writing a policy this quarter is commercial, not legal. Most of your AI users are on tools you did not buy and cannot see, putting your information into them, and not telling you. That is the problem in front of you. The fines, if they ever arrive, will arrive later.
This is genuinely a week of work, not a quarter, provided you resist the urge to make it comprehensive.
The five-day sequence described in this section. Days 1, 4 and 5 involve no drafting at all.
Day one is an inventory, and it only works with an amnesty. Ask every team what AI tools they currently use, state clearly and in writing that nobody is in trouble for the answer, and mean it. You will discover more in a day than any audit will find in a month. If nobody admits to anything, you have learned something important about the second half of this article.
Day two is data classification. Take your three tiers and populate them with your actual information types. Do this with someone from finance, someone from HR and someone from the customer-facing side in the room. Twenty minutes each, an hour in total.
Day three is the draft. Seven clauses. Two to four pages. You can use AI to write it, and you should, because a language model is genuinely good at turning a set of decisions into readable policy prose. What it must not do is decide anything. Feed it your tiers, your approved tool list, your prohibited uses, and ask it to write those up in plain English at an eighth-grade reading level, adding nothing. Then read every line.
Day four is the pressure test. Three people, three functions, one real task each, following the draft exactly. Rewrite whatever they had to break.
Day five is training, then publication. In that order. A live forty-five minute session where you show the tiers, show two real examples of a good judgement call and a bad one, and take questions, is worth more than any acknowledgement form. Publish the document afterwards as the reference, not the event.
If you are building this into something larger, our guides on AI enablement and structuring an AI centre of excellence cover where the policy sits in a wider programme.
Four failure modes, in the order I encounter them.
Naming products. The policy lists three tools by brand. Six months later two of them have changed capability, a fourth has appeared inside software you already own, and the document is silently wrong. Describe categories of use and categories of data. Put the product list in a separate appendix that a named owner can update without reopening the policy.
Writing it alone in legal. This produces the “too restrictive, too tool-specific” outcome SHRM measured, every time.[3] Legal should draft the language. Someone who does the work should decide what the rules are.
Publishing without training. You have satisfied the paperwork instinct and none of the actual obligation, which in the EU is explicitly a literacy requirement.[12] A policy nobody has been walked through is a policy people will interpret in whatever direction is most convenient at 5pm on a Thursday.
Building it on fear. If you sell this internally as “we will be fined,” someone will eventually check the enforcement record and conclude the whole thing was theatre. Sell it on what is true: your people are already using AI, on tools you did not choose, with data you cannot see, and they are hiding it because you have not made it safe to say so.
The thing I would most like you to take from this is the two-question frame. Data in, decisions out. If your policy answers those two clearly and everything else is an appendix, it will still be broadly right in two years, which is more than most governance documents manage. And if you already have a policy, do not rewrite it from scratch. Open it, and check whether either question is actually answered. In more than half the ones I have read, neither is.
For the adjacent people-side of this, our guide to writing an employee handbook with AI covers where the AI section fits and why it can itself become an unlawful work rule if drafted too broadly.
It is a short internal document that sets out which AI tools people may use at work, what information they may put into those tools, which decisions still require a named human, and when AI involvement must be disclosed. It is not a technical document and it should not be long. Two to four pages is the right size. The two clauses that do most of the work are a data classification (what may go in) and a decision-consequence rule (what needs a human owner).
No jurisdiction currently requires the document itself. The EU AI Act does impose a related obligation: Article 4, the AI literacy provision, entered application on 2 February 2025 and obliges deployers to take measures aimed at a sufficient level of AI literacy among staff using AI systems on their behalf.[12] That is a training duty rather than a paperwork duty, which most organisations have inverted. Check the current consolidated text, since the Act is being amended. In the US, SHRM identifies 19 states as regulating employer use of AI, though enforcement so far has been light.[3]
Seven clauses cover it: a scope written wide enough to include notetakers and embedded assistants; an approved tool list with a real route to request additions; a three-tier data classification; a human accountability rule; a short list of prohibited uses; a disclosure rule paired with an explicit no-punishment clause; and a named owner with a review date. Anything beyond that is usually appendix material that will age badly.
A blanket ban tends to relocate the risk rather than remove it. KPMG and the University of Melbourne found that 44% of employed respondents already use AI in ways that contravene their organisation’s policies, and more than half avoid revealing when they use it at all.[9] Microsoft found 78% of AI users bring their own tools to work.[10] A named approved list, a fast request route and a no-punishment disclosure clause will give you far more visibility than a prohibition you cannot enforce.
Put a named owner and a specific review date in the document rather than a vague commitment. A quarterly check on the approved tool appendix and a full annual review of the policy body is realistic for most organisations. If you have built the policy around data classes and decision consequence rather than product names, the body should need very little change between annual reviews, which is the entire point of structuring it that way.
This guide draws on 2025 and 2026 survey research from Littler Mendelson, SHRM, ISACA, Gallup, Cisco, KPMG and the University of Melbourne, plus primary sources from the EEOC, NIST, ISO, the EU AI Act text and the New York State Comptroller. Every statistic was checked against the original publication before inclusion, and figures that could not be traced to a primary publisher were left out. Nothing here is legal advice: it is a structure for deciding what your policy needs to say and who needs to be in the room when you write it.