The AI policy people actually follow

Most organisations now have an AI policy. Most of them are ignored, and the reason is visible in the first paragraph: they were written to satisfy a risk register rather than to be applied by a person deciding, in ten seconds, whether to paste something into a tool.

A policy that cannot be applied in ten seconds is not a policy. It is a document that exists so somebody can say a document exists.

Why the strict version fails

It bans what people are already doing. The work is faster with these tools. A prohibition does not remove the incentive; it removes your visibility of the behaviour, which is strictly worse than the situation before.

It is too long to consult. Nobody opens a fourteen-page document before writing an email. Whatever cannot be remembered is not in force.

It uses words that need interpretation. Confidential, sensitive, proprietary. Different people classify the same document differently and both defend their answer, so the rule decides nothing.

It ages badly. These capabilities are being built into the software you already licence. A policy saying no AI will be violated by your own suppliers within a year, and the whole document loses authority with it.

What the workable version contains

Approved tools people want to use. The policy fails on the day the sanctioned route is worse than the unsanctioned one. Whatever you approve has to be genuinely good, or the policy is a description of what people will route around.

Three data classes, in plain language. Not a taxonomy — something like: internal drafts and public information, fine anywhere approved; anything with a customer or employee name in it, only the approved tool; anything under a specific contractual restriction, nowhere. Written so somebody can classify a document in one read.

A named person to ask. Every policy hits an unanticipated case. If there is nowhere to ask, people guess, and they guess in the direction that gets the work done.

A log on the approved route. Not to police individuals — so that when a customer or an auditor eventually asks what happened to their information, there is an answer.

Human approval for anything outbound. Drafting is safe. Sending, committing and paying are where incidents come from, and the line belongs there rather than around the technology.

An amnesty. Say plainly that people who have already been using these tools are not in trouble. Without it, the first version of the policy produces compliance theatre and no information about what has actually been happening.

One page, and the amnesty is the important part

The best AI policies we have helped write are one page. Most of the effort goes into the data classes, because that is the part that has to be applicable without thought.

The amnesty is what makes the rest work. An organisation that asks what people have been doing, without consequences, learns in a week what it would otherwise never learn — and that information usually reshapes the policy in ways the drafting committee would not have predicted.

That session is normally the highest-return part of an AI workshops and training engagement, and it is a document rather than a technology project.