The One-Page AI Policy YourBusiness Actually Needs
An AI policy written by AI gives you four pages of principles and changes nothing. The version that works fits on one page.
An AI policy written by AI gives you four pages of principles and changes nothing. The version that works fits on one page and answers four questions. Here they are.
Why the obvious approach fails
A business owner told the room he needed an AI policy for his employees. Then he admitted his first instinct was to ask AI to write it.
That is a reasonable instinct, and it will hand you a beautiful, useless document.
Responsible use. Human oversight. Alignment with company values. Nobody ever changed what they do on a Tuesday because of a sentence like that.
The policy question came up three separate times that afternoon at an Ask Us Anything About AI forum in Greenville, which tells you something.
The four things that have to be in it
1. Which tools are approved. Name them. "AI" is not a tool. "Claude Team and ChatGPT Business" is a tool list. If you do not name them, people use whatever is free, and free means you are the product.
2. What data can go in. Three buckets is enough. Green is public: marketing copy, general questions. Yellow is internal and dull: drafts, process notes. Red never goes in: social security numbers, bank details, health records, signed contracts, anything a client gave you in confidence.
3. What happens when red data goes in anyway. Not "do not do it." Who you tell, how fast, and what they do next.
Everyone skips this section. It is the only one that matters at four o'clock on a Friday.
4. How someone gets a new tool approved. If there is no path to yes, people route around you quietly, and now you have a policy and no idea what anyone is using.
Two things worth stealing rather than writing
The NIST AI Risk Management Framework is free, and it is the vocabulary your larger clients use in vendor questionnaires.
And your cyber insurance carrier may already have a template. Ask them first, because theirs is the one that has to satisfy a claim.
How transparent to be with customers
Someone at the same forum asked how open to be about any of this. Split it in two.
What you do with their data: tell them in writing, before they ask. If you sell to a larger company, your contract almost certainly has a confidentiality clause that predates AI and does not care that the tool is new. That exposure was created the day you signed, not the day somebody pasted.
Whether you use AI at all: disclose it where it would change their decision. Nobody discloses their word processor. If AI is producing a recommendation your client will act on, say so.
The test is one line. Would this client feel misled if they found out how it was made?
Go write the page
Draft it with AI if you like. But hand it those four headings first, because that part it cannot know about your business.
By Hand or By AI Is the Wrong Question
A designer with twenty years of depth quit AI because the output looked like a template. He was right about the output, wrong about the conclusion.
ReadWhat Claude's Text Watermark Actually Does, and What It Cannot Do
Crawlers cannot read Claude's text watermark, and retyping does not remove it. What it is, who can read it, and why it changes nothing.
ReadStop Waiting for the Green Light. Build the Alarm Instead.
Nobody is coming to say AI is allowed. What owners actually want is to find out their automation broke before a customer does.
ReadWorking on something like this?
Bring the app or the process to a free 15-minute call. I will tell you what I would look at first, and whether I am the right person for it.