Free resource · Template
AI usage policy for small teams
With no policy, everyone on the team quietly invents their own — the boldest overshare and the most careful miss out. Here is a one-page policy you can adapt in an afternoon, with the reasoning behind every line.
Free, and free of a catch. See the whole library.
Why one page, and why now
The risk in most small teams is not that AI is used — it is that it is used invisibly, each person guessing at the rules. A policy fixes that only if people can hold it in their heads at the moment of pasting, which rules out anything longer than a page. The whole thing reduces to three zones and a named human.
The policy — copy, then adapt
This is the template. Copy it, fill the brackets, and read the reasoning below before deleting anything — every line is there because its absence causes a specific problem.
AI use at [COMPANY] — the one-page version
1. Use AI freely for: drafting and improving our own writing, explaining unfamiliar material, planning and thinking, and anything already public.
2. Strip identifying details first for: anything containing client or staff names, contact details, account numbers, or commercial terms. Swap them for placeholders before pasting; put the real details back outside the tool.
3. Never paste: passwords or keys, card or bank details, anything under an NDA, or health, legal or personal records tied to a named person.
4. Use the approved tools — [LIST THEM] — on work accounts only. No personal accounts for work material.
5. You own what you send. AI output is a draft: check the facts, names and numbers before anything leaves the team.
6. Not sure which zone something is in? Ask [NAME]. The answer is not 'no' by default.
Last reviewed: [DATE]The reasoning, line by line
A policy you can defend beats a policy you can only enforce. Here is why each clause is there — and what quietly goes wrong when it is removed.
- 1Clause 1 exists because a policy that only forbids teaches people to hide their AI use — and hidden use is where the real risk lives. Saying plainly what is fine brings the practice into daylight.
- 2Clause 2 is the middle zone, and it is the load-bearing one: most 'sensitive' work is perfectly safe once names and numbers are swapped for placeholders. Without this zone, people face a false choice between oversharing and abstaining — and pick one at random.
- 3Clause 3 is short on purpose. A short absolute list gets remembered at the moment of pasting; a long one gets skimmed once and ignored forever. Everything here is unsalvageable once shared — no redaction rescues a password.
- 4Clause 4 is about where the safety settings live: work accounts can have training toggles, history and data controls set once, centrally — instead of hoping each person found the right switch in a personal account.
- 5Clause 5 is the accountability line that makes the freedom in clause 1 workable. The tool drafts; a person sends; the person answers for it. No 'the AI got it wrong' defence — which, said out loud up front, is fair.
- 6Clause 6 is the disclosure valve. An approachable named human beats a form nobody fills in — and 'not no by default' is what makes people actually ask instead of guessing quietly.
Rolling it out without theatre
How the policy arrives decides whether it is followed. Three things, in order.
- 1Introduce it in ten minutes at a team meeting, not by email attachment. The point of one page is that it can be read aloud.
- 2Amnesty first, rules second: ask what people already use AI for before the policy takes effect, with no comeback. You will learn more in that conversation than any audit would find — and the answers tell you whether your zones match reality.
- 3Put a review date on it and honour the date. Tools and rules are moving; a policy last touched two years ago reads as abandoned, and abandoned policies get ignored wholesale.
The simplest rule of all
A policy works when someone can recall it in the half-second before pasting. One page, three zones, one named human to ask. If your version has grown past that, it has stopped being a policy and become a document — cut it back until it fits in a head again.
More like this, as we write it.
The library is still filling. Start free and we will tell you when the next resource ships — one email, no spam.
Start free