Template

Executive AI Policy Template

A starting structure for an internal AI usage policy. Copy these sections into your own document and fill in the specifics for your organization — this isn't legal advice, and a policy handling sensitive or regulated data should get a legal review before it's finalized.

1. Purpose

State plainly why the policy exists: to enable staff to use AI tools productively while protecting company and customer data, and to set expectations for when human review is required.

2. Approved Tools

List which AI tools are approved for use, and note that new tools require approval before use. Include how staff can request a new tool be reviewed.

3. Acceptable Use

Define what AI tools can be used for (drafting, research, summarization, coding assistance) and where extra caution applies (anything customer-facing, anything involving a final decision affecting a person).

4. Data & Confidentiality

Be explicit about what data may never be entered into a public or non-approved AI tool — customer PII, financial data, unreleased plans, proprietary source code, anything covered by an NDA. Note which approved tools have data protection agreements in place, if any.

5. Human Oversight

State where AI output requires human review before use — client-facing communication, anything involving legal or financial judgment, any decision affecting an employee or customer.

6. Accuracy & Disclosure

Require staff to verify AI-generated factual claims before relying on them, and set expectations for whether/when AI use should be disclosed to clients or in deliverables.

7. Training

Note how staff will be trained on the policy and on using approved tools effectively, and how often training is refreshed.

8. Review Cadence

State how often this policy itself will be reviewed and updated — AI tools and risks change quickly enough that an annual review is usually a minimum, not a maximum.

Want help writing the real version?

AI Strategy engagements include policy and governance work tailored to your actual tools, data, and risk tolerance.