Course resource

Team AI Policy Checklist

Rolling out AI across a team without creating either a free-for-all or a policy everyone ignores.

Before writing anything

The sequence that works

Provision before you restrict. This is the single most important sequencing decision.

A policy that bans the tools people need, without providing approved alternatives, moves usage underground. You end up with less visibility than before you wrote anything. Approve and provision at least one good tool first, then restrict.

1. Approve and provision a tool
2. Write the policy
3. Train people
4. Then enforce

Writing it

Keep it to two pages. A twelve-page policy is read by nobody and followed by fewer.

Rolling it out

What to measure

Not usage. Usage is not the goal and measuring it makes people defensive.

Signal What it tells you
Tool requests coming in The process is trusted and being used
Incidents reported People feel safe reporting — a rise here is usually good
Shadow tools discovered The approved set is inadequate
Errors reaching customers Whether the review step is real
Time saved, self-reported Whether this is worth doing at all

A rise in reported incidents is usually a good sign. It means people are telling you rather than hiding.

The failure modes

Banning without providing. Covered above; the most common and most damaging.

A policy nobody can apply. "Use good judgement with sensitive data" gives no one a decision rule.

No route for exceptions. Someone has a genuine need the policy did not anticipate. Without a process, they just do it.

Punishing honest mistakes. One public disciplinary for a self-reported error ends incident reporting permanently.

Writing it once. Tools change quarterly. A policy reviewed annually is out of date for nine months of the year.

Rules for staff, exceptions for leadership. The fastest way to make a policy decorative.

The exception process

Someone needs a tool that is not approved. Make this a five-day process, not a five-week one:

1. Request: what tool, what for, what data class
2. Assessment against your vendor checklist
3. Decision: approve / approve with limits / decline with a reason
4. If approved: provision centrally, add to the list, set a review date
5. If declined: say what they should use instead

Step 5 is not optional. A decline without an alternative is a request to break the rules.

Review

Date Tools added Tools removed Incidents Policy changes

Quarterly for the first year. The pace of change makes anything slower ineffective.

The honest framing

The goal is not to prevent AI use. It is to make sure that when it goes wrong — and it will — the damage is small, someone notices, and you find out. Every item on this checklist serves one of those three.

Back to dashboard