Course resource
Team AI Policy Checklist
Rolling out AI across a team without creating either a free-for-all or a policy everyone ignores.
Before writing anything
- Find out what is already happening. People are using AI already, usually on personal accounts. Ask without threatening — you need honest answers more than you need compliance today.
- Name the actual risk you are managing. Data leakage? Wrong output reaching customers? Regulatory exposure? Quality? The answer shapes everything.
- Decide who owns this. A policy without a named owner is a document, not a control.
The sequence that works
Provision before you restrict. This is the single most important sequencing decision.
A policy that bans the tools people need, without providing approved alternatives, moves usage underground. You end up with less visibility than before you wrote anything. Approve and provision at least one good tool first, then restrict.
1. Approve and provision a tool
2. Write the policy
3. Train people
4. Then enforce
Writing it
- Data classification — what may go where. Without this, no other rule is enforceable.
- Approved tools list, with what each is approved for
- A short "never" list — credentials, customer personal data, decisions about people
- Human accountability — the sender owns the output
- Disclosure rules — when the audience must be told
- How to request a new tool — make this easy or people route around it
- How to report a mistake — and an explicit statement that prompt reporting is not punished
- Named owner and review date
Keep it to two pages. A twelve-page policy is read by nobody and followed by fewer.
Rolling it out
- Run a session, do not just email it. Questions in the room surface the cases you did not think of.
- Give concrete examples, not principles. "You may paste a draft blog post. You may not paste a customer list." People need the line drawn, not described.
- Say what is now allowed, not only what is forbidden. Most teams find a policy liberating if it tells them what they can do.
- Name the person to ask. Every policy generates edge cases in week one.
What to measure
Not usage. Usage is not the goal and measuring it makes people defensive.
| Signal | What it tells you |
|---|---|
| Tool requests coming in | The process is trusted and being used |
| Incidents reported | People feel safe reporting — a rise here is usually good |
| Shadow tools discovered | The approved set is inadequate |
| Errors reaching customers | Whether the review step is real |
| Time saved, self-reported | Whether this is worth doing at all |
A rise in reported incidents is usually a good sign. It means people are telling you rather than hiding.
The failure modes
Banning without providing. Covered above; the most common and most damaging.
A policy nobody can apply. "Use good judgement with sensitive data" gives no one a decision rule.
No route for exceptions. Someone has a genuine need the policy did not anticipate. Without a process, they just do it.
Punishing honest mistakes. One public disciplinary for a self-reported error ends incident reporting permanently.
Writing it once. Tools change quarterly. A policy reviewed annually is out of date for nine months of the year.
Rules for staff, exceptions for leadership. The fastest way to make a policy decorative.
The exception process
Someone needs a tool that is not approved. Make this a five-day process, not a five-week one:
1. Request: what tool, what for, what data class
2. Assessment against your vendor checklist
3. Decision: approve / approve with limits / decline with a reason
4. If approved: provision centrally, add to the list, set a review date
5. If declined: say what they should use instead
Step 5 is not optional. A decline without an alternative is a request to break the rules.
Review
| Date | Tools added | Tools removed | Incidents | Policy changes |
|---|---|---|---|---|
Quarterly for the first year. The pace of change makes anything slower ineffective.
The honest framing
The goal is not to prevent AI use. It is to make sure that when it goes wrong — and it will — the damage is small, someone notices, and you find out. Every item on this checklist serves one of those three.