For anyone writing a policy people will actually read
Writing an AI policy: what belongs in it and how to get there
An AI policy isn't a legal document destined for a drawer. It answers four questions your people already have today: which tools may we use, what data may go into them, who decides what, and what do we do when something goes wrong.
Plan an introductionThe starting point
A policy people actually read
Most AI policy documents are written to cover a risk, not to answer a question. They are long, legally phrased, and nobody can work with them in practice. A usable policy fits on a few pages and answers four questions your people already have today. The rest is commentary.
Our own AI policy is public on this site, including what we don't do. That is the clearest example of the length and tone we mean.
The content
Four questions it has to answer
If these four are clear, everyone knows enough to start. Whatever else it contains is useful, but not what the policy will be judged on.
Which tools may we use
A concrete list of names, not categories. It also needs to answer what happens when someone wants to try something new: who do you ask, and how long until you get an answer. Without that route a shadow list appears that nobody can see.
What data may go into them
This is the question people trip over daily. Work with a few clear categories and an example for each: this is always fine, this only in the protected environment, this never. Examples from your own work do more here than a definition.
Who decides what
Who approves a new tool, who reviews anything going outside, and who is approachable in case of doubt. Names or roles, not departments. A policy with no point of contact mostly generates questions that land nowhere.
What do we do when it goes wrong
At some point someone pastes something into a chat window that did not belong there. That happens. The question is whether they report it or keep quiet, and that depends entirely on what the policy says about the response. A reporting route without a punitive culture buys more safety than a strict ban.
The approach
How to build one that keeps working
The writing is the smallest part. It comes down to where the content comes from and whether the people who have to follow it had any say in it.
First look at what is already happening
Almost every organisation already uses more AI than management thinks. Start by openly asking what people use and what for, with no consequences attached. That produces the real list the policy needs to be about.
Write it with the people it affects
A policy written in a boardroom reads like something happening to you. A few sessions with the teams working with it daily produce sharper rules and make the document recognisable when it circulates.
Make it a working version, not a final one
The landscape moves faster than an annual policy cycle. Put a date and an owner on it, and agree when you will look again. A policy with a review date gets updated; one without gets replaced once nobody believes it any more.
Where this lands
If you'd rather not write it yourself
The policy engagement
A policy manifesto covering approved tools, data classification, responsibilities and escalation, plus a one-pager people actually keep on their desk. From 5,000 euro.
The training underneath
A policy nobody knows changes nothing. The foundation module covers exactly these topics with the people who have to work with it, and counts towards the AI literacy the AI Act asks for.
The direction above it
Policy sets the boundaries for doing it safely; strategy determines what you focus on and in what order. They are often picked up together.
When you're not ready for this yet
- Is AI not in use anywhere yet? Then you are writing policy for a situation you do not know. Start with where it could actually help, and write the policy once you know what it is about.
- Is there already an information security policy that covers AI properly? Then a separate AI policy is mostly extra paper. Usually a short addendum and a good explanation is enough.
A human approves what goes out, client data only with permission, minimal permissions for agents, and European infrastructure where possible.
This is what a policy short enough to remember looks like. View our AI policy
Frequently asked questions
01 Is an AI policy legally required? +
The EU AI Act does not prescribe a policy document as such. It does set requirements for how organisations deploy AI and for employees' AI literacy. A clear policy is the practical way to meet that and to show it is covered.
02 How long should such a policy be? +
Short enough to read in a coffee break. In practice that means a few pages, plus a one-pager with the essentials people keep to hand. Anything longer becomes a document you look up rather than know.
03 Can we use a template from the internet? +
As a starting point for the structure, fine. The hard part is always left blank by a template, because that is exactly the part about you: which tools you use, what data you process and who decides. A filled-in template without that conversation produces a document that is formally correct and steers nothing.
04 What does it cost to have this done? +
Our policy engagement starts from 5,000 euro, including the sessions with the teams, the manifesto and the one-pager. What it ends up costing depends on the size of the organisation and whether there is something to build on.
05 How often should we update it? +
Twice a year is workable for most organisations, with an interim change when a tool is added or dropped. Put the review date in the document itself, so it becomes an agreement rather than an intention.
Policy your people will actually use?
We look together at what is already there and what is needed.