A signed two-page AI usage policy on a desk.
Governance

An AI usage policy people actually follow.

Most AI policies fail for the same reason: they are 20-page documents nobody reads, written for self-protection rather than for work. The one that works fits in two pages and answers three questions: which data, which tools, who decides.

2 pages, not 20Plain languageTemplate available

The four decisions it contains

01

Data classification

Three levels are enough: what can enter any approved tool, what only enters the controlled environment, and what never enters AI at all.

02

Approved tools

A short, living list: what is approved, for which cases, and what is explicitly forbidden — including free personal accounts.

03

Allowed and vetoed cases

Concrete examples from each area's real work. People don't break rules out of malice: they break them because nobody told them what is allowed.

04

Exceptions and an owner

Who decides when something isn't on the list, how fast they answer and how it is recorded. Without an owner, a policy is decoration.

01

Why long policies fail

Because they optimize the wrong thing. A policy written for the worst legal scenario produces employees who stop asking and use AI in hiding — the very risk it meant to prevent, multiplied. A short policy, with examples from real work and a fast exception lane, produces the opposite: people who ask before pasting. The goal is not to cover yourself; it is that on Monday at 9:00 anyone knows what to do.

02

From policy to system

Paper controls nothing: rules have to live where work happens. So every rule in the policy has an operational mirror — data classification becomes permissions and keys, the tool list becomes granted or blocked access, and the records become a panel leadership can review. That translation is exactly what we do in the diagnostic and the implementation.

  • The policy is drafted with leadership, IT and legal at the same table.
  • Each employee receives it through the Passport training, not a mass email.
  • It is reviewed quarterly: new tools enter, dead rules leave.
03

Request the base template

We condensed the structure into a template you can adapt internally: the sections, the three data levels and the exception flow, with usage instructions. We send it by email — just tell us what your company does so we send the variant that fits best.

Questions before starting

The point is choosing the right level of control.

Does the template have a cost?

The base template is free. It helps your team see the minimum structure of a usable policy; if while adapting it you need help with data classification or internal enforcement, we can review the case with you.

Does a policy protect us legally?

An enforced, documented policy is evidence of diligence, and that carries weight — with regulators, clients and insurers. But the legal opinion belongs to your counsel: we make whatever they rule executable.

What if we already have an AI policy?

Perfect: the diagnostic evaluates it against real usage. The usual gap is not in the document but between the document and what people do daily. That distance is measurable, and we measure it.

Start with the template. Or with the 30 minutes.

Request the base template by email, or book a call and we tell you what your current policy is missing to actually work.

Request the template