What belongs in a Responsible AI policy (and what doesn't)
Most AI policies are either too vague to follow or too strict to survive contact with reality. Here's the structure we use with clients.
We've reviewed a lot of "AI policies" that are really just a page of legal disclaimers nobody reads, sitting in a folder nobody opens. A policy that doesn't change behaviour isn't doing its job, and it won't hold up well if a regulator or client ever asks to see it in action. Here's what we think a working Responsible AI policy actually needs, and what's better left out.
What belongs in it
An approved tools list. A short, living list of which AI tools are approved for use, for what purposes, and who owns the decision to add new ones. This is the single most useful section, because it answers the question employees actually have: "can I use this?"
Data handling rules. Plain guidance on what kinds of information can and can't be entered into AI tools, particularly client data, personal data, and confidential business information. This should be specific enough to apply to real situations, not just "use good judgement."
Human oversight requirements. Where AI output feeds into decisions that matter (hiring, contracts, financial commitments, anything client-facing), the policy should state plainly that a human reviews and is accountable for the final output.
How to raise concerns. A simple route for staff to flag something that seems wrong: an AI tool producing biased, inaccurate, or unsafe output, or a new tool someone wants to start using. If this route doesn't exist, issues surface later and more expensively.
Review cadence. A commitment to revisit the policy and the tools list on a regular schedule. This is what keeps the document from going stale the moment it's published.
What doesn't belong in it
An exhaustive list of every possible risk. A policy that tries to anticipate every conceivable misuse becomes unreadable, and unreadable policies get ignored. Cover the realistic risks for your business, not every risk in the abstract.
Legal boilerplate with no operational meaning. If a clause doesn't translate into something an employee can actually do differently, it's filler. Filler erodes trust in the rest of the document.
Blanket bans that everyone quietly ignores. A policy that says "no AI tools" when staff are already using them off the books is worse than no policy. It creates a gap between what's written and what's real, which is exactly what an audit or incident will expose.
The test
A good way to check whether a policy is working: ask three people in different roles what it says they can and can't do. If they can answer in a sentence or two, it's doing its job. If they shrug, it needs work, regardless of how thorough it looks on paper.
Need a policy that people will actually use?
Book a free intro call, we'll talk through what a working policy looks like for your business.
Book your intro call