AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001 · Operating AI governance in a company · lesson 12 of 17 · 15 min
Writing an AI policy people actually follow
Why most AI policies fail
Two failure modes dominate. The ban policy ("do not use generative AI") drives use underground into personal accounts, where you have no visibility. The encyclopedia policy (40 pages of principles) goes unread. A good AI policy is short, specific, and paired with an approved-tools list and a way to ask questions.
The policy stack
| Layer | Length | Audience | Changes | |---|---|---|---| | AI policy (principles + accountability) | 1 to 2 pages | Everyone; signed by leadership | Yearly | | Acceptable use rules | 1 page | Everyone | Quarterly | | Approved tools list | Living table | Everyone | Monthly | | Standard operating procedures | Per process | Teams using AI in specific workflows | As needed |
What the AI policy must contain
- Purpose and scope: which people, entities, tools and use cases it covers (including AI inside existing software).
- Principles: for example human accountability, transparency, fairness, privacy and security, quality, legality. Keep them few and meaningful.
- Roles: executive sponsor, AI lead (or committee), system owners, data protection officer or privacy lead, security, and every user's responsibilities.
- Risk approach: how uses are classified (link to your inventory and the EU AI Act tiers), what needs approval, what is prohibited.
- Approval workflow: how someone requests a new tool or use case, and response times.
- Incident reporting: what counts as an AI incident and how to report it.
- Training: the AI literacy requirement by role.
- Review: owner and cadence.
Acceptable use rules: a traffic-light model
Green (allowed with approved tools): drafting and editing non-confidential text; brainstorming; summarizing public information; coding help on non-sensitive code; creating internal images.
Amber (allowed with conditions): client-facing content (human review and fact-check required); processing client or personal data (only in tools with a data processing agreement and training on inputs disabled); synthetic media of real people (written consent and labeling); customer-facing chatbots (approved design, disclosure, human handoff).
Red (not allowed): entering passwords, API keys or secrets; uploading special category data (health, religion, biometrics) without specific approval; making final decisions about people's employment, credit or access to services solely by AI; generating deceptive content, fake reviews or impersonations; using tools on the prohibited list; any Article 5 practice.
RACI for AI decisions
| Decision | Responsible | Accountable | Consulted | Informed | |---|---|---|---|---| | Approve new AI tool | AI lead | COO | Security, Privacy | Requesting team | | Classify a new use case | System owner | AI lead | Legal | Leadership | | Launch customer-facing AI | System owner | Department head | AI lead, Legal, Brand | Support team | | Respond to AI incident | System owner | AI lead | Security, Privacy, Comms | Leadership | | Annual policy review | AI lead | CEO | All department heads | All staff |
Worked example: a 15-person UK content agency
They replaced a one-line "use AI responsibly" rule with: a 1-page policy signed by the founders; a traffic-light acceptable-use page; an approved-tools table listing each tool, plan tier, whether client data is allowed, and whether training on inputs is disabled; a Slack channel for questions with a 48-hour answer promise; and a quarterly 30-minute review. Within a month, staff reported three previously unknown tools, two of which were moved to business plans with data protection terms.
Hands-on: draft your policy with an AI assistant, then edit
Act as an AI governance specialist. Draft a 1-page AI policy for [company], a [size]
[industry] business operating in [countries], serving clients in [markets].
Include: purpose and scope; 5 principles; roles (sponsor, AI lead, system owners,
privacy lead, all staff); risk approach referencing the EU AI Act tiers where EU users
are affected; approval workflow with response times; incident reporting; training by
role; review cadence. Plain English, no legal citations you are not sure of.
Then draft a 1-page acceptable-use page using Green / Amber / Red lists.
Edit ruthlessly. Replace every generic statement with something specific to how your team works. A policy that describes an imaginary company fails its first audit.
Approved tools table template
tool,plan_tier,approved_uses,client_data_allowed,personal_data_allowed,training_on_inputs,retention,dpa_signed,owner,review_date
Chat assistant (business plan),Team,"Drafting, research, analysis",yes,yes (no special category),disabled by contract,30 days,yes,AI lead,2026-12-01
Image generator,Pro,"Concept art, social visuals",no,no,check terms,n/a,no,Creative lead,2026-12-01
Meeting transcription,Business,"Internal and client calls with notice",yes,yes,disabled,90 days,yes,Ops,2026-12-01
Measuring success
- Percentage of staff completing AI literacy training.
- Number of shadow tools discovered and resolved per quarter (rising at first is good).
- Time to approve a new tool request.
- Incidents reported (zero reports usually means under-reporting).
Pitfalls
- Blanket bans that push use to personal accounts.
- No approved-tools list, so staff cannot follow the policy even if they want to.
- A policy with no owner or review date.
Video lecture: Writing an AI policy people actually follow
Lecture coming soon · 14 chapters · about 9 minutes. Read the full transcript below.
- AI policies that work
- Why policy design matters
- The policy stack
- Analogy: a travel policy
- Eight policy elements
- Traffic-light acceptable use
- Decision rights (RACI)
- Worked example: UK content agency
- Draft with AI, edit hard, measure
- Example 2: Karachi fintech (200 staff)
- Common mistakes
- Watch me do it: approved tools + policy edit
- Recap and next step
- Try this now: five steps
Lecture transcript
AI policies that work
Here's a pattern I see constantly. A company writes an AI policy that either bans generative AI, which pushes staff into personal accounts where nobody can see what's happening, or runs to forty pages that nobody reads. Neither protects anyone. In this lesson, you'll build a policy stack that people actually follow: a short policy, a traffic-light acceptable-use page, an approved tools list, and clear decision rights.
Why policy design matters
Why does policy design matter this much? Because a policy is the first thing clients, auditors and new staff read, and the thing that decides whether people use AI openly or in secret. A good policy increases safe adoption: people know which tools are approved, what data they can use, and who to ask. A bad one creates shadow AI, where you lose visibility entirely. The difference is rarely legal wording. It's clarity, brevity and whether the rules match how people actually work.
The policy stack
Think of it as a stack. At the top, a one to two page AI policy, signed by leadership, reviewed yearly. Under it, one page of acceptable-use rules, reviewed quarterly. Then a living approved tools list, updated monthly. And standard operating procedures for specific workflows, like content production or chatbot launches. Each layer changes at a different speed, which is why you separate them. You don't want to re-sign your policy every time a tool changes its pricing plan.
Analogy: a travel policy
Here's an analogy: an AI policy should work like a company's travel policy. Nobody reads a forty-page travel manual. What people actually use is a one-page summary, a list of approved booking tools, clear limits like economy for flights under six hours, and a named person to ask when something unusual comes up. The full rules exist, but day-to-day behavior is driven by the short version and the approved tools. Your AI policy stack works the same way.
Eight policy elements
The policy itself needs eight things. Purpose and scope, including AI features hidden inside tools you already use. A handful of meaningful principles. Clear roles: an executive sponsor, an AI lead, system owners, a privacy lead, and every user's responsibilities. Your risk approach and what's prohibited. An approval workflow with response times. How to report incidents. Training expectations by role. And an owner and review date. If you serve EU users, link your risk approach to the AI Act tiers.
Traffic-light acceptable use
For acceptable use, use traffic lights. Green: allowed with approved tools, like drafting non-confidential text, brainstorming, summarizing public information. Amber: allowed with conditions. Client-facing content needs human review and fact-checking. Personal or client data only goes into tools with a data processing agreement and training on inputs turned off. Synthetic media of real people needs written consent and a label. Red: never. No secrets or passwords in prompts. No final decisions about people's jobs or credit made solely by AI. No fake reviews, impersonation or deceptive content.
Decision rights (RACI)
Decision rights prevent chaos. Use a simple RACI. The AI lead is responsible for approving new tools, the operations director is accountable, and security and privacy are consulted. A system owner classifies each new use case, with legal consulted. Launching customer-facing AI needs the department head's sign-off, with brand and legal consulted. Incidents are handled by the system owner, with the AI lead accountable. And the CEO is accountable for the annual review. Write it down so nobody has to guess.
Worked example: UK content agency
Here's a fifteen-person content agency in the UK. They replaced a vague use AI responsibly line with a one-page signed policy, a traffic-light page, and an approved tools table showing each tool's plan, whether client data is allowed, and whether training on inputs is disabled. They opened a chat channel for questions with a forty-eight hour answer promise. Within a month, staff flagged three tools nobody knew about, and two were moved onto business plans with proper data terms. That's governance working: visibility first, then control.
Draft with AI, edit hard, measure
You can use AI to draft your policy. The lesson text includes a prompt that produces a one-page policy and a traffic-light page. But then edit ruthlessly. Replace every generic sentence with something specific to how your team actually works. Auditors and clients test what you do, not what you wrote. Then measure: training completion, shadow tools discovered, time to approve new tools, and incidents reported. And remember, zero incidents reported usually means under-reporting, not perfection.
Example 2: Karachi fintech (200 staff)
A second, bigger example. A two-hundred-person bank-adjacent fintech in Karachi can't use the same lightweight approach as a small agency. Their stack adds an AI committee with risk, legal, security and business members; a formal approval workflow with a two-week service level; mandatory impact assessments for customer-facing AI; and quarterly reporting to the board's risk committee. But the principle is the same: a short policy people actually read, a traffic-light page, a living tools list and clear decision rights. The size of the controls grows with the risk, not the thickness of the document.
Common mistakes
Common mistakes. Blanket bans that push people into personal accounts. No approved tools list, so staff can't follow the policy even if they want to. A policy with no owner and no review date, so it quietly goes stale. And rules that don't match reality, like banning a tool the whole sales team depends on. When you find a mismatch, fix the policy or fix the practice, but don't leave the gap open.
Watch me do it: approved tools + policy edit
Watch me do it. I open the Approved tools tab and fill it from the register. Columns: Tool, Plan tier, Approved uses, Client data allowed, Personal data allowed, Training on inputs, Retention, Processing agreement signed, Owner, Review date. The chat assistant on the team plan: approved for drafting, research and analysis; client data yes; personal data yes but no special category; training disabled by contract; thirty days retention; agreement signed; owner AI lead; review in December. The image generator on a pro plan: approved for concept art and social visuals; client data no; personal data no; training on inputs, I check the terms, it's on by default, so I note: never upload client assets. The email-rewriting browser extension someone reported: no processing agreement and unclear terms, so status: not approved, and I suggest the approved chat assistant instead. Next, I open the policy draft from the prompt and replace one generic line, use AI responsibly, with a concrete one: client-facing content needs human review and a fact-check before sending. Then the traffic-light page goes on one side of A four.
Recap and next step
Recap. Skip bans and encyclopedias. Build a stack: a short signed policy, a traffic-light acceptable-use page, a living approved tools list, and workflow procedures. Assign decision rights with a RACI, and measure whether it's working. Your next step: fill in the approved tools table from the lesson text for the tools on your inventory, and draft your one-page policy using the prompt. Then book a thirty-minute review with leadership to sign it.
Try this now: five steps
Here's exactly how to try this now. Step one: list every AI tool on your inventory in the approved tools table, with plan tier, whether client data is allowed and whether training on inputs is disabled. Step two: run the drafting prompt from the lesson text with your company's details. Step three: edit the draft line by line, replacing anything generic with how your team actually works. Step four: put the traffic-light rules on one page. Step five: book thirty minutes with leadership to sign it, and set a review date six months out.
Key takeaways
- Effective AI policy is a stack: short signed policy, one-page acceptable-use rules, a living approved-tools list, and workflow SOPs.
- Traffic-light rules (green, amber, red) make acceptable use concrete; red covers secrets, sole-AI decisions on people and deception.
- A RACI clarifies who approves tools, classifies uses, launches customer-facing AI and handles incidents.
- Measure training completion, shadow tools found, approval time and incident reports.
Try it
Fill in the approved-tools table for every tool in your inventory, then draft a one-page AI policy and traffic-light page using the prompt. Book a leadership sign-off.