← All FAQs
AI

Do I need an AI use policy?

Yes, and this is genuinely true regardless of whether your business has made any formal, deliberate decision to "adopt AI." If your staff have internet access (essentially every business today), they are almost certainly already using AI tools in some form, which means you already have AI-related risk exposure today, whether or not there's a policy governing it.

Why "We Haven't Adopted AI" Is Rarely Actually True

Even without any formal, top-down decision, individual employees routinely adopt AI tools independently for drafting emails, summarising documents, research, and problem-solving. This organic, bottom-up adoption happens regardless of whether leadership has made a deliberate decision about it, meaning the realistic question isn't "should we allow AI," it's "how do we govern AI usage that's already happening."

What Happens Without Any Policy at All

  • No consistency in which AI tools are used, staff choosing whatever's personally familiar or convenient, often free consumer-tier tools with less favourable data handling terms
  • No guidance on what data is appropriate to enter, leaving individual staff members to make inconsistent, often incorrect judgment calls
  • No audit trail if a client, auditor, or regulator ever asks how AI is being used with their data, "we don't have a policy" is not a defensible answer
  • No accountable owner if an AI-related incident occurs, no clear individual responsible for AI governance within the business

What a Genuinely Useful Policy Actually Contains

Effective AI policies are specific and practical rather than vague, general statements. Rather than "use AI responsibly," a useful policy specifies: which tools are approved (ideally verified business/enterprise tiers with appropriate data protection terms), specific categories of data that must never be entered into any AI tool, and clear escalation guidance for situations that don't neatly fit the defined rules.

Policy Alone Isn't Sufficient

A written policy that's never actually communicated to staff, or communicated once and then forgotten, provides limited genuine protection. Meaningful governance includes staff training with signed acknowledgement (creating a genuine record that the policy was communicated and understood), and periodic review as both your business's AI usage and the broader regulatory landscape continue to evolve.

Who Should Actually Own This

A named, specifically accountable owner, not necessarily requiring deep AI technical expertise, but genuinely responsible for maintaining and enforcing the policy, matters more than the technical sophistication of the policy document itself. Diffuse, unowned responsibility is precisely how AI governance quietly fails in practice, everyone assumes someone else is handling it.

Getting Started Without It Becoming an Overwhelming Project

A practical starting policy doesn't need to anticipate every conceivable AI scenario, it needs to cover the most common, realistic situations clearly, with a defined process for handling genuinely novel situations as they arise, rather than delaying any policy at all until an impossibly comprehensive document is ready.

Our Approach

We help build a practical, specific AI use policy grounded in your business's actual current usage (discovered through the GovernAI risk assessment phase), with staff training and a named governance owner, so you have genuine, demonstrable governance in place rather than an unaddressed, invisible risk.