MODULE 7 · LESSON 1

Free — no login required

Sign in to track progress, save quiz attempts and enrol in the full course.

Sign in to track progress / enrol

An AI Policy People Actually Follow

Why most AI policies fail

They are written to protect the organisation from every conceivable misuse, which makes them long, abstract and full of terms like "appropriate" and "as necessary". Nobody reads them, and the ones who do cannot tell whether a specific thing they want to do is allowed.

A policy that does not decide cases is not a control. It is documentation of intent.

Meanwhile the actual behaviour continues — the shadow AI use from module 1 — because people have work to do and the sanctioned route is either absent or worse than the alternative.

The one page

Cover five things, concretely.

1. What you must never put into a general-purpose AI tool. A short, literal list. Not "confidential information" — that is a category people argue with. Something like: customer personal data, anything under NDA, credentials or access keys, unreleased financial results, identifiable information about a colleague's performance, health or conduct.

Six concrete items beat two pages of principles, because people can hold six items in their head while working.

2. What is fine, explicitly. Policies that only prohibit teach people the tool is dangerous. Say plainly that drafting, summarising public material, rewriting your own text, brainstorming and code assistance in a sanctioned environment are all fine. This is what makes the list in point 1 credible.

3. What always needs a human before it leaves. Anything reaching a customer, a regulator, a court, a public channel, or a decision about a person. Name the categories rather than gesturing at importance.

4. Which tools are sanctioned, and for what. With a route to ask about a new one that returns an answer in days rather than a quarter. A slow approval route is functionally a prohibition, and it produces shadow use.

5. Who to ask, and who decides. A name or a role. "Contact the AI governance forum" without saying who that is means nobody asks.

Absolute rules and judgement rules

Distinguish these explicitly, because conflating them is what makes policies unusable.

🔗 Match the Pairs
Never paste credentials or access keys into any AI toolDrop here
Never enter identifiable information about a colleague's conductDrop here
Customer-facing output requires human review before sendingDrop here
Whether this analysis is reliable enough to base a decision onDrop here
Whether to use AI assistance in preparing this document at allDrop here

Absolute rules should be few, unambiguous and never subject to a good reason. Everything else should say what to weigh, not what to do — because a policy that tries to pre-decide every judgement call becomes a document that gets ignored the first time it produces an absurd answer.

Approval proportionate to risk

Three tiers is usually enough, and the point is that most things fall in the first.

📅 Timeline
Use freelySanctioned tools, internal work, human reviews the output before it matters. No approval. This should cover the large majority of use.
Notify and recordAnything processing customer data, anything embedded in a business process, anything whose output goes to a customer with a human in the loop. Recorded in the inventory, reviewed periodically.
Approve before buildingAnything making or materially influencing a decision about a person, anything customer-facing without human review, anything in a regulated process, anything using sensitive categories of data.

The failure mode to avoid is putting everything in tier three. It creates a queue, the queue creates delay, and delay creates the workaround — which is now invisible to you.

Prohibition without provision

The most important principle in this lesson, and it generalises well beyond AI.

If you prohibit a capability people need to do their work and do not supply an adequate alternative, you do not eliminate the behaviour. You relocate it somewhere you cannot see, which is strictly worse: the same data exposure, none of the visibility, no ability to guide it, and no learning about what people actually need.

So the sequence is always: provide first, then prohibit the unsanctioned route. Not the other way round.

If you write nothing else, write this and circulate it. Adapt the specifics; keep the shape.

Using AI at [organisation] — the short version

Use the sanctioned tools for drafting, summarising, rewriting and thinking things through. That is encouraged, not merely tolerated.

Never put any of these into any AI tool: customer personal data, anything under NDA, passwords or access keys, unreleased financial figures, or identifiable information about a colleague's performance, health or conduct. These six have no exceptions.

Anything that goes to a customer, a regulator or the public gets read by a person first. You are responsible for what you send, exactly as you would be for anything you wrote yourself.

If AI helped you produce something and you have not checked the specifics — names, numbers, dates, quotes, citations — do not pass it on.

Want to use a tool that is not on the sanctioned list? Ask [named person]. You will get an answer within five working days.

That is under 200 words. It decides the overwhelming majority of real cases. It is memorable enough to influence behaviour at the moment of use, which is the only moment that matters.

The fourth paragraph is the one that prevents the most damage, because it targets the actual mechanism of harm. The risk is rarely that someone used AI; it is that a specific unchecked claim travelled onward with the organisation's name attached.

Two implementation notes. Circulate it as itself, not as an appendix to a longer document, or people will read the longer document's length and none of its content. And put a date on it, because a policy on AI written now will need revisiting, and an undated policy quietly becomes a policy nobody trusts.

Knowledge Check

Why does prohibiting unsanctioned AI tools without providing an adequate alternative make things worse rather than better?

📚 Flashcards1 / 6
Term

Why policies fail

Click to flip
Definition

Written to cover every conceivable misuse, so they are long, abstract and unable to decide a specific case. A policy that decides no cases is documentation of intent rather than a control.

Click to flip back
💡Key Takeaway

A policy that cannot decide a specific case is not a control. Write one page covering what must never be entered, what is explicitly fine, what always needs human review, which tools are sanctioned and who decides — with six literal red lines rather than categories people can argue with. Keep absolute rules few and let everything else be judgement scaled to consequence, and always provide an adequate sanctioned route before prohibiting the alternative.