Key takeaways
- A team policy fits on two pages. If people cannot remember it, they will not follow it.
- Decide seven things: scope, approved tools, data rules, disclosure, verification duties, ownership and IP, and training. Everything else is boilerplate.
- The person who uses AI owns the output, including its errors. Verification is a duty, not a suggestion, and it belongs in writing.
- Start with a draft from the free AI policy generator, then spend your time on the three decisions only you can make: tools, data, and disclosure.
Why your team needs its own policy
A company-wide AI policy, if one exists, tells people what is forbidden. A team policy tells them what to do on Tuesday: which tool, which data, which checks, who signs off. If your team has neither, people are already using AI on personal accounts, quietly, without any of that. A two-page team policy fixes it in an afternoon.
This guide is for managers and is not legal advice; have HR or legal review what you write, especially in a regulated industry. The free AI policy generator drafts a policy from your answers, and the steps below explain the decisions behind each section so the draft is actually yours.
Three decisions only you can make
Everything else is boilerplate. These three are judgment calls that depend on your team; make them before you open a template.
- Which tools are approved, and for which data. With an enterprise plan this is easy; without one, decide whether to request a business-tier plan and what people may do meanwhile.
- What data is off limits, in terms a new hire can apply without asking. The red/yellow/green classification from AI privacy at work is the fastest way.
- When people must disclose AI use, to whom, and how. Teams disagree most here, and unstated expectations cause the most resentment.
Step 1: scope
State who and what the policy covers.
- People: everyone on the team, including contractors and interns, on any device used for work.
- Tools: chat assistants, meeting recorders, writing aids, image and video generators, code assistants, and the AI features inside software you already use (email, CRM, office suites). The last category is the one people forget.
- Work: anything produced for the company or on its behalf, whether or not it leaves the building.
Keep the scope broad and the rules short. A policy that lists ten tools by name is stale in a quarter; one that says "approved tools are listed at [LOCATION], maintained by [OWNER]" survives.
Step 2: approved tools
Sort tools into three tiers and keep the list somewhere anyone can find in five seconds.
- Tier 1, approved for all permitted data: the company's enterprise or business plan, with training excluded by contract, single sign-on, and admin controls. Name the plan, not only the vendor.
- Tier 2, approved for green data only: consumer accounts of major assistants, used with training turned off, for public information and general work.
- Tier 3, not approved: anything not on the list, including unreviewed browser extensions, free summarizer websites, and meeting bots. Include a simple way to request a review.
If you have no Tier 1 tool, say so, make all work use Tier 2 until one exists, and send IT the request; the privacy guide includes a template email.
Step 3: data rules
Adopt a three-color classification and give examples from your own team's work, because examples are what people remember.
- Red, never in any AI tool without written approval: personal data about customers or employees, credentials, unreleased financials, legal matters, source code, anything under NDA, and any category regulated in your field (health information, financial account data, student records, privileged material).
- Yellow, Tier 1 tools only, or anonymized first: internal documents without personal data, plans, notes, pipeline data with names removed.
- Green, any approved tool: public information, general writing, learning.
Add the anonymization steps (replace names with roles, remove identifiers and metadata, blur specific numbers) as a short checklist, plus one sentence that overrides everything: when in doubt, do not paste it; describe it instead.
Step 4: disclosure
Decide three things and write each as one sentence.
- Internal disclosure: when a colleague or manager should be told that AI was used. A reasonable default: no announcement for help with drafts, formatting, or summaries; mandatory disclosure when AI produced the substance of analysis, recommendations, or numbers, so the reviewer knows what to check.
- External disclosure: when customers, clients, or the public should be told. Client-facing deliverables, published content, and anything a person would reasonably assume a human did deserve a clear rule. In some fields and jurisdictions disclosure is required; ask legal.
- Recording disclosure: meeting recorders and transcription tools must be announced to everyone on the call and turned off on request. Recording consent laws vary by state, so make this an unconditional rule.
The wrong answer is silence: half the team will assume disclosure is expected and quietly judge the other half.
Step 5: review and verification duties
Write this sentence into the policy verbatim: the person who uses AI to produce work owns that work, including its errors. Then set minimum checks by output type.
| Output type | Minimum check before it leaves your hands |
|---|---|
| Internal draft, email, summary | Read the whole thing; verify any name, date, or number |
| Anything with numbers | Reconcile every figure to the source |
| Anything with citations or references | Open each one and confirm it says what the output claims |
| Customer, legal, HR, or regulatory content | Human review by the accountable owner, plus the normal approval path |
| Code and automations | Test in a safe environment; review before it touches production data |
Add a reminder of how these tools fail: confident wrong answers, invented sources, stale knowledge, arithmetic slips, and bias in judgments about people. How to fact-check AI output is the training material.
One rule deserves its own line: AI must not make decisions about people (hiring, performance, discipline, credit, eligibility) without a human making the call and able to explain it. Several jurisdictions regulate automated decisions in employment and lending, and this is where legal and reputational risk concentrates.
Step 6: ownership and IP
Four points, stated plainly.
- Work product made with AI on company time belongs to the company, like any other work product.
- Do not paste third-party material you do not have rights to use (licensed content, a competitor's documents, a partner's confidential files) into any tool.
- Do not use AI to generate content that imitates a specific living artist, writer, or brand, or that reproduces someone else's logo or likeness.
- Copyright protection for purely AI-generated material is limited. In the US, the Copyright Office has taken the position that material generated entirely by AI without meaningful human authorship is not eligible for copyright, and the details are still developing. If owning a creative asset matters (a logo, a campaign, a product name), get a person substantially involved in creating it and talk to legal.
Step 7: training
A policy nobody has been taught is a document, not a practice.
- A 30-minute onboarding session for everyone, covering the three decisions, the data colors with your team's own examples, and the verification table. Record it for new hires.
- A shared prompt library with the team's proven prompts and their checks. The site's prompt library is a starting point; your own wins are better.
- A named champion who answers questions, maintains the approved-tool list, and collects what is working.
- A quarterly 15-minute refresh, attached to a meeting that already exists: what changed in the tools, what went wrong, what to add.
- Your own example: use the Tier 1 tool visibly, disclose as the policy says, and report your own first mistake.
If you operate in the EU, the EU AI Act includes an obligation to ensure that staff who use AI systems have a sufficient level of AI literacy. Training is not optional there, and it is a good idea everywhere.
Step 8: exceptions, incidents, enforcement, and review
- Exceptions: who can grant one, how to ask, and how long it lasts. Make it easy; a painful exception process is how shadow AI starts.
- Incidents: what to do if someone pastes red data by mistake. Report it, delete the chat, tell the champion, and fix the process rather than punishing the honest person.
- Enforcement: what happens on repeated or reckless violations, consistent with existing company policy. Keep it proportionate.
- Review: the policy gets a version number and a date, and a review every six months or sooner when tools or laws change.
A worked example: a 12-person marketing team
Picture a marketing team at a software company with no company-wide policy, where the manager has noticed three people using personal ChatGPT accounts for campaign copy.
She makes the three decisions first. Tools: a business-tier plan requested from IT and, until it arrives, Tier 2 rules for consumer accounts with training off. Data: red is customer lists, unreleased launch dates, pricing, and anything from the CRM; yellow is briefs and drafts with customer names removed; green is published content and general brainstorming. Disclosure: nothing required for drafts and edits; any AI-generated statistic, quote, or claim is flagged to the reviewer; nothing AI-generated goes out as the words of a real person.
Her verification rules: every statistic in published content links to a source a human opened, product claims are checked against current documentation, and AI-generated images are labeled internally and never depict real people. Training is a 30-minute session on the team's own examples, a shared prompt library, and one champion. Three weeks later the personal accounts are gone, the library has 14 prompts, and the first data incident (a customer name pasted into a consumer tool) is reported within the hour and becomes a new training example.
The fill-in template outline
Copy this into a document and fill in the brackets. The AI policy generator will produce a draft along these lines from a short questionnaire.
- Purpose and scope. This policy covers [TEAM NAME], including [CONTRACTORS / INTERNS], for all work-related AI use on any device. Owner: [NAME]. Version [NUMBER], dated [DATE].
- Approved tools. Tier 1 (all permitted data): [PLAN NAMES]. Tier 2 (green data only): [CONSUMER TOOLS, TRAINING OFF]. Tier 3 (not approved): everything else. Request a review via [PROCESS].
- Data rules. Red (never without written approval): [YOUR EXAMPLES]. Yellow (Tier 1 only, or anonymized): [YOUR EXAMPLES]. Green (any approved tool): [YOUR EXAMPLES]. Anonymization checklist: [STEPS]. When in doubt, describe, do not paste.
- Disclosure. Internal: [RULE]. External: [RULE]. Meetings and recordings: announce every time, stop on request.
- Review and verification. The user owns the output. Minimum checks: [TABLE]. AI does not make decisions about people without a human owner who can explain the decision.
- Ownership and IP. The company owns work product. No unlicensed third-party material as input. No imitation of specific artists, brands, or people. Creative assets that must be owned get human authorship and legal review.
- Training. Onboarding session: [WHEN]. Prompt library: [WHERE]. Champion: [NAME]. Refresh: [CADENCE].
- Exceptions, incidents, and enforcement. Exceptions via [PROCESS]. Incidents: report to [NAME] within [TIME]; no penalty for honest reporting. Repeated or reckless violations handled under [EXISTING POLICY].
- Review. Next review date: [DATE].
A prompt to draft your first version
Use it in an approved tool. Nothing here requires confidential input.
Act as an experienced operations leader who writes practical, two-page AI use policies for small teams in plain language. You are not a lawyer; flag anything that needs legal or HR review.
Draft a team AI policy for:
- Team: [TEAM NAME AND FUNCTION], [NUMBER] people, at a [COMPANY SIZE] [INDUSTRY] company.
- Approved tools: [LIST TOOLS AND PLAN TYPES, OR SAY NONE YET]
- Regulated data we handle, if any: [FOR EXAMPLE HEALTH INFORMATION, FINANCIAL ACCOUNT DATA, STUDENT RECORDS, OR NONE]
- Our decisions: internal disclosure rule [YOUR RULE]; external disclosure rule [YOUR RULE]; meeting recording rule [YOUR RULE].
- Typical outputs: [FOR EXAMPLE CUSTOMER EMAILS, REPORTS WITH NUMBERS, PUBLISHED CONTENT, CODE]
Structure the policy with these numbered sections: purpose and scope; approved tools in three tiers; data rules using red, yellow, and green with examples drawn from our work; disclosure; review and verification duties with a table of minimum checks by output type; ownership and IP; training; exceptions, incidents, and enforcement; review cadence.
Constraints: under 900 words, second person, no jargon, every rule written so a new hire could apply it without asking. Include one sentence stating that the person who uses AI owns the output and its errors. End with a short list of items to confirm with legal or HR.
If any of my inputs are missing or unclear, ask me up to five questions before drafting.
Next steps
- Generate a first draft in minutes with the free AI policy generator.
- Base the data rules on AI privacy at work.
- Make verification a skill rather than a slogan with How to fact-check AI output and AI hallucinations explained.
- Learn the vocabulary your legal team will use: workplace AI policy, AI governance, responsible AI, and human in the loop.
- Roll the policy into onboarding with the hiring and management prompts, and see the AI for operations managers playbook for team-level workflows.
Frequently asked questions
Do we really need an AI policy for a small team?
Should we ban AI tools until we figure it out?
Who should approve a team AI policy?
Do employees have to disclose when they use AI?
How often should we update the policy?
Keep going
AI privacy at work: what happens to what you paste
Where your pasted text goes, how consumer and enterprise AI plans differ, a red/yellow/green data test, and how to ask IT for an approved tool.
SafetyHow to fact-check AI output: a step-by-step process
A step-by-step process for verifying AI-generated facts, numbers, quotes, code, and citations, with prompts that make the model show sources and doubt.
FundamentalsHow to use AI at work: a practical operating manual
An operating manual for using AI at work: pick a tool, learn five daily use cases, prompt well, verify output, protect data, and follow a 30-day plan.
FundamentalsAI hallucinations explained: why models make things up and how to catch it
What AI hallucinations are, why models invent facts, the situations where it happens most, and a verification checklist to run before anything ships.
Job playbookAI for Operations Managers
Operations managers live in SOPs, incident reports, staffing plans and spreadsheets, which is the material AI handles best. Here is how to use it to get your week back, and where the line is for safety and people decisions.
Job playbookAI for HR Professionals
First drafts of policies, announcements, and survey analysis in minutes, with employee data and employment decisions kept where the law and your judgment say they belong.
Job playbookAI for Project Managers
AI cannot run your project, but it can draft the status report, turn a messy meeting into an action list, and pressure-test your risk register in minutes. Here is how project managers use it without losing the plot.
Job playbookAI for Small Business Owners
AI answers the one-star review calmly, drafts the month of posts, turns your voice memo into an SOP, and preps the questions for your CPA. You still make the calls, sign the checks, and own what goes out under your name.
Job playbookAI for Marketers
Draft campaigns faster, mine customer feedback for messaging, and turn reporting into a ten-minute job, without drifting off-brand or into a CAN-SPAM problem.