Purpose and scope
Who the policy applies to and what AI tools it covers.
A clear AI policy helps people understand what is allowed, what is prohibited, what requires approval and when human review is required.
It often happens because AI tools are easy to access, useful and fast. However, unapproved AI use can expose confidentiality, privacy, cyber security, intellectual property, accuracy and compliance risks.

Who the policy applies to and what AI tools it covers.
Which AI systems may be used for work and for what purposes.
When AI must not be used, including unlawful or high-risk purposes.
What information must never be entered into AI tools unless controls are approved.
When outputs must be checked before publication, decisions or customer communication.
How staff verify output and consider fairness.
How AI use is documented for important decisions or high-risk processes.
How staff report errors, privacy concerns, security issues or harmful outputs.
Minimum awareness training and policy review cycles.
If a tool is not approved, do not use it with work information. If the output affects a person, decision, customer, safety issue or legal obligation, a human must review it.