Comply · AI Governance

    How do we write an AI policy people actually read?

    Most AI policies are legal documents nobody on the team has opened. We write the one-page version that answers the questions people actually have, so it gets followed instead of ignored.

    Last reviewed:

    Sound familiar?

    • The current policy, if one exists, is a twelve-page PDF written for lawyers and read by nobody.
    • Employees paste confidential data into public tools because no one told them what's allowed and what isn't, in plain language.
    • There's no distinction between low-risk uses (drafting an email) and high-risk uses (making a hiring decision), so the policy is either too strict to use or too vague to enforce.
    • Nobody owns keeping the policy current as tools and use cases change month to month.

    What we do

    One-page policy

    A single page that says what's allowed, what needs approval, and what's banned — written for the people who have to follow it, not for auditors.

    Use-case tiering

    Clear examples of low, medium and high-risk use so employees can self-assess without escalating every question.

    Rollout and training

    A short rollout plan and a communication that gets read, instead of a policy buried in an intranet nobody visits.

    Ownership and review cadence

    A named owner and a fixed review interval, so the policy keeps up with new tools instead of going stale in a shared drive.

    Questions we get

    Does a one-page policy satisfy EU AI Act obligations?

    The policy itself is one artifact among several. It needs to sit alongside an AI inventory and an approval process to cover the accountability obligations the regulation expects from an AI-using organisation.

    Who should own the policy internally?

    Usually someone with authority over both risk and product decisions — legal or compliance alone tend to write policies that get ignored by the people using the tools.

    How often does it need updating?

    At minimum whenever a new class of tool enters common use, plus a scheduled review at least annually.

    Tell us what's running in production.

    We'll tell you what we'd check first — and what we wouldn't bother with.

    Book a call
    Related
    More in Comply