In an organisation without an AI policy, employees are already using AI; the organisation just doesn't know it. The point of a policy isn't to ban but to show the safe route.
01. An Approved Tool List
Which tools are cleared for corporate use must be written down. Keep the list short and current; a process that rejects every request feeds shadow usage.
02. The Data Rule
The most critical clause: which data may enter which tool. Customer personal data, price lists, source code and contract text each need their own decision.
03. Responsibility for Output
The person using AI output is responsible for the result. That sentence belongs in the policy explicitly; it sets the expectation of review for code, reports and text going to customers.
04. Transparency
If content going to customers was AI-generated, how that is handled must be decided. In some sectors and on the EU side, labelling obligations are already in force.
05. Training
Publishing the policy isn't enough. Short training with concrete examples works far better than making people read a list of rules.
06. A Request Path
Leave a simple route for an employee who wants to use a new tool. If the process is easy people use it; if it's hard they carry on with personal accounts.