How to Build an AI Policy That Works

Microsoft 365
Jackie Bilodeau

Written by Jackie Bilodeau

I am the Communications Director for CGNET, having returned to CGNET in 2018 after a 10-year stint in the 1990's. I enjoy hiking, music, dance, writing, cheering on Bay Area sports teams, and traveling near and far as much as I can. Read more about my work at CGNET here.

September 1, 2026

A customer recently reached out to us for some basic advice on setting up an AI policy for his organization. It’s a question we suspect a lot of organizations are asking right now. Because here’s the thing: If your organization hasn’t written an AI policy yet, that doesn’t mean your employees aren’t using AI. It probably just means everyone is making up their own rules.

Someone is using ChatGPT to polish an email. Someone else is asking Copilot to summarize a meeting. Another person has discovered an AI tool that turns three hours of work into twenty minutes and is understandably delighted with themselves.

None of this is necessarily bad. Organizations should want employees experimenting with AI and finding ways to work more efficiently. But there’s a big difference between encouraging experimentation and having no idea what information people are feeding into which AI systems. That’s where some sensible AI guidelines come in.

So, with that in mind, I put together a simple step-by-step guide to creating AI guidelines for your organization, along with a handy table of the guidelines you can save, share, or print out for future reference.

Step One: Find Out What’s Already Happening

Before writing a policy, find out how employees are actually using AI. Ask which tools they use, what they use them for, whether they have free or paid accounts, and what kinds of information they enter into them.

This doesn’t need to feel like an investigation. You’re trying to understand what’s happening, not catch someone asking ChatGPT to make the quarterly report sound less boring.

You may discover people using AI for research, meeting notes, writing, spreadsheets, coding, translation, or dozens of other tasks. That gives you a much better starting point than downloading a generic AI policy from the internet and hoping it applies to your organization.

Step Two: Decide What’s Off-Limits

Employees need to know what they can and cannot put into an AI system. Confidential client information? Employee records? Financial data? Personally identifiable information? Internal strategy documents? Your guidelines should make the boundaries clear.

The rules may differ depending on the platform. An enterprise AI service with appropriate security and data protections may be approved for information that should never be pasted into a free consumer chatbot.

That distinction is important. Employees shouldn’t have to make complicated data-security decisions every time they open an AI tool.

Step Three: Create an Approved AI Toolbox

You don’t want employees signing up for every shiny new AI service that appears online, but you don’t want to squash useful experimentation either.

Create a list of approved AI tools and what they can be used for. Then establish an easy process for requesting something new. Someone should review its security, privacy, licensing, data retention, and other risks before it becomes part of the organization’s technology collection.

Think guardrails, not roadblocks.

Step Four: Keep a Human in Charge

AI can produce remarkably convincing nonsense. Your guidelines should therefore make one thing unmistakably clear: AI can help create the work, but a human owns the result.

Employees should verify important facts, calculations, citations, recommendations, and other AI-generated information. The higher the stakes, the greater the level of human review.

You should also address copyright, bias, inappropriate content, and situations where AI use should be disclosed. No policy can anticipate every scenario, so one old-fashioned rule still works surprisingly well: if something feels sensitive, questionable, or unusually consequential, ask before doing it.

Step Five: Train People

You can write the world’s greatest AI policy, put it in SharePoint, email everyone a link—and confidently assume that roughly six people will read it.

Training makes the policy real. Show employees examples of acceptable and unacceptable AI use, explain what information shouldn’t be entered into certain systems, and teach them to recognize hallucinations and verify important answers.

Just as importantly, show people what they can do with AI. The goal is safe adoption, not making employees afraid to touch it.

 

A Simple AI Guidelines Checklist

AI Policy Guidelines

 

Don’t Carve It in Stone

AI is changing far too quickly for a policy written today to sit untouched for five years. New tools appear, existing platforms gain new capabilities, regulations evolve, and employees discover uses nobody anticipated.

Assign someone responsibility for reviewing the guidelines periodically and give employees a way to raise questions or suggest changes. You don’t need to rewrite the policy every time ChatGPT gets a new button, but you should revisit it when your technology, risks, or use of AI meaningfully changes.

Most importantly, remember what the policy is supposed to accomplish. The goal isn’t to stop AI. It’s to make AI useful without creating unnecessary security, privacy, legal, or reputational risks.

There are two bad approaches to AI governance: “Nobody is allowed to use AI” and “Have fun, everybody!”

A good policy lives comfortably somewhere in between.

 

 

For over forty-three years, CGNET has provided state-of-the-art IT services to organizations of all sizes, across the globe. We’ve done it all, from IT and cybersecurity assessments to cloud services management to generative AI user training. Want to learn more about who we are and how we might be able to help you? If so, check out our website or send us a message!

 

You May Also Like…

You May Also Like…

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Translate »
Share This
Subscribe
CGNET
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.