One page, because nobody reads eleven
Your organisation may already have an AI policy somewhere. It runs to eleven pages, it was written to reduce risk rather than to be followed, and your people team cannot tell you what it permits on a Tuesday afternoon.
What you need is different: one page, specific to HR, answering the questions your team is actually asking. What may I use this for. What must I never use it for. What can I paste in. What do we tell candidates and employees. Who answers if it goes wrong.
Build it outside this site. Nothing here is stored, there are no accounts, and a policy that lives in a course is not a policy. Put it in whatever your team actually opens.
In plain English
- Permitted use:
- A task your team may use AI for without asking anyone first.
- Prohibited use:
- A task nobody may use AI for, regardless of deadline pressure or how good the output looks.
- Disclosure:
- Telling candidates or employees that AI was involved. A label, not a confession.
- Accountable owner:
- The named person who answers for an output, whatever produced the first draft.
The five sections
Permitted uses. Be generous and specific. Drafting job adverts, summarising policies, building interview question sets and scoring guides, onboarding material, first drafts of routine announcements, cleaning up your own writing. If your team cannot see a real list of things that are clearly fine, they will assume everything is risky and either stop using AI or use it quietly on their phones. The second is worse, because you cannot help with what you cannot see.
Prohibited uses. Also specific. Screening, ranking or scoring candidates. Producing performance ratings. Deciding disciplinary or grievance outcomes. Redundancy selection. Drafting redundancy, bereavement, disciplinary or grievance messages. Any tool that scores video interviews or infers personality, pending advice from legal. Name the tasks, not the principles. Handle sensitive matters carefully is not a rule anyone can apply under pressure.
Confidentiality. No names, no employee numbers, no salary figures tied to a person, no case details, no health information, no performance notes about an individual, no job titles specific enough to identify someone. State which accounts are approved and which are not.
Disclosure. Say what candidates and employees are told, and when. This is the section your legal or compliance function must see, because notification requirements vary and change.
Accountability. One sentence, and always the same sentence. The person who sends it owns it. Not the tool, not the drafter, not the team.
This template is a starting point, not legal advice. Requirements around automated decisions, candidate notification and employee data vary by country, state and sector. Take your draft to your legal or compliance function before it becomes policy, and let their version win wherever the two disagree.
HR AI POLICY: [organisation], [date]
Owner: [name]. Review date: [date, six months out].
- WHAT YOU MAY USE AI FOR
- Drafting job adverts and role descriptions
- Summarising policies and producing plain-language explainers
- Building structured interview questions and scoring guides
- Onboarding material, guides and week one plans
- First drafts of routine announcements
- Tidying and shortening your own writing
- [add your own]
- WHAT YOU MAY NEVER USE AI FOR
- Screening, ranking or scoring candidates
- Producing or drafting performance ratings
- Deciding disciplinary or grievance outcomes
- Redundancy selection
- Writing redundancy, bereavement, disciplinary or grievance messages
- Video interview scoring or personality inference tools
- Any decision about a named individual's future
- [add your own]
-
WHAT YOU MAY NEVER PASTE IN
Names. Employee numbers. Salary figures tied to a person. Grievance or
disciplinary case detail. Health information. Performance notes about an
individual. Job titles specific enough to identify someone.
Approved accounts: [list]. Personal accounts: [permitted or not].
-
WHAT WE TELL PEOPLE
Candidates are told: [agreed wording, checked with legal].
Employees are told: [agreed wording, checked with legal].
Anything going to a person largely as generated is disclosed.
-
WHO IS ACCOUNTABLE
The person who sends it owns it. A human decision about a person must be
explainable by that human, in their own words, without mentioning software.
Unsure? Ask [name] before you send.
Checkpoint
Five sections: permitted uses, prohibited uses, confidentiality, disclosure, accountability. Written specifically enough that someone under deadline pressure can apply it without asking.
Lead with the permissions
Policies written as a list of prohibitions fail in a predictable way. People read them, conclude AI is dangerous and vaguely forbidden, and use it anyway where nobody can see, help or correct anything.
Put the permitted list first and make it real. If the opening half is a genuine list of things people may do freely, the prohibited half carries far more weight, because it reads as a short set of serious exceptions rather than a wall of no.
โ Weak prompt
Prompt
Write an AI policy for our HR team.
Output
1. Purpose and scope. 2. Definitions. 3. Governance framework. 4. Risk appetite. 5. Data handling principles. 6. Compliance monitoring and review cadence.
A governance document. Nobody in your team reads past the word framework, and it answers none of the five questions they actually have on a Tuesday.
โ Good prompt
Prompt
Write a one-page AI policy for a five-person HR team. Under 400 words, plain English, no legal phrasing. Exactly five sections: what you may use AI for, what you may never use it for, what you may never paste in, what we tell candidates and employees, and who is accountable. Concrete tasks not principles. Permitted list first.
Output
You may use AI to draft job adverts, summarise policies, build interview questions and scoring guides. You may never use it to screen, rank or score candidates.
Specific, short, and answers what people actually want to know. It fits on a wall and survives a busy afternoon.
Make it survive contact
Test it before you publish. Take five real things your team did last month, hold each against the draft, and see whether the policy gives a clear answer. Any case that leaves you shrugging is a case your team will resolve by guessing.
Here is my draft HR AI policy:
[paste it]
Here are five real situations from my team last month:
- [situation]
- [situation]
- [situation]
- [situation]
- [situation]
For each, say exactly what my policy tells the person to do. If the policy
is ambiguous or silent, say so plainly and suggest the single shortest
sentence that would close the gap.
Then list anything in the policy that a person under deadline pressure
could reasonably talk themselves out of. Do not rewrite the document.
Cut this HR AI policy to under 350 words without losing any rule.
Remove every sentence that only restates a principle.
Keep all concrete task names, since those are the part people remember.
Keep the permitted list first.
Return the shorter version only, no commentary.
Set a review date six months out and put it in a calendar now. Tools change, your team's habits change, and any policy written before people had really used these tools will contain at least one line that already looks wrong.
Finish the quiz below and the People First badge is yours. The more useful thing you leave with is a page your team can actually follow, and a clear line between the admin AI speeds up and the decisions about people that stay human, explainable and yours.
๐ Quiz
Question 1 of 4What are the five sections of the HR AI policy?