Nobody reads the ten-page version
Somewhere in your organisation there may already be an AI policy. It was written by people who are paid to reduce risk, it runs to eleven pages, and it contains the phrase where appropriate more than once. Your team has not read it. If they have, they cannot tell you what it permits.
That is not a failure of discipline. It is a failure of format. A rule that people cannot recall at the moment they need it is not a rule, it is a document.
What you need is one page, ideally half of one, that answers four questions your team is genuinely asking: what can I paste in, what must I never paste in, when do I have to say I used AI, and who is on the hook if it is wrong.
In plain English
- Disclosure:
- Telling someone that AI helped produce what they are reading. Not a confession, just a label.
- Personal data:
- Anything that identifies a living person: names, emails, addresses, ID numbers, health details.
- Enterprise account:
- A paid company version of a tool with an agreement about how your data is handled. Different from a free personal login.
- Accountability:
- The named person who answers for the output, regardless of what produced the draft.
The four questions
What may be pasted in. Be specific and generous where you safely can. Public information, your own drafts, internal notes with no personal or commercial detail, anonymised examples, general questions. If your team cannot see a list of things that are clearly fine, they will assume everything is risky and either stop using it or use it secretly. The second one is worse.
What may not. Also specific. Customer names and contact details, staff records, salaries, anything under a signed confidentiality agreement, unreleased financials, credentials and passwords, source code if your organisation says so. Name the categories, not the principles. Do not treat sensitive information carefully is not a rule anyone can apply at four in the afternoon.
When to disclose. Set a plain threshold. A useful default: no disclosure needed when AI helped you draft, tidy or summarise something you then reviewed. Disclosure needed when the output goes to a customer largely as generated, when it informs a decision about a person, or when someone reasonably assumes a human wrote it personally.
Who is accountable. One sentence, and it is always the same sentence. The person who sends it owns it. Not the tool, not the drafter, not the team. This single line prevents most of the arguments you would otherwise have later.
Check your organisation's existing policy before you write yours. Your one-pager should sit underneath it as a practical translation, never contradict it. If the two disagree, the official one wins and you go and ask why.
โ Weak prompt
Prompt
Write an AI usage policy for my team.
Output
1. Purpose and scope. 2. Definitions. 3. Acceptable use principles. 4. Data governance framework. 5. Compliance and monitoring. 6. Review cadence.
It produced a governance document. Nobody on your team will read past the word framework, and it answers none of the four real questions.
โ Good prompt
Prompt
Write a one-page AI ground rules note for a team of nine in customer operations. Plain English, under 300 words, no legal language, no headings beyond four. Answer exactly four things: what may be pasted into an AI tool, what may never be, when to tell someone AI was used, and who is accountable for the output. Use short bullets. Assume the reader is busy and slightly nervous.
Output
You can paste: your own drafts, internal notes with no customer details, anonymised examples, general questions. Never paste: customer names or contact details, staff or pay records, anything under NDA.
Specific, short, and answers what people actually want to know. It fits on a wall and survives a busy afternoon.
Write a one-page AI ground rules note for my team.
Team: [9] people doing [what they do]
Tools they use: [ChatGPT / Claude / Gemini / Copilot], on [free personal / company] accounts
Existing company policy says: [paste the key lines, or write none that I know of]
Requirements:
- Under 300 words, plain English, no legal phrasing
- Exactly four sections: what you can paste in, what you must never paste in,
when to say AI was used, who is accountable
- Short bullets, concrete examples, no principles without examples
- End with one line telling people who to ask when unsure
Do not add sections I did not request.
Checkpoint
Your one-pager answers four questions: what may be pasted in, what may not, when to disclose, and who is accountable. Short and clear beats comprehensive and ignored.
Write the permissions first
Most policies are written as a list of prohibitions, and they fail in a predictable way. People read them, conclude that AI is dangerous and vaguely forbidden, and then quietly use it on their phones where you cannot see it, help or correct anything.
Lead with what is allowed. If the first half of your page is a genuine list of things people can do freely, the second half carries far more weight, because it reads as a small set of real exceptions rather than a wall of no.
Add one line naming the person to ask when something is not covered. Every policy has gaps. What you want is for the gaps to arrive at your desk as a question rather than as a decision somebody made alone.
Make it survive contact
Test it before you publish. Take five things your team did last week, hold each against your draft, and see whether the rule gives a clear answer. Any case that leaves you shrugging is a case your team will resolve by guessing.
Here is my draft AI ground rules note:
[paste it]
Here are five real situations from my team last week:
- [situation]
- [situation]
- [situation]
- [situation]
- [situation]
For each situation, say what my rules tell the person to do. If the rules are
ambiguous or silent, say so plainly and suggest the single shortest sentence
that would fix the gap. Do not rewrite the whole document.
Then read it aloud in a team meeting, all four sections, in under two minutes. If you cannot get through it in two minutes, it is too long, and you have written the eleven-page version with better formatting.
Cut this AI ground rules note to under 200 words without losing any rule.
Remove every sentence that only restates a principle.
Keep all concrete examples, since those are the part people remember.
Return the shorter version only, no commentary.
Revisit it in three months. Tools change, your team's habits change, and a rule written before anybody had used these tools properly will have at least one line in it that now looks silly.
๐ Quiz
Question 1 of 4What are the four questions a team-level AI policy needs to answer?