LearnAI home

Setting Rules ยท Lesson 5

How to Set Safe AI Rules for Your Team

A short policy that protects you without stopping useful work.

Why the ban does not work

The instinct, when a manager first understands the risks in this course, is to ban the tools. It is an understandable instinct and it fails in a predictable way. People do not stop using AI. They stop telling you they use it, on personal accounts, on their own phones, outside every control you have. A ban does not remove the risk. It removes your visibility of it, which is worse.

The alternative is not a forty page document nobody reads. It is one page that a new starter can absorb in five minutes and actually remember on a Tuesday afternoon.

In plain English

Shadow use:
Staff using tools the organisation has not approved, usually because the approved route is missing or too slow.
Human in the loop:
A person who reviews and takes responsibility for AI output before it goes anywhere or does anything.
No-blame reporting:
A culture where telling someone about your own mistake is safe, so problems surface early enough to fix.
Acceptable use:
The short statement of what people may and may not do with a tool at work.

The one page policy

Six clauses cover most organisations. Write them in your own words and keep them short enough to fit on a screen.

One: these are the approved tools, and here is how to get access. Name them. If your plan excludes company data from model training, say so, because that is the single fact that most changes what people can safely do. Make the request route genuinely easy, or you have rebuilt the ban by accident.

Two: this never goes in, on any tool. Passwords and keys. Customer and client records. Anything under a confidentiality agreement. Medical, financial and legal details about identifiable people. Unreleased company information. Keep the list to one line each.

Three: anonymise instead of abandoning the task. Say explicitly that replacing names with labels is allowed and encouraged. Without this clause the second clause reads as a ban on doing your job, and people route around it.

Four: a person signs off anything that leaves the building. Client emails, published content, code, quotes, numbers, advice. The reviewer owns the output. It is not the tool's mistake, it is theirs, and saying that clearly is what keeps standards up.

Five: check the facts, and say when you cannot. Any figure, date, quote or claim going to a customer gets verified against a real source. If it cannot be verified, it comes out.

Six: when something goes wrong, tell us today. More on this below, because it is the clause that determines whether the other five are worth anything.

This is a starting structure, not legal advice. Regulated sectors, personal data rules and client contracts may impose specific obligations, so run your draft past whoever handles legal or compliance where you work.

Checkpoint

A workable policy names the approved tools, lists what never goes in, permits anonymised work, requires a named human sign-off, mandates fact checking, and makes reporting mistakes safe.

The clause that does the real work

Someone on your team will paste something they should not have. Someone will send a client a figure that turned out to be invented. This is not a hypothetical, it is a matter of time, and the only variable you control is how quickly you find out.

A credential pasted into a chat window and reported within an hour is an administrative task. The same credential reported in three months, after an incident, is a serious event. A wrong number caught before the client reads it is an edit. Caught afterwards, it is a relationship.

So write the response down in advance, before anyone needs it. Say what to do (tell your manager or the named contact the same day), say what happens next (contain it, fix it, note what we learned), and say what does not happen: nobody is disciplined for an honest mistake that they reported promptly. Then, the first time it happens, behave exactly as written. Everyone will be watching to see whether the policy was real. You get one chance to prove it.

The mistakes that cost serious money are almost never the mistakes people admitted to.

โŒ Weak prompt

Prompt

Write an AI policy for my company.

Output

1. Purpose. This policy governs the utilisation of artificial intelligence technologies by all personnel. 2. Scope. This policy applies to all employees, contractors and third parties...

Generic boilerplate with no tools named, no data list, and no reporting route. It will be filed, never read, and change nobody's behaviour.

โœ… Good prompt

Prompt

Draft a one page AI acceptable use policy for a 25 person architecture practice. We use a business tier assistant that excludes our data from training. Cover: approved tools, what must never be pasted, that anonymising client details is encouraged, human sign-off before anything reaches a client, fact checking any figure, and a same-day no-blame reporting route to the office manager. Plain English, no legal jargon, under 400 words, formatted so it fits on one screen.

Output

What you can use. Which details must be removed first. Who signs off before a client sees it. What to do if you get it wrong, and what will not happen to you if you tell us today.

Specific enough to be usable on Monday. Someone can read it in five minutes and know what to do, which is the only property that matters.

Prompt you can copy: draft your one page policy

Draft a one page AI acceptable use policy for [size and type of organisation]. Approved tools: [list them, and whether the plan excludes company data from training]. Cover, in this order:

  1. Approved tools and how to request access.
  2. What must never be pasted, in short lines.
  3. That anonymising details is encouraged, with an example.
  4. Human sign-off before anything reaches a customer, and who owns the output.
  5. Fact checking any figure, date or quote used externally.
  6. A same-day, no-blame route for reporting mistakes, naming who to tell. Plain English, no legal jargon, under 400 words, readable in five minutes.
Prompt you can copy: write the what-went-wrong process

Write a short internal process for when someone at work has used an AI tool badly: pasted confidential information, or sent out something unverified that was wrong. Include the first three actions in order, who to tell, and a plain statement that nobody is disciplined for an honest mistake reported promptly. Tone: calm and practical. It should make reporting feel routine rather than career-ending. Under 250 words.

Prompt you can copy: run a ten minute team briefing

Write a ten minute team briefing that introduces our AI rules without sounding like a warning. Include: two realistic examples of good use in [our industry], two examples of the line being crossed, the code word idea for phone calls, and three questions to ask the room so it becomes a discussion. Assume nobody is technical. No scare tactics.

Review it, and mean it

Put a date on the policy and revisit it every few months, because both the tools and the scams move faster than any document. Ask the team what the rules are stopping them doing that they think is reasonable, and fix those cases rather than repeating the rule louder. A policy people quietly work around protects nobody at all.

Watch for the failure mode where the policy exists only for junior staff. If the founder pastes the board pack into a free consumer tool, the rules are decoration and everyone can tell.

๐Ÿ“ Quiz

Question 1 of 4

Why does an outright ban on AI tools usually make things worse?

Found this useful? Pass it on.