Here is a fact worth sitting with: your employees are already using AI. Some are drafting emails in ChatGPT, some are pasting customer data into a chatbot to summarise it, some are running code through an assistant IT has never heard of. This is happening right now, in every organisation, regardless of whether anyone approved it. The term for it is shadow AI, and pretending it does not exist is not a policy.
So the real question is not "should our people use AI?" They already do. The question is whether they are doing it inside guardrails you have set, or entirely in the dark. That is what an AI policy is for. And in 2026 it is not optional in the way it once felt: regulators, auditors, insurers, customers, and courts have started to treat the absence of an AI acceptable use policy as a governance failure on its own.
The catch is that most AI policies fail for the same reason most policies fail. They are long, written by lawyers for lawyers, and nobody reads them. A policy nobody reads cannot be followed. So the goal is not the most thorough document. It is the most usable one.
The six blocks of a usable policy
A policy people will actually follow needs six parts, and not many more. Each answers a question an employee genuinely has.
- Scope. Who does this cover, which tools count as "AI" for this purpose, and where does it apply? Contractors and personal devices are the parts people forget.
- Approved tools. The clear list of AI tools people are allowed to use, and, just as important, a simple path to request a new one. If there is no easy way to ask, people will just use whatever they want and not tell you. The request process is what pulls shadow AI into the light.
- Data rules. The heart of it. What data may and may not be entered into an AI tool, mapped to your data classification tiers. "Never paste customer PII, source code, or anything marked confidential into an external tool" is the kind of concrete rule people can follow. Vague rules like "use good judgment" are not rules.
- Prohibited uses. The bright lines. No unreviewed AI output going straight into a decision that affects a person, no using AI to generate anything you could not stand behind, whatever your specific red lines are.
- Accountability and incident reporting. Who owns this policy, who do you tell if something goes wrong, and what happens after a violation? People need to know it is safe to report a mistake, or they will hide them.
- A review cycle. A named date to revisit it. AI tools change monthly. A policy written once and frozen is out of date within a quarter, and everyone knows it, which is another reason nobody follows the stale ones.
Start by finding the shadow AI
Before you write a word, do the one step most organisations skip: inventory the AI that is already in use. You cannot govern what you cannot see. Ask around, look at what tools are actually being accessed, and be genuinely curious rather than punitive, because the goal is an honest picture, not a witch hunt. You will almost certainly find more than you expected, and that inventory tells you what your policy actually needs to address, versus what a generic template thinks it should.
Then map your data classification tiers to clear allow-and-prohibit rules, name the owner and the reporting contact, and distribute it for employees to acknowledge. Acknowledgement matters: it turns "we had a policy somewhere" into "everyone confirmed they read it," which is the difference an auditor cares about.
Rules plus controls, not one or the other
A policy is necessary and not sufficient. The rules tell people what to do; technical controls catch the cases where they slip. The two reinforce each other:
| The rule (policy) | The control (technical) |
|---|---|
| Use only approved AI tools | Allowlist approved tools; block unapproved consumer AI where appropriate |
| Never paste sensitive data into AI | Data-loss-prevention rules that flag sensitive data going to external services |
| Report incidents to a named owner | Monitoring and logging so incidents are visible, not just self-reported |
Leaning entirely on controls turns your company into a place where people feel policed and route around you, which recreates shadow AI. Leaning entirely on rules trusts everyone to be perfect, which they are not. The workable posture is clear, humane rules backed by controls that catch the genuine mistakes.
The mindset that makes it work
The best AI policies share a mindset: they are written to enable safe use, not to forbid AI. A policy that says "no AI, ever" is ignored within a week and drives everything underground. A policy that says "here is how to use AI safely, here are the tools we trust, here is the line you do not cross, and here is how to ask for more" gets followed, because it helps people do the thing they already want to do, safely.
That framing also connects to the wider governance picture your board and auditors will ask about, which we cover in the risk module of executive AI literacy. A policy is one visible piece of a responsible AI posture, and it is the piece you can put in place fastest.
If you want help drafting a policy that fits your actual data, tools, and risk tolerance, rather than a generic template, that is something we do as part of our governance work. Get in touch and we will start from your real shadow-AI inventory, not a boilerplate.
Sources
Frequently asked questions
- Does my company need an AI policy?
- Yes. In 2026, regulators, auditors, insurers, customers, and courts increasingly treat the absence of an AI acceptable use policy as a governance failure in itself. And practically, your employees are already using AI tools, so the choice is not whether AI is used but whether it is used inside rules you have set.
- What should an AI acceptable use policy include?
- Six core parts: scope (who and what it covers), an approved tools list with a process to request new ones, data rules for what may and may not be entered into AI tools, prohibited uses, accountability and incident reporting, and a review cycle. Keep it short enough that people actually read it.
- What is shadow AI and why does it matter?
- Shadow AI is employees using AI tools that IT has not approved or does not know about, often pasting company data into consumer chatbots. It matters because it creates data-leak and compliance risk invisibly. The first step in any AI policy is to inventory the AI already in use, including shadow AI, because you cannot govern what you cannot see.
- How do you enforce an AI policy?
- Through a mix of clear rules people understand and technical controls: allowlisting approved AI tools, blocking unapproved consumer tools at the network level where appropriate, and data-loss-prevention rules that flag when sensitive data is sent to external AI services. But enforcement starts with a policy that is short and usable, because rules nobody reads cannot be followed.