Skip to main content
Framework

What an AI policy covers

Ten sections, and what goes wrong when each one is missing. Written so that you can hold your own policy up against it without buying anything — including deciding that a one-page guide is the right document for you.
First

Three depths, and none of them is the good one

The temptation is to describe the advanced framework as thorough and the use guide as basic. That framing sells the wrong document to the wrong organisation, which is the specific harm this distinction exists to prevent.

AI Use Guide

One page a person can read standing up. Right for a small team where everybody is already in the same conversation, and where a longer document would go unread.

6 of 10 sections required

Standard AI Governance Policy

A written policy with named sections, so a new member of staff can find the rule that applies to them without asking. Right once the team is large enough that not everybody hears everything.

9 of 10 sections required

Advanced Organisational AI Governance Framework

The same rules, plus the machinery a large organisation needs to keep them true across departments — a tool register, review schedules, role-specific training, an escalation path. Right when coordination is the hard part, not when the risk is.

10 of 10 sections required

A use guide is not a policy with sections deleted

It answers six of the ten in a line each. The other four are answered by ordinary practice rather than by written sections — a two-person farm has a process for reviewing a new tool, and it is the owner deciding. Writing that down as a numbered section does not make it more true, and pretending otherwise is how small organisations end up with compliance theatre.

The sections

10 questions somebody is actually asking

Each one is written as the question a member of staff has in their head, rather than as a heading. If your policy answers the question, it does not matter what the section is called.

Purpose and scope

Why do we use this at all, and who does it apply to?

Required in the Standard AI Governance Policy and the Advanced Organisational AI Governance Framework.

Without it: Without a stated purpose a policy reads as a list of prohibitions, and staff route around it rather than through it. Scope matters as much: contractors and volunteers are usually the people nobody told.

Approved tools

Which tools can I use?

Required at every depth, including a one-page guide.

Without it: Staff use whatever they already have. Unapproved use is rarely defiance — it is the predictable result of never having been told, and it is the most common finding in every organisation that has not written this down.

Prohibited uses

What must never go near this?

Required at every depth, including a one-page guide.

Without it: Every unlisted use is implicitly permitted. The ones that need naming are exactly the ones a reasonable person would not think to ask about.

Data handling

What can I put into it, and what can I not?

Required at every depth, including a one-page guide.

Without it: Do not upload sensitive data is not a rule, because nobody thinks their own work is the sensitive kind. Naming the actual files — intake forms, case notes, payroll, disciplinary records — is what makes it usable.

Human review

What must a person check before it goes out?

Required at every depth, including a one-page guide.

Without it: The failure is never the draft. It is the draft that went out because everybody assumed somebody else had read it.

Disclosure

When do we tell people AI was involved?

Required at every depth, including a one-page guide.

Without it: Staff decide individually and inconsistently, which is worse than either answer. There is no universal rule here — funders, students, customers and community participants are owed different things — so the organisation has to choose rather than inherit.

Training

What am I supposed to have learned, and by when?

Required in the Standard AI Governance Policy and the Advanced Organisational AI Governance Framework.

Without it: The policy exists and nobody knows it does. Acknowledgement is not training and does not substitute for it.

When something goes wrong

I made a mistake — what do I do?

Required at every depth, including a one-page guide.

Without it: People hide it. An organisation with no reported incidents has either a small operation or a reporting problem, and usually cannot tell which.

Reviewing a new tool

How does something new get onto the approved list?

Required in the Advanced Organisational AI Governance Framework.

Without it: The list ages. A tool approved on terms the vendor has since changed is being relied on for a promise that was withdrawn, and nobody notices because approval has no expiry.

Ownership and review

Who is responsible for this, and when is it looked at again?

Required in the Standard AI Governance Policy and the Advanced Organisational AI Governance Framework.

Without it: This is the section whose absence explains all the others. A policy with no owner and no next date is a document rather than a practice.

After it is written

An approved policy stops being editable

Once a policy is approved, the text is fixed. Changing it forks a new version and leaves the old one standing, because somebody acted under the old wording and the record of what the rule was on the day still has to exist.
approvedactivescheduled for reviewsupersededarchived

Board review is a state, not a stage everybody passes through. An eight-person nonprofit with a working board and a four-person farm with no board at all both reach approved; they reach it by different routes. Assuming the board step would leave the farm’s policy permanently unfinished.

How we help organisations write one