What an AI policy covers
Three depths, and none of them is the good one
AI Use Guide
One page a person can read standing up. Right for a small team where everybody is already in the same conversation, and where a longer document would go unread.
6 of 10 sections required
Standard AI Governance Policy
A written policy with named sections, so a new member of staff can find the rule that applies to them without asking. Right once the team is large enough that not everybody hears everything.
9 of 10 sections required
Advanced Organisational AI Governance Framework
The same rules, plus the machinery a large organisation needs to keep them true across departments — a tool register, review schedules, role-specific training, an escalation path. Right when coordination is the hard part, not when the risk is.
10 of 10 sections required
A use guide is not a policy with sections deleted
It answers six of the ten in a line each. The other four are answered by ordinary practice rather than by written sections — a two-person farm has a process for reviewing a new tool, and it is the owner deciding. Writing that down as a numbered section does not make it more true, and pretending otherwise is how small organisations end up with compliance theatre.
10 questions somebody is actually asking
Purpose and scope
Why do we use this at all, and who does it apply to?
Required in the Standard AI Governance Policy and the Advanced Organisational AI Governance Framework.
Without it: Without a stated purpose a policy reads as a list of prohibitions, and staff route around it rather than through it. Scope matters as much: contractors and volunteers are usually the people nobody told.
Approved tools
Which tools can I use?
Required at every depth, including a one-page guide.
Without it: Staff use whatever they already have. Unapproved use is rarely defiance — it is the predictable result of never having been told, and it is the most common finding in every organisation that has not written this down.
Prohibited uses
What must never go near this?
Required at every depth, including a one-page guide.
Without it: Every unlisted use is implicitly permitted. The ones that need naming are exactly the ones a reasonable person would not think to ask about.
Data handling
What can I put into it, and what can I not?
Required at every depth, including a one-page guide.
Without it: Do not upload sensitive data is not a rule, because nobody thinks their own work is the sensitive kind. Naming the actual files — intake forms, case notes, payroll, disciplinary records — is what makes it usable.
Human review
What must a person check before it goes out?
Required at every depth, including a one-page guide.
Without it: The failure is never the draft. It is the draft that went out because everybody assumed somebody else had read it.
Disclosure
When do we tell people AI was involved?
Required at every depth, including a one-page guide.
Without it: Staff decide individually and inconsistently, which is worse than either answer. There is no universal rule here — funders, students, customers and community participants are owed different things — so the organisation has to choose rather than inherit.
Training
What am I supposed to have learned, and by when?
Required in the Standard AI Governance Policy and the Advanced Organisational AI Governance Framework.
Without it: The policy exists and nobody knows it does. Acknowledgement is not training and does not substitute for it.
When something goes wrong
I made a mistake — what do I do?
Required at every depth, including a one-page guide.
Without it: People hide it. An organisation with no reported incidents has either a small operation or a reporting problem, and usually cannot tell which.
Reviewing a new tool
How does something new get onto the approved list?
Required in the Advanced Organisational AI Governance Framework.
Without it: The list ages. A tool approved on terms the vendor has since changed is being relied on for a promise that was withdrawn, and nobody notices because approval has no expiry.
Ownership and review
Who is responsible for this, and when is it looked at again?
Required in the Standard AI Governance Policy and the Advanced Organisational AI Governance Framework.
Without it: This is the section whose absence explains all the others. A policy with no owner and no next date is a document rather than a practice.
An approved policy stops being editable
Board review is a state, not a stage everybody passes through. An eight-person nonprofit with a working board and a four-person farm with no board at all both reach approved; they reach it by different routes. Assuming the board step would leave the farm’s policy permanently unfinished.
