AI Policy Template for a 50-Person Company
One side of paper, in the words you would actually circulate — the approved-tools list, the never-list, who checks the output, who owns it, and the amnesty paragraph most templates leave out.
Somebody in your firm is already using AI. Not as a project — as a habit. A client's spreadsheet pasted into a chat window at 8pm, to get a summary out of it before the morning. This is true at nearly every firm of fifty people I have looked at, and usually before anyone has said the word "policy" out loud.
That is the situation an AI policy exists for. Not to satisfy an auditor. To give fifty people one page that answers the question they are currently answering privately, each in their own way.
Why it has to be one page
The templates that circulate are written for organisations with a compliance function. They run to twelve pages and open with a definition of machine learning. A policy nobody has read does not reduce your exposure, because the exposure is a person pasting a client list into a free tool, and that person will not have got to page nine.
So the constraint comes first: one side of paper, plain words, and every line answerable by someone on their second week. Everything below fits that. If you want the reasoning behind each part, the piece on what governance a smaller firm actually needs covers it; this is the document itself.
The five sections, with the words
1. What we use, and who approved it.
The tools approved for work use are listed at the end of this page. If you want to use something that is not on the list, ask [name] first. Adding one is normally quick. Using an unapproved tool for client work is not a small thing, because it decides where our clients' data goes.
The list matters more than the paragraph. Keep it as an actual list — tool, what it is used for, who approved it, the date. Three entries is a fine starting point. An empty list is the tell that nobody has looked.
2. What never goes in.
Do not put any of the following into an AI tool: client records or anything identifying a client, personal data about staff, our commercial terms, or anything from a client who has told us not to. If you are unsure whether something counts, it counts.
This is the section that earns the page. Write it for your firm, not from a template — a care provider and a broker have different never-lists, and the specific one is the one people follow. Keep it to things you can name.
3. Who checks the output before it leaves.
Anything produced with AI that goes to a client or a regulator is checked by the person whose name is on it, the same way you would check work from a new starter. You remain responsible for it. "The tool wrote it" is not an explanation we can give a client.
Most policies stop at inputs. Outputs are where the actual damage happens, and this sentence is the whole of the control.
4. Who owns this.
[Name] is responsible for this policy. If an AI tool produces something wrong and it reaches a client, tell [name] the same day. Nobody is in trouble for reporting one. People are in trouble for hiding one.
One named human, not a committee. A committee at this size means the review happens when three people are free at once, which is never.
5. When we look at it again.
Reviewed every six months, and whenever we add a tool or a supplier changes what theirs does.
Six months is not arbitrary. The models underneath these tools change on a shorter cycle than an annual review, so a control written once starts drifting away from the thing it was written about.
The paragraph most templates miss
Add an amnesty.
If you have already been using an AI tool for work, tell [name] this month and that is the end of it. We would rather know.
Without it, the policy's first effect is to drive existing use underground, and you end up with a tidy document and a less accurate picture of your own firm than you had before writing it.
Getting it adopted
Circulate it once, in full, in the body of an email — not as an attachment, not as a link to a portal. Spend ten minutes on it in a team meeting, and use the time to collect the questions people actually have. They are usually a version of "can I use it for X" and "am I going to get told off".
Then answer the first few requests to add a tool quickly. A policy that takes a fortnight to say yes teaches people to stop asking.
What this does not cover
This page is proportionate to a fifty-person firm doing ordinary things — drafting, and first-pass work on documents. If you are using AI to make or materially influence decisions about people, such as who gets hired or who gets credit, you are in different territory and one page is not enough. That distinction, and why controls written once stop matching a model that keeps changing, is the subject of the board briefing on static controls and live models.
If you would rather know where you stand before you write anything, the AI readiness scorecard takes about five minutes, scores you across the areas above and shows the result straight away. No email required.
Ready to integrate AI into your business?
See how Model Context Protocol (MCP) can connect your AI assistant to all your business tools. Book a call with our team to discuss your specific needs.
Book a Call (opens in a new tab)