The AI policy every business should have before the regulator asks for it

Most businesses are using artificial intelligence every day and have no policy governing it. Staff use it on their own initiative, on whatever data seems useful, with no agreed rules and no oversight. It works, until the day someone asks how you manage it — and increasingly, someone will. A client’s procurement team, a regulator, an insurer. When that question comes, “we don’t have a policy” is not an answer anyone wants to give.

An AI policy is the document that closes that gap. The mistake businesses make is treating it as a technical artefact for the IT team. It is not. It is a governance document, and it belongs to the business, because the questions it answers are business questions.

What an AI policy actually covers

A useful AI policy does not describe the technology. It sets the rules of use, and a handful of points carry most of the value.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

Which tools are approved, and for what. Not an open field and not a blanket ban — a named set of tools staff may use, for defined purposes, so people know where the line is.

What data may and may not go in. This is the most important clause. Client data, personal data and commercially sensitive material going into a public AI tool is a data-protection exposure, so the policy must be explicit about what is never permitted to leave the business this way.

Human review of output. AI produces confident, fluent, sometimes wrong work. The policy should require a person to be accountable for anything AI-assisted before it reaches a client or a decision.

Ownership and accountability. Who owns AI risk in the business, and who staff turn to with a question. An unowned risk is an unmanaged one.

Vendor terms. A basic awareness of what each approved tool does with the data you put in — because not all of them treat it the same way, and some use it in ways a business handling client data cannot accept.

Why “before the regulator asks” matters

The timing is the point. Data-protection law already applies to how you use AI on personal data — there is nothing to wait for there. The EU’s AI Act is phasing in, with its bans on the most harmful uses already in force and broader obligations arriving across 2026 and beyond, and it reaches businesses outside the EU that serve the EU market. But in practice, clients are the ones moving fastest: procurement questionnaires now routinely ask suppliers how they use AI and how they protect data fed into it.

Writing the policy after you have been asked is writing it under pressure, and visibly late. Writing it now is cheap, and it converts an exposure into a position you can stand behind. It is also the structural fix for the problem of staff already using AI without oversight — the policy is what turns improvised use into governed use.

Keep it short enough to be used

A policy nobody reads governs nothing. The goal is not a forty-page document drafted to impress a lawyer; it is a short, clear set of rules staff can actually follow, backed by brief training so people understand the why, not just the what. It should be reviewed regularly, because the tools and the regulation are both moving. And it should be paired with knowing what is actually in use — a policy written without first finding out which tools staff have already adopted is governing a fiction, which is why it goes hand in hand with addressing shadow IT.

Most businesses are running AI without a policy, and the first client or regulator to ask will make that visible. Getting ahead of it is inexpensive now and awkward later. We will build the governance layer before someone asks to see it.

Start a Conversation

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming