- One Page, Written to Be Read
How to Write an AI Use Policy People Actually Follow
Most AI policies fail for the same reason most policies fail: they are written to protect the organization rather than to help the reader decide. Here is the structure that works.
The Test
Can Someone Decide From It in Thirty Seconds?
The moment a policy has to work is a specific one: a member of staff is looking at a task, wondering whether they can use an AI tool for it, and deciding whether to look it up or just carry on. If the answer takes more than about thirty seconds to find, they carry on. That is not a discipline problem; it is a document design problem.
Everything below follows from that. One page. Specific tool names rather than categories. Examples from your actual work. A named person to ask. And, critically, a clear statement of what is allowed. A policy that only prohibits reads as “do not use AI,” which is not what you mean and not what you will get.
This template is the one we hand to Dallas business owners, sized for a company with one office and no legal department. It is a single page on purpose. A twelve-page policy in a twenty-person Plano or Dallas office is a document nobody reads and therefore nobody follows.
THE STRUCTURE
Seven Sections, One Page
1
Why this exists
Two sentences. “We want you to use these tools. Here is what has to stay out of them.” Sets the tone as enablement, which changes how the rest is read.
2
Approved tools, by name
Actual product names and which account to sign in with. “Approved enterprise- grade solutions” tells nobody anything and gets ignored.
3
What never goes in
Named data classes with an example each: patient records, client matter files, payroll, anything under NDA. Examples do the work that categories cannot.
4
What always needs review
Anything going to a client, anything with a number in it, anything cited as fact. State the rule as “check before sending,” not “use good judgment.”
5
Disclosure expectations
When clients, patients, or colleagues should be told AI was involved. Increasingly a regulatory question as well as an ethical one.
6
Who to ask, by name
A person, not a mailbox. The whole point is to make asking easier than guessing, and people do not ask an inbox.
7
What happens if something goes wrong
State plainly that reporting a mistake promptly is the expected behavior and will not be punished. This single paragraph is what determines whether you hear about the next incident in an hour or in six months, and it is the one most policies leave out. See what to do when data goes into an AI tool.
Review it on a date, not on an incident
Put a review date on the document, two or three times a year is realistic. AI tools and their terms change faster than any other category of software you run, and a policy naming products that were replaced last spring teaches people that the policy is not maintained.
Should the policy just ban AI outright?
We have never seen that work. Bans do not stop the behavior; they move it onto personal accounts and personal phones where you have no visibility, no logging, and no ability to help. A ban is a policy that produces the outcome it was written to prevent.
Do we need a lawyer to write this?
For most small businesses, a sensible one-page policy adapted from a good template is a large improvement over nothing and does not need to start with counsel. If you are in a regulated field or have client contracts with data- handling clauses, have your lawyer read it, which is much cheaper than having them write it.
How do we get people to actually read it?
Introduce it at the same moment you give them a sanctioned tool. A policy arriving alone reads as a restriction; a policy arriving alongside “here is the thing you have been wanting, and here is how to use it safely” gets read, because the first half is good news.
BK
Written and reviewed by Bob Kehr, President & Founder of Kehr Technologies, Plano City Council member, and Plano Chamber Small Business Person of the Year 2022. He has written and rewritten this policy for clients enough times to know which sections get read.
Last reviewed August 2026 · This page is technology guidance, not legal advice. Call 214-444-3583. Kehr Technologies is based in Plano, Texas, and works with businesses throughout the Dallas area.