Kehr Technologies

How to Write an AI Use Policy People Actually Follow

Most AI policies fail for the same reason most policies fail: they are written to protect the organization rather than to help the reader decide. Here is the structure that works.

The Test

Can Someone Decide From It in Thirty Seconds?

The moment a policy has to work is a specific one: a member of staff is looking at a task, wondering whether they can use an AI tool for it, and deciding whether to look it up or just carry on. If the answer takes more than about thirty seconds to find, they carry on. That is not a discipline problem; it is a document design problem.

Everything below follows from that. One page. Specific tool names rather than categories. Examples from your actual work. A named person to ask. And, critically, a clear statement of what is allowed. A policy that only prohibits reads as “do not use AI,” which is not what you mean and not what you will get.

This template is the one we hand to Dallas business owners, sized for a company with one office and no legal department. It is a single page on purpose. A twelve-page policy in a twenty-person Plano or Dallas office is a document nobody reads and therefore nobody follows.

THE STRUCTURE

Seven Sections, One Page

1

Why this exists

Two sentences. “We want you to use these tools. Here is what has to stay out of them.” Sets the tone as enablement, which changes how the rest is read.

2

Approved tools, by name

Actual product names and which account to sign in with. “Approved enterprise- grade solutions” tells nobody anything and gets ignored.

3

What never goes in

Named data classes with an example each: patient records, client matter files, payroll, anything under NDA. Examples do the work that categories cannot.

4

What always needs review

Anything going to a client, anything with a number in it, anything cited as fact. State the rule as “check before sending,” not “use good judgment.”

5

Disclosure expectations

When clients, patients, or colleagues should be told AI was involved. Increasingly a regulatory question as well as an ethical one.

6

Who to ask, by name

A person, not a mailbox. The whole point is to make asking easier than guessing, and people do not ask an inbox.

7

What happens if something goes wrong

State plainly that reporting a mistake promptly is the expected behavior and will not be punished. This single paragraph is what determines whether you hear about the next incident in an hour or in six months, and it is the one most policies leave out. See what to do when data goes into an AI tool.

Review it on a date, not on an incident

Put a review date on the document, two or three times a year is realistic. AI tools and their terms change faster than any other category of software you run, and a policy naming products that were replaced last spring teaches people that the policy is not maintained.

FAQS

Frequently Asked Questions

Should the policy just ban AI outright?

We have never seen that work. Bans do not stop the behavior; they move it onto personal accounts and personal phones where you have no visibility, no logging, and no ability to help. A ban is a policy that produces the outcome it was written to prevent.

For most small businesses, a sensible one-page policy adapted from a good template is a large improvement over nothing and does not need to start with counsel. If you are in a regulated field or have client contracts with data- handling clauses, have your lawyer read it, which is much cheaper than having them write it.

Introduce it at the same moment you give them a sanctioned tool. A policy arriving alone reads as a restriction; a policy arriving alongside “here is the thing you have been wanting, and here is how to use it safely” gets read, because the first half is good news.

BK

Written and reviewed by Bob Kehr, President & Founder of Kehr Technologies, Plano City Council member, and Plano Chamber Small Business Person of the Year 2022. He has written and rewritten this policy for clients enough times to know which sections get read.

Last reviewed August 2026 · This page is technology guidance, not legal advice. Call 214-444-3583. Kehr Technologies is based in Plano, Texas, and works with businesses throughout the Dallas area.

Continue Reading

AI Use Policy Template

This structure, already written. Free to download.

Building an AI Risk Register

The governance layer above the policy.

Where Human Review Must Sit

How to write section four so it holds up.

Scroll to Top