Module 2.4
Keep it short and answerable
A policy is not a brake on AI — it is what lets an organization use it with confidence, by making the safe uses obvious and the risky ones deliberate. And it does not need to be long: anyone should be able to answer three questions from it — what is allowed, what is not, and who decides. The policy areas below are simply where those three questions get answered in practice.
| Policy Area | Required Decision |
|---|---|
| Approved tools | Which AI tools may be used, by whom, for what? |
| Data rules | What may never be pasted, regardless of tool or setting? |
| Review rules | Which outputs require human approval before action? |
| High-risk uses | Which uses are restricted or prohibited entirely? |
| Logging | What must be recorded, and where? |
| Incident response | What happens after a mistake, leak, or unsafe output? |
| Ownership | Who is accountable for AI-assisted work and its consequences? |
| Policy review | How often is the policy reviewed, and who approves changes? |
A finished policy line is short and answerable: “Marketing may use approved AI tools to draft content; a named editor approves anything before it is published.” That one sentence answers all three questions at once — what is allowed, what is not, and who decides.
Triage the consequence of a wrong output
One of those policy areas — high-risk uses — needs a shared yardstick. Ask: if this AI output disappeared or was proven wrong right now, what is the worst thing that would happen? This table triages that consequence; the top tier covers inputs that are hazardous in themselves — secrets, credentials, sensitive personal data, privileged company data, or automated execution authority.
| Answer | Risk Level | Action |
|---|---|---|
| Exposure cannot be undone; access cannot be easily revoked. | Prohibited Without Governance | Do not paste or connect such inputs unless policy, access controls, and monitoring already exist. See the full Risk Ladder. |
| Irreversible harm — financial loss, legal exposure, safety impact | Critical | Do not proceed without formal controls and documented human approval. |
| Professional, financial, or regulatory consequence | High | Verify with a qualified expert or primary source before acting. |
| Disruption to a team or process, recoverable | Medium | Add a review step before output is acted on. |
| Minor inconvenience, easily corrected | Low | Proceed with standard review. |
NIST AI Risk Management Framework provides a rigorous governance foundation for organizations that need to scale beyond these starting points. See the Appendix for the full citation.
If you do not already have an AI policy, the Template Kits below turn this framework — the three questions, the policy areas, and the triage — into documents you can adopt directly.
Two Template Kits turn Modules 1 and 2 into ready-to-use documents in Word or PDF: the Individual Kit for one person using AI tools on their own, and the Team Kit for anyone responsible for how others use AI.
See the Template Kits →