Module 2.4

Keep it short and answerable

A policy is not a brake on AI — it is what lets an organization use it with confidence, by making the safe uses obvious and the risky ones deliberate. And it does not need to be long: anyone should be able to answer three questions from it — what is allowed, what is not, and who decides. The policy areas below are simply where those three questions get answered in practice.

Policy AreaRequired Decision
Approved toolsWhich AI tools may be used, by whom, for what?
Data rulesWhat may never be pasted, regardless of tool or setting?
Review rulesWhich outputs require human approval before action?
High-risk usesWhich uses are restricted or prohibited entirely?
LoggingWhat must be recorded, and where?
Incident responseWhat happens after a mistake, leak, or unsafe output?
OwnershipWho is accountable for AI-assisted work and its consequences?
Policy reviewHow often is the policy reviewed, and who approves changes?
What one answer looks like.

A finished policy line is short and answerable: “Marketing may use approved AI tools to draft content; a named editor approves anything before it is published.” That one sentence answers all three questions at once — what is allowed, what is not, and who decides.

Triage the consequence of a wrong output

One of those policy areas — high-risk uses — needs a shared yardstick. Ask: if this AI output disappeared or was proven wrong right now, what is the worst thing that would happen? This table triages that consequence; the top tier covers inputs that are hazardous in themselves — secrets, credentials, sensitive personal data, privileged company data, or automated execution authority.

If you cannot answer the question, that is itself an answer. Stop and clarify before proceeding.
AnswerRisk LevelAction
Exposure cannot be undone; access cannot be easily revoked. Prohibited Without Governance Do not paste or connect such inputs unless policy, access controls, and monitoring already exist. See the full Risk Ladder.
Irreversible harm — financial loss, legal exposure, safety impact Critical Do not proceed without formal controls and documented human approval.
Professional, financial, or regulatory consequence High Verify with a qualified expert or primary source before acting.
Disruption to a team or process, recoverable Medium Add a review step before output is acted on.
Minor inconvenience, easily corrected Low Proceed with standard review.

NIST AI Risk Management Framework provides a rigorous governance foundation for organizations that need to scale beyond these starting points. See the Appendix for the full citation.

If you do not already have an AI policy, the Template Kits below turn this framework — the three questions, the policy areas, and the triage — into documents you can adopt directly.

Two Template Kits turn Modules 1 and 2 into ready-to-use documents in Word or PDF: the Individual Kit for one person using AI tools on their own, and the Team Kit for anyone responsible for how others use AI.

See the Template Kits →
Disclaimer: These templates are starting points for organizations without existing AI governance. They are not legal documents. Consult qualified legal counsel before implementing any policy.