AI in Business — Foundations112 · Module I · Lesson 03 of 5
Article · 12 min

The internal AI policy

What every firm now needs, and how to write it.

Summary

Every firm now needs an internal AI-use policy. Scope: which tools employees may use, with what data, for what tasks, with what disclosure. Written, dated, communicated, and enforced. The absence of a policy is itself a policy — usually the wrong one.

Objectives
  • 01State the six sections every AI policy must cover.
  • 02Distinguish allowed, review-required, and prohibited use.
  • 03Design an enforcement mechanism proportionate to your risk.
The Lesson

The six sections

1. Approved tools and how to request additions. 2. Data classifications and what can go into which tools. 3. Task categories: allowed, review-required, prohibited. 4. Disclosure requirements (to customers, to reviewers, in commits). 5. Training and onboarding. 6. Incident response when the policy is violated.

Enforcement

Policies that are not enforced are worse than no policy — they create the illusion of governance while producing none. Proportionate enforcement: audit logs on approved tools, periodic reviews, clear consequences for violations of the data classifications. Overkill enforcement drives shadow AI use.

Key Ideas
  • The absence of a policy is a policy — usually a bad one.
  • Proportionate enforcement beats theater or absence.