We want a first AI data policy on paper, but do not know where to start
You do not need forty pages. A workable first AI policy fits on one or two A4s and has five sections: purpose, allowed tools, data classification, output control, incident. Write it in plain language so colleagues actually read it.
Try this first
- 1Section 1, purpose: write in two sentences why AI is allowed and what the company wants from it. Also state explicitly what you do not want, for example customer data in public chats.
- 2Section 2, allowed tools: list business-paid tools that are allowed, with version. Private accounts or free tiers without business terms go on the not-allowed list explicitly.
- 3Section 3, data classification: three levels is enough. Public can go anywhere, internal only into approved tools, confidential and personal data go nowhere without written approval.
- 4Section 4, output control: AI output is a first draft, not the final version. Whoever sends or publishes owns the facts, numbers and sources.
- 5Section 5, incident: what to do if AI did something wrong or if customer data ended up in it. One contact person, one timeframe, no blame culture.
When to bring us in
Want a template that fits your sector and existing security policy, we can fill in the first version with you.
See also
- Can I paste a customer file or email into ChatGPT?Depends on the account and settings. Free ChatGPT and a Team tenant behave very differently from what most people assume.
- I want a one-page AI policy for my teamA real one-pager beats a thick document nobody reads. Four headers and concrete examples.
- How do I tell if an AI answer is made up?Models sound confident even when they are wrong. A few habits catch most mistakes.
None of the above fits?
Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.
Or skip the DIY entirely
Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.