Skip to content

Leadership in the Age of AI

What Your AI Policy Should Say.

By Carlos CoutinRevenue Streams LLCOctober 8, 20263 min read

Most AI policies fail in one of two ways. They are so long that nobody reads them, or so strict that everybody works around them. Either way, your people keep using AI, and the policy protects nobody.

A good AI policy is short enough to remember and specific enough to act on. Its job is to let people use AI with confidence, because they know where the lines are. A policy that only says no does not stop AI use. It only stops people from telling you about it.

Does a company with 50 to 300 people need one?

Yes, as soon as people use AI at work, and in most companies that day has already passed. Without written rules, every person decides alone what is safe to paste into which tool. Some will be so careful that they get nothing from the tools. Others will not be careful enough. Neither is a choice you would make on purpose. Written rules also protect the people already doing the right thing, because they no longer have to guess.

There is also the outside world. A client asks how their information is handled. A board member asks who approved the tools. A buyer asks during diligence. A written policy is the difference between an answer and an apology.

What every AI policy must answer

If a policy cannot answer these in plain words, it is not finished.

  1. Which data may go into which tool? Sort your information into a few plain groups, such as public, internal and confidential, and say where each group may go. Client information, personal information and anything covered by a contract get the strictest line. When in doubt, the stricter group wins.
  2. Which tools are approved, and on which accounts? Company accounts, set up by the company, with privacy settings the company chose. Personal accounts are where the risk hides.
  3. What must a person check before AI work leaves the building? AI drafts, analyzes and automates. People decide. Anything that goes to a client, a regulator or the board is read and owned by a person, because accountability does not transfer to software.
  4. Who decides when something new comes along? New tools appear every month. Name one owner and a short path for asking. If a yes takes weeks, people will stop asking.
  5. What happens when someone makes a mistake? Say it plainly: report it fast, and reporting is never punished. The mistake you hear about in an hour costs far less than the one you discover in a quarter.

What to leave out

  • Legal language nobody reads. Write it the way you would explain it to a new hire on their first day.
  • A list of every AI tool on the market. List what is approved, and how to ask about the rest.
  • Rules you will not enforce. Every rule nobody follows teaches people to ignore the rules that matter.

For most companies, one or two pages is enough. Have your counsel review it, then keep it short enough that people actually read it.

Signs your current policy is not working

  • People ask you privately whether they are allowed to use a tool.
  • Nobody can name who approves a new one.
  • The policy was written once and has not been opened since.
  • The licenses you pay for sit unused while people use their own accounts.

Who should own it

Not IT alone, and not legal alone. IT knows the tools. Legal knows the contracts. Neither sees how the sales team writes proposals or how finance closes the month. Give the policy one owner on the leadership team, with input from operations, IT, HR and finance, and have the CEO sign it. The owner’s job is to keep the path to yes short and the rules current.

Then give it a rhythm. Review it every quarter, and any time a major tool changes. When the tools change next month, the policy should already say who updates the rules.

How to roll it out

Teach it. Do not just email it. Walk each department through the policy using its own work: the proposal, the payroll file, the client report. Show one good use and one line nobody crosses, both from that department’s own week. People remember the example long after they forget the rule. Then keep it where the work happens, not in a folder nobody opens.

If you are not sure what your people use today, find out first. Shadow AI is usually the first thing a policy has to address. Every Revenue Streams engagement sets which data may go into which tool, and who decides. Those rules are written down and owned by the company, as part of AI adoption. The standard behind that work is published in the responsible AI principles.

A good AI policy shows your people where the guardrails are, so they can move faster inside them.

Leadership in the Age of AI

Which AI does your team use, and for what?

Start with a private executive briefing. 90 minutes with your leadership team. You leave with a clear first move.

Subscribe

Insights. Strategic thinking for founders and CEOs navigating growth.