A good AI policy names what needs to exist, clearly enough that anyone in the business can follow it. These are the elements it should cover.
One approved business-grade AI environment. A single, organisation-controlled account with a no-training data agreement, so the tools your team uses cannot learn from what you put into them.
A hard rule against personal AI accounts for work data. Free and personal plans are off-limits for anything that touches the business, because that is where data leaks.
Clear rules on what data can and cannot go into AI tools. Client information, commercial details and anything protected by law or contract stays out unless the approved environment and the client allow it.
Human review of anything AI produces before it goes out. AI output is a draft, not a finished product. A person checks it before it reaches a client, a file or a decision.
A written record of where AI is used across the business. A simple register of the tools, who uses them and what they touch. This is also the direction ISO 42001 points, and it makes the difference between governing AI and hoping for the best.
Being upfront with clients about how AI is used on their work. No surprises. Clients know where AI is in the process and where a person is still in charge.
Training staff on the rules. A policy nobody has read is not governance. Your people need to understand what is allowed, what is not, and why, so the policy holds in practice rather than only on paper.