An internal AI usage policy is a document that tells employees what is and is not permitted when working with artificial intelligence. It arises for a simple reason: tools are used even without permission, and without rules, contracts, clients' personal data and unpublished company information end up in them. A usable policy is short and specific. It defines the approved tools and the way a new tool is approved, clearly states what data must not be entered into them, specifies where AI output needs to be verified by a human and where it is prohibited entirely, addresses the labelling of generated content and copyright, and sets out who an incident is reported to. Supplement it with brief training and a list of approved tools that you update regularly, otherwise the policy becomes a dead document.
See also: Register of AI systems, Employee AI Literacy, AI management system.