An AI policy, drafted in five minutes.

Most organizations are exposed because people are using AI tools with no policy in place, and nobody decided that on purpose. Answer ten questions and watch your draft build as you go. The full policy comes as an editable Word document.

3. Which AI tools will you allow?
4. How are people signed in today?
5. What must never go into an AI tool?
A role, not a name, so the policy survives staff changes.
7. When must a person review AI output?
8. When do you tell people AI was used?
9. Annual training?

Your draft continues with:

    Unlock the full policy.

    See every section here, and get it as an editable Word document by email.

    A policy is the first control, not the last.

    What usually comes next, in order.

    Business accounts

    Move people off personal and free accounts onto ones you manage, with sign-in controls and model training turned off.

    Data boundaries

    Label what is confidential, and set up the tools so the rules in the policy are enforced, not just written down.

    Ownership

    Someone who approves tools, keeps the list, and answers when something goes wrong. The policy names the role; the organization has to fill it.

    Questions about the policy.

    The ones we hear most, with straight answers.

    All questions

    Why does a small organization need an AI policy?

    Because people are already using AI tools, usually personal accounts of consumer tools, and often with customer or company information pasted in. Most organizations that are exposed did not decide to be. A short written policy is the cheapest control there is.

    Is this legal advice?

    No. It is a solid starting draft built from your answers. Have counsel who knows your industry review it before you adopt it, especially in healthcare, finance, education, or government.

    What happens to my answers?

    The preview is built in your browser. When you unlock the full draft, your answers are sent to us so we can email you the Word version, and they are used for nothing else.

    What comes after the policy?

    Approving tools, moving people onto business accounts, and deciding who owns AI risk. The AI Readiness Assessment scores where you stand on all of it.

    Three ways to start.

    Pick the one that matches where you are. None of them costs anything.

    See where you stand

    Ownership, shadow AI, data, and security, scored in ten minutes.

    Take the AI Assessment

    Talk it through

    Thirty minutes on rolling out AI safely. No sales sequence.

    Book a Call

    Read more

    Why AI governance starts before the first tool is bought.

    Read the Article