An AI policy, drafted in five minutes.
Most organizations are exposed because people are using AI tools with no policy in place, and nobody decided that on purpose. Answer ten questions and watch your draft build as you go. The full policy comes as an editable Word document.
Your draft continues with:
A starting draft built from your answers, not legal advice. Have counsel who knows your industry review it before you adopt it.
A policy is the first control, not the last.
What usually comes next, in order.
Business accounts
Move people off personal and free accounts onto ones you manage, with sign-in controls and model training turned off.
Data boundaries
Label what is confidential, and set up the tools so the rules in the policy are enforced, not just written down.
Ownership
Someone who approves tools, keeps the list, and answers when something goes wrong. The policy names the role; the organization has to fill it.
Why does a small organization need an AI policy?
Because people are already using AI tools, usually personal accounts of consumer tools, and often with customer or company information pasted in. Most organizations that are exposed did not decide to be. A short written policy is the cheapest control there is.
Is this legal advice?
No. It is a solid starting draft built from your answers. Have counsel who knows your industry review it before you adopt it, especially in healthcare, finance, education, or government.
What happens to my answers?
The preview is built in your browser. When you unlock the full draft, your answers are sent to us so we can email you the Word version, and they are used for nothing else.
What comes after the policy?
Approving tools, moving people onto business accounts, and deciding who owns AI risk. The AI Readiness Assessment scores where you stand on all of it.