Most AI use policies fail for the same reason most policies fail: they're written to cover every possible scenario instead of the handful that actually come up. The result is a document that's technically comprehensive and practically useless — long enough that no one reads past the first page, vague enough that it doesn't answer the question someone actually has at 4pm on a Tuesday. A policy that gets used is usually shorter, more specific, and written around real situations rather than hypothetical edge cases.

Start With Questions, Not Rules

Before drafting anything, collect the actual questions people are asking. What tools are staff already using informally? Where has someone hesitated, unsure if something was allowed? Where has AI already caused a small problem — an inaccurate summary sent to a client, a chatbot response that overstepped? A policy built from these real cases will cover the situations that matter and skip the ones that don't.

Four Things Every Policy Needs

1. A clear list of approved tools, updated on a set schedule (quarterly works for most teams) rather than left to go stale. An approved list that hasn't been touched in a year signals that the policy isn't being maintained.

2. A default answer for new tools. Rather than requiring sign-off for every new tool someone wants to try, give people a simple self-check (data sensitivity, output stakes, human review) they can run before asking permission — and a clear channel for the cases that don't clear it.

3. Explicit guidance on sensitive data, stated in plain terms: what can never go into a prompt, and what requires a business-tier or education-tier agreement first. This is the section people actually need on hand, so it should be the easiest to find.

4. A note on accountability, making clear that AI-assisted output still carries the same review standards as any other work product. The goal isn't to slow people down — it's to make sure "the AI said so" is never treated as a substitute for judgment.

Keep It Living

A policy that's reviewed once and then filed away will be wrong within six months, because the tools and the ways people use them keep changing faster than most institutional documents do. Building in a short quarterly review — even fifteen minutes with the right two or three people — keeps the policy matched to what's actually happening instead of what was happening when it was written.

Try Themis

Get personalized ethics guidance: Visit AI Ethics Advisor

Navigating AI assessment decisions requires balancing multiple ethical considerations unique to your context. Themis provides personalized guidance for your specific assessment challenges, helping you make informed decisions that protect both efficiency and fairness.

Wear Your Ethics

Learning AI ethically isn't just about what you know—it's about the values you carry forward. Our collection features thoughtfully designed apparel and accessories that reflect your commitment to responsible AI use.

Reply

Avatar

or to participate

Keep Reading