Briefing

What an Artificial Intelligence acceptable-use policy needs to contain

What belongs in it, what is padding, and what makes it enforceable.

Most Artificial Intelligence policies fail in the same way. They are long, they are written in the language of risk management, and the people expected to follow them have never read past the first page. A policy nobody reads is not a control. It is a document produced so that somebody can say a document exists.

A policy that works is short, specific to your organisation, and answers the questions a reasonable employee would actually ask. There are six of those.

1. What may I use

Name the tools. Not categories, not principles, the actual tools your organisation has decided are acceptable, and the versions or tiers that decision applies to.

This is the single most common omission. A policy that says staff may use "approved tools" without saying which tools are approved has moved the problem rather than solved it, and it puts every employee in the position of guessing.

If the list is short, that is fine. A short list that is accurate beats a long list that is aspirational.

2. What must never go in

Be concrete and use your own vocabulary. Not "confidential information", which everybody interprets differently, but the specific categories your organisation holds: customer records, staff files, anything covered by a confidentiality clause, unpublished financial results, security details about your own systems.

Where you can, give an example of the mistake rather than the rule. People generalise correctly from examples and poorly from abstractions.

3. What must be checked before it is used

Say where a human has to read the output, and be specific about what a check consists of. "Review before use" means nothing to somebody in a hurry.

The useful test is consequence. Anything that reaches a customer, a payment, a regulator or a decision about a person needs a competent reader who can decline it. Internal drafting that a colleague will read anyway usually does not.

Name who is competent to check. In most organisations this is obvious once asked and undefined until then.

4. Who decides on something new

There will be a new tool next month. If the policy does not say how a request is made and who answers it, the practical answer becomes that people either ask nobody or ask everybody, and both produce inconsistency.

One named role, a route for asking, and an expectation of how long an answer takes. That is enough. A decision framework that requires a committee will be bypassed the first time somebody is under deadline.

5. What happens when something goes wrong

State plainly what to do if confidential information has gone somewhere it should not have, or if output turned out to be wrong after it was acted on.

The point of this section is speed, and speed depends on people not being afraid. If disclosing a mistake reads as career-limiting, you will hear about incidents late or not at all, which is the outcome that actually causes damage. Say explicitly that reporting promptly is the expected behaviour and is treated as such.

6. Who is accountable for this policy

One name. Someone whose job it is to keep the tool list current, answer the questions in section four, and bring it back for review.

A policy with no owner ages out of relevance within a year, and an outdated policy is worse than none, because it gives false assurance to the people relying on it.

What to leave out

A definition of Artificial Intelligence. It will be wrong within a year, it will be argued about, and nobody's behaviour changes because of it.

A statement of principles. Responsible, ethical and transparent are not disputed by anyone, which is why they do not constrain anything. If a principle does not rule out a specific action, it is decoration.

A summary of legislation. Cite what applies to you, put the detail somewhere else, and keep the policy to what a person has to do.

How to tell whether it will hold

Two tests, both cheap.

Give the draft to somebody who will have to follow it and ask them what they may not do. If they cannot tell you in a sentence, it is not clear enough yet.

Then take a real request that arrived recently and follow the policy through to a decision. Most drafts fail here, because they establish who approves things without establishing what the approval is based on.

Length

Two pages. Three if your organisation is genuinely complex.

The instinct to be comprehensive is what produces the document nobody reads, and a policy that is not read has no effect on anything, whatever it says.

This briefing is free to read in full. There is no subscription, no sign up and nothing to unsubscribe from.

All briefings

Take the first step

Most engagements start with a short discussion about what your organisation is trying to achieve and where technology is getting in the way. From there we agree a clear scope and a fixed price before any work begins.