Blog · October 3, 2026 · 5 min read

How to write an AI policy for your team (the 7-part checklist owners actually finish)

Most AI policies fail twice: too vague to enforce, or too legal to read. Seven sections, plain English, finishable in one sitting — with a free template to start from.

“We have an AI policy” usually means one of two failed documents: a one-line rule (“don't paste confidential info”) nobody can apply, or a nine-page legal memo nobody reads. Both leave the employee alone with a blank prompt box making judgment calls they were never equipped for.

Who this is for

An owner or office manager at a 10–500 person company — no security team, no general counsel, and staff already drafting client work with AI. If your team touches other people's data — client financials, tenant records, patient files, candidate résumés — this checklist is written for you.

The 7-part checklist

1. Name the approved tools — and the waitlist. List what's sanctioned today. Anything not on the list isn't banned forever; it's “ask first.” A policy with no path to “yes” gets routed around.

2. Sort your data into three buckets. Green: public, already shared, generic. Yellow: internal but not client-identifying. Red: anything naming a client or containing their records — financials, health data, IDs, contracts. The buckets do the work; the rest of the policy just references them.

3. Say what to do with Red — before it happens. “Never paste Red data into any AI tool” is half a rule. The other half: what the employee does instead — strip the names, use the approved tool with the guardrail on, or ask. People follow rules that come with a move.

4. Redaction is allowed; hiding is not. Make it explicit that removing identifiers re-classifies a draft — an anonymized case review is Yellow, not Red. This single paragraph does more for compliance than any threatening clause.

5. Set the review rule for outbound work. AI-assisted client-facing work gets human-checked before it leaves. Name who checks (the sending employee is fine) and what they check (facts, names, numbers, voice).

6. State the monitoring honestly. If tools watch for policy violations, say so in this document, in the same breath as the rules. An AI policy that hides its own enforcement teaches employees to distrust section one.

7. Give it an owner and a date. Who answers questions, who may approve a new tool, when the policy gets revisited. Undated policies rot into folklore.

The part that makes it stick

A policy that lives in the tools is worth ten that live in the handbook. CoaPro turns a written policy like this into browser-level enforcement — the red-bucket rule shows up as the prompt is written, with a cited warning and a redact button. The free template implements this exact structure; see it enforced in a 30-minute walkthrough.

Sources

  • Structure informed by SANS AI security policy templates and NIST AI RMF framing (secondary sources; both name the same sections)
  • CoaPro policy template — https://coapro.org/ai-policy-template

Third-party findings quoted with their sources, per our claims discipline — never presented as our own data.

See it on your own people.

A 30-minute walkthrough of the real product, then a 60-day pilot with one team. No slides, no auto-renew.

Book a demo