AI GOVERNANCE

How to Write an AI Policy for Your Business

Your people are already using AI tools, often in ways that quietly create data protection, IP and reputational risk. A good AI policy channels that use rather than pretending it is not happening. This page sets out what to put in one and how to make it stick.

Book a conversation

Why you need one now

The question is no longer whether your staff use AI; it is whether they do so with any guidance. Without a policy, employees paste confidential documents, client data and personal information into public AI tools, create work whose ownership is unclear, and rely on output no one has checked. That is shadow AI, and it accumulates risk silently until something goes wrong. A policy turns unmanaged use into managed use.

What a good AI policy covers

  • Acceptable use and approved tools: what AI can be used for, and which tools are sanctioned
  • Data rules: what must never be entered into public AI tools, above all confidential, personal and client data
  • Human oversight: where a person must review AI output before it is used or acted on
  • Transparency: when AI involvement must be disclosed, to customers, staff or regulators
  • Ownership and review: who owns the policy and how often it is revisited as tools and rules change

The mistakes to avoid

Two failures are common. The first is a blanket ban, which does not stop AI use, it just drives it underground where you cannot see or govern it. The second is downloading a generic template, adopting it unread, and giving it to no one to own, so it protects nobody. A workable policy is specific to how your business actually uses AI, and it has a named owner who keeps it current.

How to make it stick

A policy that lives in a folder changes nothing. Brief staff on it in plain terms, give it a named owner, and revisit it as tools and regulation move, because both move quickly. It should sit inside a wider AI governance approach and align with the direction of regulation such as the EU AI Act, so the policy and the law point the same way.

Getting it written with help

Writing a policy that is specific, usable and current is quicker with someone who has done it before. A fractional CIO or CISO can produce one that fits how your business actually works, brief the organisation on it, and fold it into a governance framework, rather than leaving you with a template nobody follows.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

Daniel writes AI policy the way it needs to work in practice: specific to the business, owned by someone, and part of a governance framework, not a generic document that protects no one.

Frequently asked questions

Why does my business need an AI policy?

Because your staff are already using AI, and without guidance they feed confidential, personal and client data into public tools, create work of unclear ownership, and rely on unchecked output. A policy turns that unmanaged use into managed use and closes the risk.

What should an AI policy include?

Acceptable use and approved tools, clear data rules about what must never go into public AI, where human oversight is required, when AI involvement must be disclosed, and a named owner with a review cadence. It should be specific to how your business actually uses AI.

Should we just ban AI tools?

A blanket ban rarely works; it drives AI use underground where you cannot see or govern it, which is more dangerous than managed use. A good policy channels AI use safely rather than pretending it is not happening.

Who should own the AI policy?

A named individual, senior enough to keep it current and enforce it, usually whoever owns technology or security. An unowned policy drifts out of date as tools and regulation change, and quickly stops protecting anyone.

Do we need an AI policy for the EU AI Act?

A policy is not the whole of AI Act compliance, but it is a core part of the governance the Act and data protection law expect, and it demonstrates oversight of how AI is used. For UK firms with EU customers, aligning the policy with the Act’s direction is sensible.

NEXT STEP

Not sure where your AI risk actually sits?

The free AI Readiness check shows where AI use is creating exposure in your business and what to address first, which is the right starting point for a policy that fits. When you want to talk it through, a conversation is the next step.

AI Readiness check Book a conversation