The company has no AI policy. The staff have several, one each, unwritten.
Ask a room of staff whether they use AI at work and most will say no. Ask whether they have ever pasted an email thread into an assistant to summarize it, or asked one to tidy up a proposal, or used one to write the formula they could not remember, and most will say yes.
This is not a problem with the staff. It is what happens when a company has no answer to “what are we allowed to do with this”, so every person supplies their own.
Some are cautious. Some are pasting customer data into a free tool with a privacy policy nobody has read. The company cannot tell which is which.
What the unwritten plan costs
Its data, slowly. Not in a breach, usually, but in a steady leak of the information a business is made of: who its customers are, what it charges, what its problems are. Each paste is small. None is logged.
Consistency. Two people in the same team produce two different qualities of work with two different tools, and nobody can say which approach is better because nobody is looking.
The thing it was hoping for. Scattered private use does not change a process. It makes individuals a little faster at tasks that were never the bottleneck.
A policy people can follow
The fix is a page. One page, written for the people who will follow it, not for the people who will file it:
- what you may use AI for, in plain categories
- what data may go into which tools, with the tools named, so nobody has to guess
- what must never be pasted anywhere: customer personal data, financial details, anything under contract
- who to ask when it is not clear
- a sentence saying the company wants people using these tools well, so the page reads as permission with edges rather than a prohibition
Then a briefing. Half a day, for the leadership team first and then everyone, on what these tools do well, what they do badly, and how to tell the difference when a vendor calls. Not a demo. A working session on the company’s own tasks and documents. The template is here.
Where this goes next
The policy is the second of the five things a real AI plan contains, and it is the fastest to do. The first is knowing where AI would actually pay off in the business, which is a few weeks of part-time work. Once both exist the company has something its competitors mostly do not: a written answer to the question, and staff who know what it is.
Until then, the plan exists. It is just written in a hundred private chat histories, and nobody can read it.