Every engagement starts with a clarity intake — no blind guesses, no cold meetings.
Fusion Advisory
Insights/Implementation & Scaling

The One-Page AI Policy Every Company Should Have (Steal This)

Governance8 min readJuly 15, 2026

Your team is already using AI, with or without permission. A practical one-page policy — approved tools, data rules, disclosure, and review — you can adopt this week.

MS
Mike Sweigart
Managing Partner — Technology & AI

Your team is already using AI. Right now. Today. Someone in finance pasted a vendor contract into a chatbot to get a summary. Someone in marketing drafted next week's campaign copy. Someone in ops asked it to clean up a spreadsheet full of customer records.

They did not ask permission, because there is no one to ask.

Here is the part that matters: the absence of a policy is itself a policy. It is the worst one available to you. When there is no sanctioned path, people do not stop — they route around you. They use personal accounts, on personal devices, under personal terms of service. Your company data goes somewhere, and you have no record of where, no ability to audit it, and no way to correct course.

You have not prevented AI use. You have only made it invisible.

Why should the policy be one page?

Because a policy nobody reads protects nobody. That is the entire argument.

The fourteen-page template you found online was not written to change behavior. It was written to survive a lawsuit. Those are different jobs. A long policy creates a paper trail; a short policy creates a decision rule your bookkeeper can apply at 4:45 on a Thursday without calling anyone.

Long policies fail for exactly the same reason long onboarding fails — the volume signals thoroughness to the author and signals "skip this" to the reader. Research on workplace policy comprehension has pointed in one direction for decades: length and compliance move in opposite directions.

So the goal shifts. You are not writing a compliance artifact. You are writing a document that enables adoption with guardrails — one that tells people yes, here, this way, rather than a wall of no. That framing is also what separates the companies where AI takes hold from the ones where it quietly dies, which we cover in more depth in our piece on why AI projects fail at the adoption layer rather than the technology layer.

What goes on the page?

Six sections. Nothing else. Here is the skeleton — adapt the specifics, keep the structure.

1. Approved tools

Name the tools your company sanctions, and name the tier. This is the single most overlooked line in most policies.

The tier determines the data terms. A free consumer account and a business or enterprise account from the same vendor can carry meaningfully different commitments around retention, training, and administrative control. Do not assume — read the terms of the specific plan you are actually paying for, and write the conclusion into this section in plain English.

Something like: "Approved: [Tool A], Business tier, company-provisioned accounts only. Anything else requires a conversation with [owner] first." If you want to understand what you are actually agreeing to before you write this line, start with our companion piece on where your data actually goes when your team uses AI.

2. What data may and may not go in

Give people three buckets, not a taxonomy.

  • Public or general — anything already published, or generic work with no company specifics. Marketing copy, industry research, general drafting, "explain this concept." Green light, no approval needed.
  • Internal — non-public but not sensitive. Process documents, internal memos, anonymized operational data. Allowed in approved tools on approved tiers only.
  • Restricted — never goes in, full stop. Customer PII, employee records, financials that are not public, credentials and keys, source code if that is your product, and anything covered by an NDA or a client contract.

Then add the one sentence that makes this usable: "If you are unsure which bucket something is in, treat it as restricted and ask."

3. Human accountability for output

A named human owns anything that leaves the building. Not a team. A person.

Write it as a rule: anything going to a customer, a regulator, a lender, or the books gets reviewed and approved by an accountable human before it goes. AI drafts. Humans approve. The person who sends it owns it, exactly as they would have if they had typed every word themselves.

This section quietly resolves the anxiety underneath most AI conversations in a company — the sense that the machine is taking over judgment. It is not, and saying so explicitly helps. We unpack that dynamic further in our article on what AI actually changes about roles versus what it leaves alone.

4. Disclosure

Be specific about when you tell people, because vagueness here produces either over-disclosure or none.

A workable default: disclose when AI involvement is material to the judgment being bought — an analysis, a recommendation, a deliverable a client is paying you to think through. Do not bother disclosing routine drafting assistance, formatting, summarizing an internal call, or cleaning up an email. Nobody discloses spell-check.

And add the override: if a client contract or a regulator says otherwise, the contract wins.

5. Security basics

Three lines will do most of the work.

  • Company accounts only. Not personal ones. This is what gives you visibility and offboarding control.
  • Never paste credentials, API keys, or passwords into any AI tool.
  • If you make a mistake, report it. You will not be punished for reporting.

That third line is not softness — it is operational self-interest. The mistakes that hurt companies are the ones nobody mentioned for six weeks. A punitive posture buys you silence, and silence is the expensive outcome. This is the same category of failure we describe in what actually goes wrong in AI implementations.

6. Who to ask, and when this gets reviewed

Put a name and a date on the page. "Questions: [Name, email]. Next review: [date, roughly quarterly]."

The date matters more than it looks. This field is moving quickly, and a policy with a review date is a living document your team trusts. A policy with no review date is a fossil the moment your vendor changes a term.

One practical note: this is operating guidance, not legal advice. If you are in healthcare, financial services, insurance, or another regulated industry, have counsel read the page before you circulate it. It is one page — that is a short review.

What should you deliberately leave out?

Three things, all of which feel responsible and all of which make the policy worse.

Exhaustive tool lists. The moment you enumerate fourteen approved tools, you have created a document that is wrong within a quarter. Name your primary sanctioned tool, name the tier, and define the process for adding one. The process outlives the list.

Blanket bans. "No AI without written approval" produces exactly one outcome: the same usage, now hidden from you, on personal accounts. You have traded a manageable risk for an invisible one. If you are inclined toward a ban because the technology feels unfamiliar, the higher-leverage move is building fluency first — that is the argument in our piece on building real AI literacy on your team.

Aspirational language. "Use AI ethically and responsibly." "Exercise good judgment." These sentences feel like governance and function as decoration. They give no one a decision rule. Test every line against a simple standard: could a new hire, alone, use this sentence to decide whether to paste a specific document into a specific tool? If not, cut it or make it concrete.

How do you roll this out in a week?

Five steps, one per day, no committee.

  • Monday — pick the owner. One name. Usually an ops leader or a COO, not IT by default. This person answers questions and owns the review date.
  • Tuesday — choose the sanctioned tool and tier. One primary tool. Provision company accounts. Read the terms for that specific tier.
  • Wednesday — write the page. Six sections above. If it runs past one page, you are over-writing it.
  • Thursday — say it out loud, in a real meeting. Not an email. Fifteen minutes, live, and lead with why — that you want people using these tools, that this is the safe lane, and that reporting a mistake carries no penalty. A policy announced by email reads as restriction. The same policy announced in person reads as permission.
  • Friday — set the review date. Put it on the calendar with the owner's name on it. Done.

If you want a clearer read on where your organization actually stands before you write anything, our AI readiness assessment takes a few minutes and will tell you which of these steps is your real bottleneck. And once the page exists and people are using sanctioned tools daily, the natural next question is when to move from ad-hoc prompting into something durable — which we walk through in going from ChatGPT to actual company software and in building an operations team that can absorb this.

The bottom line

You are not choosing between AI use and no AI use. That decision was made for you, informally, by people who were just trying to get their work done faster. You are choosing between visible use you can guide and invisible use you cannot.

One page. Six sections. A named owner and a review date. It will take an afternoon, and it will do more for your risk posture than a fourteen-page document sitting unread in a shared drive — because the point was never the document. The point is that when someone is holding a client contract and wondering whether it can go in the box, they know the answer without asking.

If you would like a second set of eyes on your page before it goes out — or you want help deciding which tier and which tool actually fit how your company operates — tell us about your situation here and we will point you in the right direction.

What’s next?

This article is designed to help you move through the implementation & scaling stage of your AI evaluation.