Employees experiment with AI whether or not you publish a policy. A short, readable plan beats a 20-page handbook nobody opens. Share it in your next team meeting and post it where people already look for procedures.
Section 1: Approved tools
List tools the company pays for and permits. Ban shadow apps that upload customer data to unknown servers. Include how to request access.
Section 2: Never paste without approval
Examples: full credit card numbers, medical details, unreleased financials, employee disciplinary notes, and contracts under NDA.
Section 3: Human review required
Anything a customer, regulator, or partner will see needs a named reviewer. AI drafts; humans publish.
Section 4: Reporting mistakes
Define a no-blame channel for reporting accidental data paste or wrong sends. Quick reports prevent repeat incidents.
Section 5: 30-minute onboarding
Walk through one real task live: draft, edit, approve. Hands-on beats slides. Schedule refreshers when you add tools or change policies.