How-To Guides

Build a Team AI Policy

A simple, one-page AI usage policy template for your team or small business — what's allowed, what's not, and how to keep data safe.

Why you need this

Teams using AI need clear guidelines. Without a policy, people either avoid AI entirely (missing the benefits) or use it recklessly (pasting confidential data into public tools). A simple one-page document prevents both problems.

Step 1. Define scope

  • •List which AI tools are approved (e.g., ChatGPT, Claude, Copilot).
  • •List which tasks can use AI (drafting, research, coding) and which cannot (legal advice, medical advice, anything requiring professional judgement).
  • •Keep it short — one page max.

Step 2. Set data handling rules

  • •No customer PII in public AI tools (don't paste names, emails, addresses, or financial data into ChatGPT, Claude, or Gemini).
  • •No confidential company data (financials, strategy, client lists).
  • •For sensitive work, use approved tools only or local AI (like Ollama).

Step 3. Set disclosure requirements

When must employees disclose AI use?

  • •Client-facing work: always disclose.
  • •Internal documents: not required but recommended.
  • •Code: add a comment noting AI assistance.
  • •Be clear about when AI output is presented as human work vs. AI-assisted.

Step 4. Set quality standards

  • •AI output must be reviewed by a human before use.
  • •Fact-check all claims and statistics.
  • •Verify code runs correctly before deploying.
  • •Spell-check and tone-check written content.
  • •The employee is responsible for the final output, not the AI.

Step 5. Template policy

Provide a copy-paste template for your team to adapt.

Policy Template

AI Usage Policy — [Company Name]. Approved tools: [list]. Permitted tasks: [list]. No customer or confidential data in public AI tools. All AI output must be reviewed by a human before use. Client-facing AI content must be disclosed. Questions: contact [manager]. Review date: [quarterly].

Step 6. Implementation

  1. 1.Review the policy with your team in a short meeting.
  2. 2.Get sign-off from key people.
  3. 3.Train staff on approved tools and prompt patterns.
  4. 4.Review quarterly and update as tools evolve.
  5. 5.A policy that isn't communicated doesn't exist.

Quick Tips

  • •Keep it simple — one to two pages maximum.
  • •Don't ban AI but guide it.
  • •Align with existing data protection policies.
  • •Update the policy as tools change.
  • •Keep the approved tools list current.
  • •Consider a simple approval process for new tools.

Need More Help?

StarCaller Academy offers 1-to-1 sessions to help you with any of these topics and more.