Short answer
Your first AI policy does not need to be a legal thesis. It needs to tell staff which tools are approved, what they may use AI for, what data must never go into public tools, when human review is mandatory, who owns the rules, and how to report mistakes.
- Two pages is enough for a first enforceable policy.
- The key control is data classification: public, internal, confidential, and restricted.
- Human review is mandatory before AI affects customers, money, employment, law, safety, or security.
Many organisations have no AI policy not because they are careless, but because the subject feels too large. Leaders imagine a legal manual, a technical standard, a training programme, and a risk register all at once. So nothing gets written, while staff quietly use AI anyway.
That is the wrong trade. A two-page policy that people understand and managers enforce is a real control. It gives staff permission to use AI where it helps, and a clear stop sign where the risk is too high.
The two-page template
Use the clauses below as a starting point. Do not copy blindly. Replace roles, tool names, data categories, and escalation contacts with your own reality.
Purpose and scope
"This policy applies to all employees, contractors, interns, and partners using AI tools for company work, whether the tool is paid, free, embedded in another product, or accessed on a personal account."
Why it matters: This prevents the common loophole: "I used my own account, so the company policy did not apply."
Approved uses
"Staff may use approved AI tools for drafting, summarising, translating, brainstorming, formatting, public research, meeting notes, and first-pass analysis where a human checks the result before use."
Why it matters: A policy that only says no will be ignored. Name the useful work you actually permit.
Prohibited data
"Do not enter passwords, API keys, bank files, payroll, health records, legal matters, customer personal data, unreleased financials, trade secrets, or confidential client material into public AI tools."
Why it matters: The clearest control is a short list of data that never belongs in public tools.
Human review
"AI output must be reviewed by a competent person before it is sent to customers, used for employment decisions, filed with regulators, posted publicly, or relied on for financial, legal, medical, or security decisions."
Why it matters: AI can sound certain when it is wrong. High-impact work needs named human ownership.
Tool approval and ownership
"The operations lead owns the approved-tool list, the IT lead owns access and security settings, and the department manager owns correct use inside their team."
Why it matters: Policies fail when nobody owns them. Split ownership by decision type.
Incident reporting
"If sensitive data is entered into the wrong AI tool, report it immediately to the named owner. The company will investigate, contain, document, and improve controls without punishing good-faith reporting."
Why it matters: People hide mistakes when reporting feels dangerous. Fast disclosure matters more than blame.
Page one: acceptable use
The first page should be practical enough for a staff member to use without calling IT. Name approved tools. Name allowed uses. Name the data that never goes into public AI. If your organisation uses enterprise AI products, say which ones are approved for internal documents and who may access them.
A good rule is to classify data into four buckets. Public data can go into approved tools. Internal data can go into approved business tools. Confidential data needs a business tool with the right contract and access controls. Restricted data needs explicit approval or a private workflow.
Page two: review, ownership, and incidents
The second page should make accountability visible. AI-generated work must be reviewed before customers, regulators, banks, employees, or the public rely on it. AI may assist a decision; it should not become the accountable decision-maker.
Name the policy owner. Name the person who approves tools. Name the person staff call when they accidentally paste the wrong thing into the wrong tool. Then set a review date. In the first year, quarterly review is sensible because tools, contracts, and staff behaviour are changing quickly.
The paragraph to avoid
Do not write: "Employees may use AI responsibly." It sounds reasonable and controls nothing. Responsible according to whom? Which tool? Which data? Which review step? Which manager? A policy is useful only when two people reading it reach the same answer.
The two-page version is not the end of AI governance. It is the starting line. As AI use grows, you can add a register of approved tools, supplier reviews, staff training, audit logs, and deeper controls for agents. But you do not need all of that to begin.
For the data rules behind this template, read Where Does Your Business Data Go When You Use AI?. For agent permissions, see Agentic AI, Explained for the Business Owner.
Frequently asked questions
How long should a company AI policy be?
For a small or mid-sized firm, two pages is enough to start: scope, allowed uses, prohibited data, human review, approved tools, ownership, and incident reporting. A short enforced policy beats a long document nobody reads.
What data should never go into public AI tools?
Passwords, API keys, personal customer data, payroll, bank files, health records, legal matters, trade secrets, confidential client material, unreleased financials, and anything your contracts or privacy law require you to protect.
Who should own the AI policy?
One senior business owner should own the policy, usually operations, risk, HR, or IT depending on the organisation. IT should control access and technical settings, while managers remain responsible for how their teams use AI.
Can staff use AI for customer communication?
Yes, but AI-generated customer messages should be reviewed before sending unless the use case is tightly controlled, low-risk, and already approved. The customer must not receive invented facts, false promises, or confidential details.
How often should the AI policy be reviewed?
Review it at least quarterly in the first year, and immediately after a new AI tool, incident, customer requirement, or regulatory change. AI use is changing too quickly for an annual-only review.
Sources and usage note
This is a management template, not legal advice. Regulated organisations should review it against their privacy, employment, sector, and contract obligations.
About the author
Peter Bamuhigire
Software architect and ICT consultant — business management systems across Africa
Peter Bamuhigire has led ERP, SaaS, and custom software programmes for organisations in Uganda, Kenya, Rwanda, DRC, Senegal, Sierra Leone, and Guinea over the last fifteen years, and runs the practice as principal architect.