Skip to main content
← Back to Currents

AI Usage Policy: 5 Things It Should Actually Cover

August 26, 2026

AI ReadinessAI StrategyEnterprise AI
A rules board of crossed-out icons posted poolside while the AI-labeled robot floats obliviously in an inner tube

An AI usage policy is the written rulebook for how your people use AI tools at work: what can go into a prompt, which tools are approved, and what happens after a mistake. A policy that works covers five things: the data that never goes in, what a public share link exposes, each tool's retention settings, who approves new tools, and the consequence for a slip. Skip one and your people fill the gap with guesses.

The gap reaches the top of the company. In Deloitte's Board Practices Quarterly survey on board AI use, published July 21, 2026, 51% of public company respondents said their board had no board-specific AI policy. Six days later, on July 27, 2026, Axios reported that publicly shared Claude artifacts were showing up in Google search.

1. Name the data that never goes in a prompt. "Don't share sensitive information" isn't a rule, because nobody agrees on what sensitive means. List the categories: client contracts, anything under an NDA, unreleased financials, credentials and API keys, and personal data about employees or customers. Leave a category off the list and someone will decide for themselves. They'll guess wrong. If a key has already gone out, our plan for the first 24 hours after an API key leak is the next read.

2. Explain what a public share link exposes. The Axios story happened because people treated a public link as a private handoff. Anthropic told Axios that shared links aren't guessable, and that sharing one makes the content publicly accessible. So a link you post in a forum to ask for help can be found by a search engine. Your policy should say that in plain words, and it should cover every share button: chats, docs, and dashboards.

3. Check retention and training settings, tool by tool. Business and enterprise plans of many AI tools keep your prompts out of model training. Consumer plans of the same product often don't. "Use approved tools" means nothing until someone confirms which settings are on for your accounts. We check each tool and each account type separately, because one product name can cover two very different sets of terms.

4. Name who approves a new tool, and how fast. Deloitte's survey shows how informal this still is at board level. Among public company respondents, 47% said the company doesn't expressly support AI use in board and committee work, and 8% said company-sanctioned tools are available for it. A policy with no named approver and no turnaround time has a real rule anyway: whoever asks first gets a yes from whoever they ask. A slow approver has the same result, because people stop asking.

5. Say what happens when someone breaks it. A policy with no stated consequence gets ignored in the first busy week. Write the consequence down. Then say clearly that reporting a mistake beats hiding it, because you can't contain a leak nobody reported. People report fast only when reporting doesn't cost them their job.

When we review an AI usage policy during a readiness assessment, we read it the way a new hire on a deadline would. If that person can't tell in ten seconds whether a contract excerpt can go into a prompt, the policy has failed, however complete it looks.

None of this needs new software. It needs five decisions that someone writes down. If you're working out where AI governance fits in a wider plan, our AI readiness assessment starts there, and what an AI readiness assessment actually tells you covers what comes out of it. AI that ships, not AI that demos.

Have a problem worth solving?

Tell us what you are trying to build or modernize, and we will tell you honestly how we would approach it.