Do You Need an AI Policy? What to Put in It (and What to Skip)
Yes - but a one-page policy your team actually reads beats a 30-page document that exists only to be ignored. What to include, what to cut, and why most AI policies fail.

The short answer
Yes, you need one — and it should fit on a single page. Only 38% of organizations have a comprehensive AI policy (ISACA, 2026), while roughly two-thirds of employees already use AI they believe is prohibited. A policy's job is to make the approved path obvious and the forbidden path specific. Everything else is theater.
Here's the uncomfortable pattern we see inside mid-market companies: leadership commissions an AI policy, legal writes eleven pages of principles, it gets posted to the intranet, and absolutely nothing changes. Meanwhile someone in finance is pasting a customer contract into a personal ChatGPT account because it's Thursday and the summary is due Friday.
That's not a governance failure in the abstract. It's a measurable cost. Shadow AI showed up in 20% of breached organizations in IBM's 2025 study, and those breaches cost an average of $670,000 more than incidents without it (IBM Cost of a Data Breach, 2025).
If you're the COO or founder who has to sign off on this, the question isn't whether to write a policy. It's what to put in it so it changes behavior instead of decorating a shared drive.
Do you actually need a written AI policy?
Yes, if anyone at your company uses AI at work — which, in practice, is everyone. The trigger isn't company size or industry. It's the moment employees start putting company data into tools you didn't procure, which has already happened whether or not you know about it.
The data on this is unambiguous. Two-thirds of office professionals report using AI tools at work despite believing they weren't permitted (PagerDuty, 2026). Nearly half of employees in a separate survey said they were using explicitly banned AI tools, and 58% admitted pasting sensitive data — client records, internal documents — into large language models (Anagram, via Newsweek).
And it's not a junior-employee problem. Senior decision-makers are more than twice as likely to use unapproved AI tools as the people they manage — 65% versus 31% (TrustedTech, 2026). The person who would approve the policy is statistically the most likely to violate it.
Meanwhile, 63% of organizations in IBM's research had no AI governance policy at all, and 97% of those that suffered an AI-related security incident lacked proper AI access controls. The gap between policy and reality is wider still: 33% of executives claim comprehensive AI usage tracking, but Deloitte's research found only 9% have working governance systems (via Kiteworks).
So the honest answer is: you need a policy, and you need to assume the first draft won't be followed.
What should an AI policy actually contain?
Five things, and they all fit on one page. A useful AI policy answers the questions an employee has at the moment they're about to use a tool — not the questions a regulator might ask in two years.
1. The approved tool list, with names. Not "enterprise-grade AI tools." The actual names: which chat assistant, which coding tool, which note-taker, and on which account. Vague permission is functionally the same as no permission — people default to whatever they already have open. This list should be short and it should be maintained monthly.
2. The data red lines. Name the categories that never go into an AI tool regardless of which one: customer PII, credentials, unreleased financials, source code under a customer NDA, health data. Be specific enough that someone can check their own behavior in four seconds. Cyberhaven's longitudinal research found the share of AI inputs containing sensitive data has climbed to 39.7% (Cyberhaven, 2026) — this is the clause that does the most work.
3. The human-review rule. State which outputs require a named human sign-off before they leave the building: anything client-facing, anything legal or financial, anything that becomes a decision of record. McKinsey's 2026 survey found 74% of respondents rate inaccuracy and 72% rate cybersecurity as highly relevant AI risks (McKinsey State of AI, 2026). Review is how you address the first one without banning the tool.
4. The disclosure rule. Where AI-generated content must be labeled — for customers, in deliverables, in hiring. If you operate in or sell into the EU, this is no longer optional: from 2 August 2026, Article 50 of the EU AI Act requires that any chatbot or copilot tell users they're interacting with AI, and that synthetic content be labeled (Gibson Dunn, 2026). The same date opens enforcement on the Article 4 AI literacy obligation — staff training proportionate to their role.
5. One named owner and one channel. A person, not a committee, plus a Slack channel or email alias where anyone can ask "can I use X for Y?" and get an answer inside a day. We covered the ownership question in depth in Who Should Own AI Automation Inside a Mid-Market Company? — the short version is that the owner needs budget authority and operational proximity, not just a title.
What should you leave out?
Most of what ends up in a first draft. The instinct is to write something comprehensive; the effect is something unreadable. Cut these:
Ethical principles sections. "We will use AI responsibly and transparently" changes nobody's Thursday afternoon. If a sentence can't be violated, it can't be followed. Put the values in your comms, not your policy.
Blanket bans. Banning a tool doesn't remove it — it moves it to a personal device where you have zero visibility and zero logs. That's strictly worse than a supervised version of the same behavior. If a tool is genuinely unacceptable, block it at the network layer and provide a named alternative in the same sentence.
Full regulatory frameworks you're not ready for. NIST's AI RMF is a risk-management methodology; ISO/IEC 42001 is a certifiable management system (Vanta, 2026). Both are legitimate, and both are the wrong first move for a 120-person company that doesn't yet know which tools its team uses. Borrow NIST's vocabulary now; pursue certification when a customer contract requires it.
Model-specific rules. Anything written about a named model version will be stale within a quarter. Write about data categories and use cases, which change slowly.
Long approval workflows for low-risk use. If getting permission to summarize a meeting takes a week, people will stop asking. Tier it: low-risk use is pre-approved, medium-risk needs the owner's sign-off, high-risk goes to a review. Three tiers, not seven.
Why do AI policies fail even when they're well written?
Because a policy is a communication artifact, not a control. It only changes behavior where the compliant path is faster than the non-compliant one.
In creative teams, 96% of organizations have formal AI restrictions — and 96% of employees use unauthorized tools anyway (Digital Applied, 2026). That's not a policy-quality problem. That's a policy that was written without providing a sanctioned tool that does the job.
The fix is boring and structural: pair every restriction with a provision. Ban personal accounts and buy enterprise seats the same week. Forbid customer data in public models and stand up an internal assistant that can access it safely. Require disclosure and give people the template. We go deeper on the technical side of this in How to Roll Out AI Without Leaking Company Data.
There's a performance argument here too, not just a risk one. Only 39% of McKinsey's respondents report any enterprise-level EBIT impact from AI — but the high performers who do were twice as likely to have leadership commitment and defined processes for measuring AI initiatives. Structure correlates with results. MIT's Project NANDA found roughly 95% of enterprise GenAI pilots deliver no measurable P&L impact (via Fortune); unclear rules are one of the reasons pilots stay pilots. We unpacked that failure mode in Why 95% of AI Pilots Fail to Reach Production.
The version we'd actually recommend
When we help a mid-market team set this up at Mesh Flow, the policy is rarely the hard part — it's a page, and it takes an afternoon. The hard part is the two weeks before it, spent finding out what people are already using.
Run a discovery pass first: check SSO logs, expense reports for AI subscriptions, and browser extensions. Ask the question amnesty-style — "tell us what you use, nobody's in trouble" — because you'll get a more accurate answer than any audit. Most teams find between eight and twenty tools nobody approved. Then write the policy around what you found, not around what you wish were true. A policy written against reality gets followed; one written against an imagined org gets ignored. (Shadow AI: Why Your Team Already Uses AI You Don't Know About covers how to run that discovery.)
Review it quarterly for the first year. Tool landscapes move faster than your handbook cycle.
Frequently Asked Questions
How long should an AI policy be?
One page, or two at most. Only 38% of organizations have a comprehensive AI policy, but length isn't what's missing — specificity is. If an employee can't find the answer to "can I paste this in?" within ten seconds, the document is too long regardless of how good it is.
Do small companies need an AI policy?
Yes, and arguably more urgently. Smaller teams have less visibility into tool usage: 59% of workers at companies with fewer than 10 employees say their employer has no clear AI policy or they aren't sure one exists, versus 34% at companies over 1,000. The exposure is the same; the guardrails are thinner.
What happens if we don't have an AI policy?
Practically, you accept the shadow-AI cost profile: IBM found shadow AI in 20% of breached organizations at a $670,000 premium per breach, and 97% of organizations with AI-related incidents lacked AI access controls. Legally, if you touch the EU market, the AI Act's transparency and literacy obligations become enforceable on 2 August 2026.
Should we ban ChatGPT at work?
Almost never. Bans move usage to personal accounts and personal devices, where you have no logs and no DLP. Provide an enterprise-licensed equivalent and ban the personal account, not the capability — that's a rule people can follow without slowing down.
Do we need ISO 42001 or NIST AI RMF?
Not to start. NIST AI RMF gives you a risk vocabulary and lifecycle discipline that's useful immediately and free to borrow. ISO/IEC 42001 is a certifiable management system worth pursuing when customers or regulators start asking — it's still rare enough in 2026 to be a genuine differentiator, but it's a program, not a first step.
The bottom line
- Write the policy, keep it to a page, and make it answer the questions people actually have mid-task.
- Include five things: approved tools by name, data red lines, human-review triggers, disclosure rules, and one named owner with a fast-response channel.
- Skip ethical principles, blanket bans, model-specific rules, and frameworks you're not ready to operate.
- Discover what's already in use before you write anything — a policy that ignores reality gets ignored back.
- If you want a second pair of eyes on the rollout rather than just the document, Mesh Flow does this work with mid-market teams.
Sources
- IBM — Cost of a Data Breach Report 2025
- Kiteworks — Analysis of IBM's 2025 Breach Report and Shadow AI
- McKinsey — The State of AI: Global Survey 2026
- ISACA Pulse Poll 2026 — via MarkTechPost, Enterprise AI Governance in 2026
- PagerDuty — Shadow AI Workplace Survey, 2026
- Anagram survey — via Newsweek, 2025
- TrustedTech — Shadow AI and Executive Risk, 2026
- Cyberhaven data-exposure research — via Anomity, 2026
- Gibson Dunn — EU AI Act Omnibus Agreement and 2026 Deadlines
- Vanta — NIST AI RMF and ISO 42001 Compared
- Digital Applied — Creative Teams AI Policy Compliance Gap, 2026
- MIT Project NANDA — via Fortune, 2025