Writing an AI usage policy your team will actually read
28 May 2026 · 6 min read

Most AI usage policies fail for the same reason: nobody reads them. They are twelve pages of borrowed legal language, copied from a template built for a company ten times your size, listing tools you do not use and scenarios you will never face. It sits in a shared drive, unread, until an auditor or a nervous client asks for it. That document does not change how anyone behaves, and behaviour is the whole point.
A good AI usage policy for a small team is short, specific, and tied to the tools you actually open every day. It tells people what they can use, what they must never do, and who to ask when they are unsure. One page, written in plain language, that a new hire can absorb in five minutes. This guide walks through what to put in it, how to keep it accurate, and how to roll it out so people genuinely read and follow it.
A generic template tries to cover every AI system in existence, so it stays vague. Vague policies give no real guidance. When someone is about to paste a client contract into a chatbot to summarise it, "use AI responsibly and in line with company values" does not stop them. "Do not paste client documents into ChatGPT" does.
Specificity also makes the policy honest. If you name the five tools your team really uses and describe how each one should be handled, you are documenting reality rather than an aspiration. That matters under the EU AI Act, where almost every small business is a deployer, an organisation using AI systems under its own authority in a professional context, rather than a builder of them. A deployer's job is to use these tools carefully and be able to show they did. A policy anchored to your real toolset is part of that evidence. A generic one that describes tools you have never touched is not.
The heart of the policy is a short table of the AI tools your team is allowed to use, each with a note on how sensitive its use is. You do not need a formal risk assessment for everyday tools. You need a simple, honest tiering so people know where the care is required.
The EU AI Act sets out four risk tiers, and they are a useful frame here:
For each approved tool, write one line: the tool name, what it is used for, and its tier. Anything not on the list is not approved until someone checks it. That single rule stops the quiet spread of unvetted tools, which is how client data ends up somewhere nobody intended.
Every policy needs a short list of things that are never allowed, stated plainly. Keep this section blunt. These are the rules that protect your clients, your reputation, and your legal position all at once.
Sections to include in your one-page policy:
These three sit close together because they all cover how AI meets the outside world.
Disclosure. Article 50 of the EU AI Act sets transparency duties. If a chatbot talks to your customers, it must tell them they are dealing with AI. If you publish AI-generated or manipulated content, such as a synthetic image or a deepfake-style video, that must be disclosed too. Turn this into a simple house rule: label AI chat interfaces clearly, and mark AI-generated media as such. It is easier to build this habit now than to retrofit it later.
Confidentiality and data handling. Spell out what counts as sensitive: client data, personal data, unreleased work, credentials. State where such material may go, which is usually only into tools you have vetted and that offer a business agreement covering data use, and where it may never go, which is public consumer tools. Keep it concrete so the answer is obvious in the moment someone is tempted.
Human oversight. The rule is simple: a person is responsible for every AI output that leaves the building or feeds a decision. AI drafts, a human owns. Whoever sends the email or ships the design is accountable for it, exactly as if they had written every word themselves. This one line does more for quality and safety than any amount of technical detail.
People will hit situations the policy did not anticipate. That is fine, as long as they know where to go. Name a person or a role, whoever owns AI questions at your company, and make clear that asking is always the right move when something is unclear. A policy that punishes questions drives risky use underground. A policy that welcomes them surfaces problems while they are still small.
Then set a review cadence and put the date on the document. Every six months is reasonable for a small team, plus a quick look whenever you adopt a new tool or the rules change. The EU AI Act applies in phases. The transparency duties under Article 50 apply from 2 August 2026, while the heavier high-risk obligations under Annex III, for deployers and providers alike, were moved to 2 December 2027 by the 2026 Digital Omnibus, so a policy that is reviewed on a schedule will keep pace rather than going stale. A dated document also shows a client or regulator that this is a living practice, not a one-off gesture.
Writing the policy is half the work. Getting it into people's heads is the other half. A few things make the difference:
An AI usage policy is one of the four artefacts that turn "we tried to be careful" into "we can show it," alongside a risk-classified tool inventory, role-based training with dated certificates, and a dated compliance record you can hand to a client, insurer, partner, or regulator. Klaar helps small European teams put those pieces together without drowning in legal text, but the policy itself is something you can start today. Open a blank page, list your real tools, draw your red lines, and keep it to a single page people will genuinely read. That is worth more than any twelve-page template gathering dust.
Klaar walks you through inventory, training, policy and the dated evidence.