← Back to blog

Guides

An AI usage policy for a 300-person company

Harriet Team · · 4 min read

At some point in the last year someone in your company was made accountable for AI. Often it was added to an existing title. The first thing they are asked to produce is a policy, and the first thing they discover is that every template online was written for a bank with a governance department or a startup with none.

This is the version for a company of a few hundred people, probably regulated, with real budget and no platform team. It has seven sections, each one a decision, and ends with a first draft of the words.

Before you write anything

Find out what people use. A policy written before the shadow AI map describes an imaginary company. One written after it describes yours. Give the survey a week, then write.

The seven sections

1. Approved tools, and how to get one

Name the assistant the company provides and how it reaches people. If it is provisioned to every device through your identity provider, say so, because it means nobody needs to sign up for anything. Then say what happens with everything else. The realistic rule is that new AI tools and AI features inside existing tools go through a short review before use, and personal accounts are not used for company work once the approved assistant is available.

2. What data can go in

This is the section people will read, so make it a table. Three rows is enough for most companies. Public and internal information, fine. Confidential and customer data, only through the approved assistant with the right model and region. Regulated categories such as personal data of customers, health, or financial records, only where your data protection lead has approved the specific workflow. Name the categories in your own terms, not the law’s.

3. Where processing happens

If you operate in the EU or UK, say which region your regulated data is processed in and that this is enforced by the platform, not by asking nicely. State whether the vendor trains on your content. Each should take one sentence, because the platform should already be doing it. If you cannot write those sentences, close that gap first. The data sovereignty page covers what that takes.

4. Who reviews new tools and skills

AI use inside a company grows through skills and connectors, not just chat. A skill that reads the CRM or sends an email needs someone to have looked at it. Say who reviews, what they check, and how long it takes. Scanning skills and connectors before they run, and holding the risky ones for an owner’s approval, is the mechanism. Name the owners.

5. How AI work is checked

People will paste AI output into contracts, customer emails and board packs. The policy should say that the person sending it is responsible for it, and that a human reads anything customer-facing or legally binding before it goes. Keep it short and repeat it in training.

6. What is logged and who sees it

Say plainly that prompts and tool calls through the company assistant are recorded, that the records exist for security and audit, and who can access them. People accept logging that is explained and resent logging they suspect. Your ISO 42001 or SOC 2 auditor will look for this sentence too.

7. Who to ask

One name and one channel. Most policy failures come from people guessing because asking felt like admitting something.

A first draft you can adapt

The whole policy fits on a page. Something like this.

We provide an AI assistant to every employee, installed on your device through our identity provider. Use it for company work instead of personal accounts. New AI tools, including AI features inside tools we already use, go to [name] for a short review before use.

Public and internal information can go into the company assistant freely. Confidential and customer information goes only through the company assistant, which processes it in [region] with training on our data switched off. Personal data in regulated categories goes only into workflows [data protection lead] has approved.

Skills and connectors are scanned before they run. Higher-risk ones need approval from the team that owns the process. You are responsible for anything you send that AI helped produce, and customer-facing or binding documents are read by a person before they go out.

Prompts and tool calls through the company assistant are logged for security and audit. [Role] can access the logs. Questions go to [name] in [channel].

Fill in the brackets and it is a policy. Review it every quarter against the tools people use, because that list will change.

What the platform has to do for the policy to be true

A policy is only as good as the system behind it. Region enforcement, scanning, logging and per-team model access cannot be done by hand. They are settings on the platform the assistant runs on, which is what Harriet’s security model provides.

If you are drafting one now, book a call and we will go through it against what your rollout does.

Common questions

What should an AI usage policy include?

Seven sections. Which tools are approved and how to get one. What data can go into an AI tool and what cannot. Where processing happens for regulated data. Who reviews new AI tools and skills before use. How AI-produced work is checked before it leaves the company. What is logged and who can see it. And who to ask when something is not covered. Anything longer than two pages will not be read.

Who should own the AI policy in a mid-sized company?

One named person, usually the head of IT, operations or security, with sign-off from legal and whoever owns compliance. Committees write long policies nobody follows. A single owner with the authority to approve tools and answer questions keeps it alive.

Do we need an AI policy if we only use Claude or ChatGPT for business?

Yes. The plan you bought decides the vendor's terms, not your people's behaviour. A policy covers what data goes in, how outputs are checked, what happens with personal accounts, and what to do with AI features inside other tools. None of that is settled by the subscription.

How does an AI policy relate to ISO 42001?

ISO 42001 is the management-system standard for AI. If your company is pursuing it, or your customers are asking about it, a usage policy is one of the first artefacts an auditor expects, alongside an inventory of AI systems in use and records of how each one was assessed. Writing the policy around real use makes the inventory honest.