Writing an Internal AI Policy People Follow

2026年8月8日2 次浏览来源:Dev.to阅读原文

Nearly every internal AI policy fails in the same way: it is correct, comprehensive, and impossible to apply at the moment somebody is standing in front of a text box with a document in their clipboard.

Followability is a property of individual sentences, and it is testable.

The test each rule has to pass Three conditions.

A rule that fails any of them will be ignored — not out of defiance, but because it cannot be used at the moment of decision.

1.

Decidable in ten seconds, alone.

The reader must be able to apply it to the thing in front of them without asking anyone, looking anything up, or making a judgement about “sensitivity” in the abstract.

If applying the rule requires a conversation, the rule is a process, and processes are skipped under deadline.

2.

Checkable afterwards.

Somebody must be able to tell whether the rule was followed.

Not to punish anyone — because a rule nobody can check is a rule nobody can improve, and you will never learn which of your rules are wrong.

3.

It has an exit.

Every rule needs a named place to go when it does not fit the situation, with a response time.

Without one, the first genuinely awkward case teaches everyone that the policy is advisory.

Run the test over your existing draft before writing anything new.

Most drafts lose half their sentences, and the half that survives is the policy.

Six rules, rewritten The left column is what these clauses usually say.

The right column is the same intent, made decidable.

Instead of Description Use good judgement with sensitive data Nothing from the Restricted list goes into any AI tool.

The Restricted list is on the intranet, it fits on one screen, and it is the same list the data classification policy already uses.

Do not enter confidential information You may paste internal documents into .

You may not paste anything containing a customer name, an account number, or an employee's personal data into any tool, approved or not, without the redaction step below.

Always review AI output before use Anything leaving the company — email to a customer, a document sent externally, published copy — is read in full by the sender before it goes.

Internal drafts do not need this.

Only use approved tools The approved list is here and is updated within five working days of a request.

Anything not on it: ask in #ai-help; a yes or no comes back within two working days.

Be transparent about AI use Say so when a customer-facing document was substantially drafted by a model and you are the named author.

You do not need to disclose spelling correction, summarising your own notes, or code completion.

Do not rely on AI for important decisions A model output may not be the sole basis for: a hiring or promotion decision, a credit or eligibility decision, a disciplinary action, a medical or legal conclusion, or anything a regulator could ask you to justify.

Two things happened in each rewrite.

A category judgement was replaced by a list the reader can look at, and a universal was replaced by a scope.

The last row is the exception to the ten-second rule and is worth the cost: it is an enumerated list rather than a principle precisely because the stakes make a judgement call unacceptable, and because those categories are where an explanation may be legally required.

The classification it rests on Every workable rule above points at a data classification.

If you have one, use it and change nothing.

If you do not, make one with three tiers — not seven, because a scheme people cannot recall is a scheme they will not apply.

The single most useful sentence you can add is a worked example under each tier drawn from the reader’s own work: a specific document type per tier, named.

Abstract tiers get argued about; a named example settles ninety per cent of the cases without anybody asking.

Note that the Restricted tier does not say “never”.

A blanket prohibition on restricted data is the rule most likely to be quietly broken, because it forbids things the company has already approved

分享
Baike.dev

baike.dev helps you discover great languages, frameworks, databases, DevOps and cloud-native tools.

Quick links

About

Contribute

Found a great developer tool? Share it with the community.

Submit a tool
© 2026 baike.dev Developer EncyclopediaUpdated daily · Discover great developer tools