◈ The Promptory Daily · Issue #038

The One-Page AI Policy Template — And Why Most AI Policies Fail After They're Published

The one-page AI acceptable-use policy template — adapt it for your firm, then get it in front of your team this week. Below the template, three reasons AI policies fail after they're published, and how to avoid each one.

This template pairs with the four-section policy framework — read that first if you want the reasoning behind each section before filling in the blanks below.

◈ Before You Use This

This template is a starting point, not a finished document. Fill in the bracketed sections with your firm's actual information. For regulated industries — healthcare, financial services, legal — have your relevant counsel review the final version before it goes live. This is general governance guidance, not legal advice, and your industry's specific requirements may call for additional provisions this template doesn't include.

The One-Page AI Policy Template

[FIRM NAME] · AI Acceptable Use Policy
Version [1.0] · Effective [DATE] · Review Date [DATE + 12 months]

Purpose

[Firm Name] uses AI tools to improve the quality and efficiency of our work. This policy tells every member of our team what tools are approved, what data can and can't go into those tools, what review is required before AI-assisted work leaves the firm, and what to do when something isn't clear. Following this policy is how we use AI responsibly — for our clients and for ourselves.

Section 1 — Approved AI Tools

The following AI tools are approved for work use, on the specified account tiers:

Free consumer accounts of any AI tool are not approved for use with any work-related data. Any tool not on this list requires approval from [designated person/role] before use.

Section 2 — Data Rules

Before using an AI tool, determine which category your data falls into:

◈ Green — Approved for any approved tool

Internal brainstorming · editing non-confidential text · general research · creating templates with no client specifics · summarizing publicly available information.

◈ Yellow — Approved enterprise tool only + approval from [role] required

Internal business data · non-client-specific financial projections · internal strategic documents · [add your firm's specific yellow-category data].

◈ Red — Never enters any AI tool without explicit written authorization

Client names combined with any other client data · client financial records · health information of any kind · legal matter details · personnel records · anything marked confidential · passwords or credentials · [add your firm's specific red-category data].

When in doubt, treat data as RED until you've checked with [designated person/role].

Section 3 — Human Review Requirement

The following AI-assisted outputs require human review before leaving the firm. Review must be documented in [CRM / project management system / shared doc] with the reviewer's name and date:

Review means checking the output for accuracy, verifying any facts or citations, and confirming the content is appropriate for the intended audience. The person who reviews is accountable for the content — not the AI tool.

Section 4 — When You're Not Sure

If a situation arises that this policy doesn't clearly address:

All team members confirm receipt and understanding of this policy as part of onboarding and at each annual review. This policy will be reviewed and updated at least once per year, or whenever significant changes occur in AI tool usage or applicable regulations. Questions about this policy go to [designated person/role].

Three Things That Make AI Policies Fail After They're Published

◈ Failure Mode 1 — Publishing without explaining

Dropping a policy document in a shared drive and calling it done produces a policy that doesn't change behavior. The team needs to hear two things from leadership: why this matters specifically to this firm and its clients, and what's different now versus before. A 15-minute all-hands covering those two points increases adoption meaningfully — and costs almost nothing.

The framing that works: "This protects our clients and protects all of us. Here's the specific situation we're preventing." Concrete beats abstract — if you can use an example from your own firm's audit, without identifying individuals, use it.

◈ Failure Mode 2 — Not providing the approved alternative

A policy that says "stop using unapproved tools" without providing approved ones drives usage underground. People need AI tools to do their work effectively. Removing the unauthorized option without replacing it with something better doesn't create compliance — it creates a situation where compliance and productivity feel like opposites. Productivity usually wins.

The policy launch should be accompanied by access to at least one well-configured approved tool. It doesn't have to be perfect. It has to be available, usable, and demonstrably easier to use than the workaround.

◈ Failure Mode 3 — Not reviewing it when things change

AI tools evolve faster than almost any other technology category right now. A policy written in January that names specific approved tools may be significantly outdated by July — because those tools have updated their data practices, because new tools have emerged that the team wants to use, or because a regulation has changed that affects what's required.

The review cadence that works for most professional services firms: annually scheduled, plus an ad hoc review whenever a new tool becomes available that the team wants to use, or when a regulatory development affects your industry. The annual review doesn't need to be intensive — 30 minutes to check whether the approved tools list is current, whether the data categories still make sense, and whether anything in your regulatory environment has shifted.

Ask Jordan

Reader

I want to build this policy for our firm — we're a 14-person financial planning practice. But I'm stuck on Section 1. I don't actually know which AI tools are appropriate for our regulatory environment. How do I evaluate that?

Jordan

Good question to get specific on. For a financial planning practice, there are four things I'd check on any tool before adding it to an approved list: does it have a signed Data Processing Agreement available, does it operate under SOC 2 or equivalent certification, what does its data retention policy say for business accounts specifically, and does it explicitly prohibit using your prompts for model training on the paid tier? Every tool in The Promptory vault has been evaluated on those criteria.

◈ The One Thing

The firms that will look back on this year as the year they got ahead of AI governance are the ones who wrote the policy this month — not a perfect policy, a real one. Shadow AI is a solvable problem. An AI policy is a manageable document. The gap between where most firms are and where they need to be is smaller than it looks.

If you want help evaluating your current tool stack against a firm's specific regulatory context, that's exactly what a free Jordan session is built for.

J

Have questions about your AI stack?

Jordan is The Promptory's free AI advisor. Describe your workflow and your challenges — Jordan will reason through your situation and tell you exactly which tools fit.

◈ Talk to Jordan — Free →
← All Issues Browse 152 Vault Tools →