People need to understand what is expected of them and feel able to ask questions when something is unclear. Start the conversation with their work, their questions and their concerns. Leaders remain responsible for approving the AI rules, with the people using them helping make the guidance practical and easy to find. That guidance supports the organisation's formal requirements; it does not replace them.
Why the rules matter more than the tools
Uncertainty about permission can make people hesitant to use AI. People are not sure what they are allowed to put into a tool, whether they will be blamed if something goes wrong, or whether using it looks like cutting corners. Without clear guidance, people may make different assumptions about what is allowed. We covered the wider pattern in why AI rollouts fail. Agreed rules replace those private guesses with a shared answer.
Listen to the people the rules need to support
Before writing anything, find out what is already happening. People may be regular users, have tried AI briefly or be starting from the beginning. Each person's working manual, their own working with me manual, can record their confidence with AI and the support they would find useful, under their own sharing choices. Write the rules for the team you actually have. The goal is work done well, never AI use for its own sake, and the rules should say so.
What your AI rules should cover
- Which tools and accounts are approved, and how someone asks about one that is not on the list.
- What information is permitted in each approved tool and account, including the organisation’s rules for client, personal and confidential information. If permission is unclear, check before using it.
- How AI-assisted work is checked before it goes out, and how much checking is expected for different kinds of work.
- Who is responsible for the result. The person who sends the work owns the work.
- What support is available, including for people who need adjustments or want to go at a slower pace.
- Where questions go, what to do when something goes wrong, and how the rules themselves get changed.
Agree them together
Get the team together with the list above. Let the people who use AI most explain what helps, and the people with doubts say what worries them. Write the rules in your team's own words, and give them an owner and a review date. Some teams settle this quickly, others need a couple of goes and a bit of legal or client input first. Both are fine.
Keep them alive
Rules go stale because tools change and work changes. Put a review in the diary, and change the page when practice shows a rule is wrong or missing. Rules and real use should stay in step. The AI Adoption Programme builds this in: we understand the people and the business, agree the useful opportunities and the business rules, support the change and help managers see what is improving.
What to leave out
Avoid treating more AI use as a result in itself. Agree what information will be used to review progress, why it is needed and who can see it. Managers can review agreed actions and work outcomes, alongside the organisation’s necessary security and data controls, without ranking people by their AI activity.
If you would rather not do this from a standing start, the AI Adoption Programme runs over three months and covers the rules alongside the opportunities in each person's own role. A workshop can be a useful way to get the conversation going.
Common questions
Does a small business need an AI policy
A business introducing AI needs clear, approved guidance appropriate to its work and obligations. A practical team guide can explain the tools, permitted information, checking and responsibilities. More detailed policies or specialist input may also be needed.
What should AI rules at work cover
Approved tools and accounts, what information may and may not be used with them, how AI-assisted work gets checked, who owns the result, what support is available, and where questions go.
How do we keep AI rules current
Give the page an owner and a review date, and change it when practice shows a rule is wrong or missing. Tools and work both move, so the rules need to move with them.