AI Risk & Governance
AI Governance LensPart 4 of 4

Write This Down: A One-Page AI Use Policy

A policy nobody reads protects nobody. Here is one your team will actually remember, on one page, in four sections.

6 min read

Most AI policies fail for one reason. Nobody reads them. Twenty pages of legal language sitting in a shared drive does not change what your bookkeeper pastes into a chatbot at 4:45 on a Friday. A policy only works if your team can recall it without opening the document.

"A policy nobody can remember is not a policy. It is a document."

Here is a policy that fits on one page and that people will actually use, broken into four sections any organization can fill in regardless of size or budget.

1
Section one
List your approved tools, by name.

If staff have to guess whether a tool is okay, you have already lost the policy. Name the specific tools your organization has reviewed and sanctioned, and say plainly that anything else requires approval first.

Why this matters
An estimated 77% of small businesses using AI have no written policy at all, and fewer than one in ten nonprofits have formal AI governance in place. Most organizations are making this decision tool by tool, with no record of why.
2
Section two
Name the data that is always off limits.

Pick three to five categories that would hurt the most if exposed: donor or client personal information, financial account numbers, health information, anything under a signed confidentiality agreement. A long list gets skimmed. A short list gets remembered.

Why this matters
Nearly half of employees say their organization's AI guidelines, where they exist at all, are unclear. Clarity is often the difference between a policy that gets followed and one that gets ignored.
3
Section three
Name a real person to ask before adopting anything new.

Not IT or leadership in the abstract. A specific name or role. A clear path gets used. A vague one gets skipped entirely.

Why this matters
More than a third of employees admit they do not always follow their organization's AI policy even when one exists, often because the approval path was unclear or slower than simply proceeding without asking.
4
Section four
Assign an owner and a review date.

Someone needs to be accountable for keeping this current, or it becomes the document nobody touches again until something goes wrong. Quarterly is a reasonable cadence for most small organizations.

Why this matters
AI governance, like cybersecurity oversight generally, is not a project with a completion date. It is an ongoing condition that changes as your tools, your staff, and the threat environment change.
Copy-paste template
[Organization Name] AI Use Policy
Approved tools: [Tool A], [Tool B]. Using a different AI tool for work purposes requires approval first.
Never enter into any AI tool: donor or client personal information, financial account details, health information, anything under a signed confidentiality agreement.
Before adopting a new tool: check with [Name or Role] first.
Policy owner: [Name or Role]. Reviewed every quarter.

What This Series Has Covered

Over the past four weeks, this series moved from the basic case for taking AI adoption seriously, through the shadow AI risk already living inside most organizations, into a repeatable way to vet new tools, and now into a policy people will actually use. These are not four separate conversations. They are four parts of a single one.

The four-post series at a glance
  • Post 1 AI Adoption Reality: Why ignoring AI, or letting it run unmanaged, are both mistakes, and the three moves that create a defensible starting position.
  • Post 2 Shadow Risk: What your team is already doing with AI tools, and why the exposure is worse for smaller organizations than most leaders assume.
  • Post 3 Vendor Vetting: Five questions to ask before adopting any AI tool, regardless of budget.
  • Post 4 AI Governance Lens: A one page policy your team will actually read, and how to keep it current.

The through-line across all four posts is the same idea that sits at the center of what Defensible Cyber Risk does. Security that serves your organization, not the other way around. Not enterprise complexity, not checkbox compliance. Defensible decisions made with clear eyes about what AI actually changes and what it does not.

The ask for this week: Take the one page template into your next leadership meeting and fill in the blanks together. The conversation that produces it matters as much as the document itself.

Ready for a clearer picture of where you actually stand?

A 90-day or 30-day Security Business Review translates your organization's risk into clear, prioritized decisions leadership can act on. No enterprise complexity. No vendor lock-in. Just defensible outcomes.

Start a Conversation
AI PolicyAI GovernanceNonprofit TechnologySmall BusinessvCISO