ONLINEAGENT_OPS 2026.Q3 HOME ARTICLES CRAFT RECORD BLOG HUBS FAQ SEARCH
HOMETHE RECORDA TEAM AI POLICY YOU CAN ACTUALLY
THE RECORD · PRACTICAL

A Team AI Policy You Can Actually Adopt

Three questions a policy has to answer, why most fail on the third, and a one-page template you can adapt in ten minutes.

Someone has asked you to write the rules. Most AI policies are a page of caution that changes nobody's behaviour. Three questions do the actual work.

TL;DR — THE SHORT VERSION
  • A policy that only says "be careful" is decoration. It gives no one a decision they can make on a Tuesday afternoon.
  • Answer three questions: what may go in, what must be disclosed, who is answerable when it is wrong.
  • The third one is the one people skip, and it is the only one that matters when something goes wrong. "The AI wrote it" has never worked as a defence.
  • Consumer accounts are not covered by your company agreements. That distinction decides most of what belongs in rule one.
  • Do not ban detection-based enforcement. Detectors misclassify non-native English writers at high rates; a policy that punishes on a detector score will punish the wrong people.
  • A copyable one-page policy is at the bottom. Adapt it in ten minutes; it is written to be edited, not adopted whole.

Why most policies do nothing

The common failure is a document that is entirely about risk and contains no decidable rule. "Use AI responsibly." "Exercise judgement." "Be mindful of confidentiality." Nobody disagrees with any of it, and nobody behaves differently after reading it.

The test is simple. Can someone with a real task in front of them look at the policy and know what to do in under a minute? If not, the policy is not a policy — it is a statement of intent that will be cited only after an incident.

Question 1 · What may go in

This is the rule people actually need, because it comes up several times a day and the answer is not obvious.

01

The line is the account, not the tool

The important distinction is not "is this tool allowed" but which account is it being used through. A personal consumer account and a company account under a written agreement are governed by completely different terms, even when the interface looks identical.

Assume anything typed into a personal account may be stored and reviewed unless a written agreement says otherwise — and most consumer accounts are not covered by one.See what happens to what you type for the retention and training positions of the major vendors, with dates.

02

Name the categories, not the vibe

"Be careful with sensitive data" fails because sensitive is subjective. A list is not.

Never, in any account: customer personal data · credentials, keys, tokens · anything under NDA · unreleased financials · legal matters in progress · anything about a named individual's health, performance or employmentNO
Company account only: internal documents · unreleased plans and copy · source code · anything a competitor would find usefulGATED
Any account: published material · public research · your own drafting where none of the above appearsFINE

Redaction counts. Removing names and identifiers moves work from the first row to the third, and saying so in the policy is what makes people do it.

Question 2 · What must be disclosed

03

Disclosure that is not theatre

Disclosing every use of AI is unworkable and quickly becomes a footer nobody reads. The workable version is narrower: disclose where a reader's decision would change if they knew.

Disclose: published work under a person's byline · client deliverables · research and figures · anything presented as first-hand experience · code entering a shared codebaseYES
No need: drafting an email you then rewrote · summarising your own notes · brainstorming · formatting · looking something up you then verifiedNO

The reason to be strict about the first list is not ethics in the abstract. It is that being found out afterwards, having implied otherwise, is a trust problem — and trust problems outlast the project that caused them.

04

Do not enforce with detectors

A policy that says "we will check submissions with an AI detector" creates a worse problem than the one it solves. Detector tools misclassify a substantial majority of writing by non-native English speakers in peer-reviewed testing, and cannot support a claim about any individual.

A policy that punishes on a detector score will, predictably, punish your non-native speakers. Enforce on disclosure and on the quality of the work, which are both observable. Not on a percentage.See how to spot AI writing for the detector evidence and what the false-positive rates actually are.

Question 3 · Who is answerable

05

The rule that makes the rest work

This is the sentence most policies omit, and it is the one that decides what happens when something is wrong:

The person who submits the work owns the work. Using a tool does not transfer responsibility for the output.

Everything else follows from it. If you are answerable for the figure, you check the figure. If you are answerable for the code, you read the code. No separate rule about verification is needed, because ownership implies it.

Why it matters more than it sounds: without this line, the implicit policy is that mistakes belong to the tool. That is not a position any organisation can hold in front of a customer, a regulator, or a court. "The AI wrote it" is not a defence anywhere.

The one-page policy

Adapt this. It is deliberately short, because a policy people finish reading beats a thorough one they do not.

TEAM AI POLICY — TEMPLATE
1 · WHAT YOU MAY PUT IN Never, in any tool or account: customer personal data · credentials, keys or tokens · material under NDA unreleased financials · live legal matters · anything about a named person's health, performance or employment Company account only (not personal accounts): internal documents · unreleased plans and copy · source code anything a competitor would find useful Any account: published material · public research · your own drafting, where none of the above appears Redacting names and identifiers moves work down this list. Do that rather than not using the tool. 2 · WHAT YOU MUST DISCLOSE Disclose AI assistance where a reader's decision would change if they knew: published work under your name, client deliverables, research and figures, anything presented as first-hand experience, and code entering a shared codebase. You do not need to disclose drafting, summarising your own notes, brainstorming, formatting, or lookups you verified yourself. We do not use AI detectors to enforce this. They are unreliable and are especially unreliable for colleagues who did not grow up speaking English. Enforcement is on disclosure and on the quality of the work. 3 · WHO IS ANSWERABLE The person who submits the work owns the work. Using a tool does not transfer responsibility for the output. If you are answerable for a figure, check the figure. If you are answerable for code, read it. 4 · WHEN SOMETHING GOES WRONG Say so early. An error found internally is a small problem. The same error found by a customer is a different one. Nobody is disciplined for reporting a mistake promptly. 5 · WHEN THIS WAS LAST REVIEWED [date] — tools and their terms change. Review every six months.
TWO THINGS TO ADD YOURSELF

Which tools are approved, by name, with which account. A policy about categories still leaves people guessing about the specific product in front of them.

Who to ask. One named person. Policies without a route to a human answer produce either paralysis or quiet non-compliance, and you will not find out which until later.

TAKEAWAY

A policy is a decision aid, not a disclaimer. If it does not let someone act faster and more safely than they would have without it, it is not doing anything — and the version that gets read is the version that is short.

SOURCES

The claims here about retention, disclosure and detector reliability are sourced on the pages linked above: what happens to what you type, how to spot AI writing, and using AI at work, which covers the same ground for an individual rather than a team.

The template carries no legal weight and is not legal advice. It is a starting structure. If your organisation is in a regulated field, the categories in rule 1 are the ones your compliance people should be editing first.

ABOUTMETHODVERIFYCORRECTIONSPRIVACYCONTACTINDEXAI PROMPT GENEER · CHECKED 22 AUG 2026