# AI Use Policy Starter Template — Discussion Draft

**From Priority Governance · Free to use and edit · No email address required**

---

## Before you use this

This is a **starting policy document**, not a finished one. It gives a small organization something concrete to react to in a leadership meeting instead of starting from a blank page.

**What this is not.** It is not legal advice, not a security assessment, and not a compliance certification. It has not been customized to your organization, your sector, your contracts, or your regulators. Nobody has approved it on your behalf. Adopting it unchanged would be a mistake.

**How to use it.** Read it with the two or three people who would actually enforce it. Delete what does not apply. Argue about the bracketed decisions — those are the parts that matter. Then have whoever normally approves policy at your organization approve it, and tell your staff it exists.

**What it does not cover.** This is the policy document alone. It does not include the operating system around a policy: implementation materials, an AI tool inventory or register, data classification, vendor review, use-case records, control decisions, risk records, access guidance, an oversight cadence, evidence for a customer questionnaire, or any customization to your organization. Those remain yours to build or to source separately.

---

## 1. Purpose

`[Organization]` uses artificial-intelligence tools to work more effectively. This policy sets out how those tools may be used, what information may be entered into them, and who decides. It exists so people can use AI confidently, not to discourage them from using it.

## 2. Who this applies to

All employees, contractors, volunteers and board members who use AI tools for `[Organization]` work, on any device, whether or not the tool was provided by `[Organization]`.

## 3. What counts as an AI tool

Any service that generates, summarizes, transcribes, classifies or predicts using a model — including general assistants, meeting notetakers and transcription services, writing and content tools, image, audio and video generators, and AI features built into software you already use.

Embedded AI features are covered on the same terms as standalone tools. An AI capability inside a document editor, help desk, or meeting platform falls within this policy even though no separate application was adopted.

## 4. Approved, conditional, not approved

`[Organization]` maintains a short list of AI tools in three categories:

- **Approved** — cleared for the uses described, with a named owner.
- **Approved with conditions** — permitted only for specific purposes, or only with specific information, as stated on the list.
- **Not approved** — must not be used for `[Organization]` work.

A tool that is not on the list has not been reviewed. Before using one for anything beyond casual experimentation, ask `[role — e.g. the Operations Manager]`.

> **Decision to make:** who maintains the list, and how quickly can someone get an answer about a new tool? If the answer is "several weeks", people will route around the policy. A few days is usually the most a real workflow will tolerate.

## 5. Information that must not be entered into an AI tool

Unless the tool is explicitly approved for it in writing, do not enter:

- `[client / patient / student]` records or anything identifying an individual
- personal information about staff, including HR and payroll matters
- financial account numbers, payment details or banking credentials
- passwords, API keys or access tokens
- anything received under a confidentiality obligation
- material subject to legal privilege or an active legal matter
- `[sector-specific category — e.g. protected health information, education records, donor records]`

**If you are unsure, do not enter it.** Describe the problem in general terms instead, or ask first. Nobody will be criticized for asking.

## 6. Recording and transcribing meetings

Meeting recording deserves its own rule because it affects people who did not choose the tool.

- Participants must receive notice **before** recording or transcription begins, every time, and any consent required by applicable law or by `[Organization]` policy must be obtained first.
- Do not record `[categories — e.g. HR matters, performance conversations, legal discussions, clinical or pastoral conversations]`.
- Store recordings and transcripts `[where]`, and delete them after `[period]`.
- If anyone objects, do not record.

> **Decision to make:** does your jurisdiction require consent from every participant, or only one? Consent requirements vary between jurisdictions and by the type of conversation. Confirm the position that applies to you before adopting this section.

## 7. Connecting AI tools to other systems

Connecting an AI tool to your email, calendar, file storage or CRM is a bigger decision than signing in to one. It grants standing access that persists until someone removes it.

Connections require approval from `[role]` before they are set up. `[Organization]` keeps a record of what is connected to what, and reviews it `[frequency]`.

## 8. Accounts

Use `[Organization]` accounts for `[Organization]` work, not personal ones, wherever an organizational account exists. Personal accounts may operate under different terms for how input is handled, and the organization may be unable to administer, recover, transfer, or close them when someone leaves.

When someone leaves, `[role]` closes or transfers their AI tool accounts and removes any connections they set up, as part of the standard offboarding checklist.

## 9. You remain responsible for the output

AI tools produce confident text that is sometimes wrong. Check anything factual before it leaves the organization. Do not send AI-generated work to a `[client / patient / family / funder]`, publish it, or rely on it for a decision without reviewing it yourself.

Where `[Organization]` has committed to disclose AI use — in a contract, a grant condition, or a professional standard — follow that commitment.

## 10. If something goes wrong

If you think sensitive information was entered into an AI tool, or a tool behaved unexpectedly, tell `[role]` **the same day**. The purpose is to contain the problem, not to assign blame. Reporting quickly is treated as doing the right thing.

## 11. Ownership and review

`[Role]` owns this policy. It is reviewed `[frequency — quarterly is realistic while AI tools change this fast]` and after any significant incident or new tool adoption.

| | |
|---|---|
| **Approved by** | `[name, role]` |
| **Approved on** | `[date]` |
| **Next review** | `[date]` |
| **Version** | `[0.1 — draft]` |

---

## The five decisions worth arguing about

If your leadership meeting only has time for a few things, make it these:

1. **Who decides** whether a new AI tool may be used, and how fast can they answer?
2. **What information is off limits** entirely, in your specific line of work?
3. **What are the meeting-recording rules**, and who must be told?
4. **Who approves connections** between AI tools and your email, files or CRM?
5. **What happens at offboarding** — who closes the accounts and removes the connections?

---

*Priority Governance publishes this template freely. It is a discussion draft: a starting policy document, not customization, implementation, legal advice, a compliance certification, or organizational approval. Review it with your own leadership and, where the stakes warrant it, with counsel.*
