The policy nobody opens

A familiar pattern: a carefully worded document sets out principles about responsibility, transparency and human oversight. It is approved, published on the intranet and rarely opened again. Meanwhile, people use AI tools in ways nobody has mapped, some sensible and some risky.

The problem is rarely the principles. It is that they do not answer the questions people actually have when they are working.

A policy is practical when an employee can answer three questions in under a minute: may I, how do I, and who do I ask?

Start with the uses, not the principles

Before refining the wording, find out what is actually happening. A simple register of AI use is often the most revealing governance step an organisation can take.

Who uses the tool, and in which team?

For which task? Drafting, analysis, customer contact, decisions about people?

With which data? Public information, internal documents, customer data, personal data?

With what consequence if the output is wrong?

The register does not need to be elaborate. A shared overview that is kept current beats a perfect one that is out of date. What matters is that the most consequential uses are visible to the people responsible for them.

Make responsibility specific

"The business is responsible" is not an answer. For each important use, someone needs to be able to make decisions about the process.

A business owner who decides how the tool is used and accepts the residual risk.

IT and security who provide technical controls, access and supplier oversight.

Specialists in law, data protection or the relevant field, brought in where the use requires it.

The board, which needs visibility of material uses and a regular way to follow up, not every detail.

Depending on the organisation's role, the use and the countries involved, specific rules may apply. Assessing them is a specialist task. The governance question for the board is simpler: has someone been made responsible for that assessment, and will unresolved questions be reported rather than hidden?

Test it with a fictional incident

The fastest way to find gaps is to rehearse. Take one realistic, fictional scenario and walk through it with the people involved.

Fictional example. An AI-assisted reply to a customer quotes the wrong price. The customer accepts it and posts a screenshot online.

Who notices, and how quickly?

Who decides whether to keep using the tool while the issue is investigated?

Who handles the customer and the public response?

Who decides what changes before the tool is used again, and who tells the board?

If the honest answer to any of these is "we would work it out", you have found a concrete task, which is far more useful than another round of policy wording.

What good looks like

In organisations where this works, the policy is short and points to practical guidance. The register is maintained by someone with time to maintain it. Each important use has a named owner. Incidents and near misses are reported without blame. And the board receives a concise picture a few times a year: material uses, open issues and decisions needed.

Warning signs: a long policy and no register, ownership described as "shared", no rehearsal of incidents, and board reporting that only appears when something has gone wrong.

Three questions for your next meeting

  1. Do we know our most consequential uses of AI today, and who owns each one?
  2. If an AI-assisted output caused harm tomorrow, who would decide what happens next?
  3. What will the board see, how often, and what would make us ask for more?