AI Policy Generator

Word document (.docx)

A 10-section AI usage policy with regulation citations tailored to your jurisdiction and industry.

AI Usage Policy

[Your Organisation] — Responsible AI Use

Draft — for review by in-house practitioners

Table of Contents

  1. 1. Purpose and Scope
  2. 2. Guiding Principles (7)
  3. 3. Permitted and Prohibited AI Uses
  4. 4. Risk Classification Matrix
  5. 5. Roles and Accountability
  6. 6. Data Governance Rules
  7. 7. Third-Party AI and Vendor Requirements
  8. 8. Monitoring, Logging, and Audit
  9. 9. Incident Response and Escalation
  10. 10. Policy Review and Update Cadence

3. Permitted and Prohibited AI Uses

Staff may use approved generative AI tools to assist with drafting, summarisation, and research. Staff must not input customer personal data, commercial terms, or confidential product plans into any AI tool that has not been listed in Schedule A — Approved AI Tools. Where an AI output materially influences a customer-facing decision, a named human reviewer…

(Sample extract — full document runs across all ten sections.)

AI Risk Register

Excel workbook (.xlsx)

A pre-scored register of AI risks mapped to your sector, with likelihood, impact, mitigations, and owners.

Sheet 1 — Risk Register

AI Risk Register — [Your Organisation]

IDRiskLikelihoodImpactRating
R-01Unintended disclosure of personal data to third-party model APIsHighHighCritical
R-02Material model error in customer-facing decisioning flowMediumHighHigh
R-03Bias in resume-screening output producing disparate impactMediumMediumMedium
R-04Vendor AI changes alter model behaviour without advance noticeHighMediumHigh
R-05Regulatory obligation (EU AI Act Art. 16) missed on high-risk systemLowHighHigh

(Sample extract — the live register includes mitigation, owner, review-date, and residual-risk columns across 12–15 rows.)

Employee AI Guidelines

Word document (.docx)

Plain-language staff guidelines with golden rules, data-handling tiers, and an escalation process.

Employee AI Guidelines

AI use at [Your Organisation] — what staff need to know

Golden rules

  1. 01

    Do not paste confidential or personal data into public AI tools

    If the tool is not on your organisation's approved list, assume anything you type leaves the organisation. When in doubt, check with your manager first.

  2. 02

    Verify AI output before you rely on it

    AI output can contain errors, outdated information, or fabricated citations. You remain responsible for accuracy — the AI is a drafting aid, not a source of truth.

  3. 03

    Escalate unexpected or harmful AI behaviour

    If an AI tool produces output that looks harmful, discriminatory, or materially wrong, stop using it for that task and report to the named escalation owner within 24 hours.

(Sample extract — the full document contains 8–10 golden rules, a four-tier data classification guide, a printable wallet card, and an incident-reporting flow.)

Ready to generate your own?

Pick the tool that fits your next compliance milestone. Each generation is a one-time payment — no subscription, no account.