You do not need a 40-page policy
Governance sounds heavy, but the essentials fit on a single page. The aim is simple: let people use AI with confidence while protecting customers, staff and the business.
1. Data: what may go into AI tools
List what is public, what is internal, and what is confidential or personal. Say clearly which AI tools are approved for which category. When in doubt, the default should be: do not paste it.
2. Accuracy: who checks the output
AI can be fluent and wrong. Require a person to check anything that reaches a customer, a regulator, a contract or a financial decision. Keep a record of what was checked.
3. Accountability: who owns each use
Every AI use case needs a named owner who can answer: what is it for, what data does it touch, and what happens if it fails.
4. People: training and support
Rules only work if people understand them. Give every user short practical training, and a place to ask questions without feeling judged.
5. Review: keep it current
Tools and laws change quickly. Review your one-page policy every quarter, and after any incident. If you operate in India, check how the Digital Personal Data Protection Act 2023 applies to the personal data your tools process.
A simple start
Print the five headings, fill in one line under each, and share it with your team this week. You can refine it as you learn. A short policy that is used beats a long one that is not.