Skip to content
GuidesJuly 19, 2026· 8 min read

How to Write an AI Policy Your Team Will Actually Follow

Most AI policies are either a blanket ban nobody obeys or a vague blessing that protects no one. Here is a template that works.

Mohammad abu Saada

Founder of Sahihly

Why most policies fail

Two failure modes dominate. The blanket ban — "no AI tools" — is unenforceable, drives usage underground, and denies you any visibility into how work is actually produced. The vague blessing — "use AI responsibly" — gives no one a decision rule, so every ambiguous case becomes a judgement call your team resolves inconsistently.

A workable policy does one thing: it tells a person facing a specific task exactly what is permitted, what must be disclosed, and who is accountable for the output.

Start by classifying the work, not the tool

Rules attached to tools go stale in a month. Rules attached to risk survive. A simple three-tier split covers most organisations:

Tier 1 — Unrestricted

Low-stakes, internal, non-published, easily verified. Brainstorming, meeting summaries you review, code scaffolding, first-draft outlines, translation for personal comprehension. No disclosure needed.

Tier 2 — Permitted with disclosure and review

Anything published externally or used to make a decision. Marketing copy, documentation, customer emails at scale, research summaries. Requires: a named human reviewer, verification of every factual claim, and an internal note recording that AI assisted.

Tier 3 — Restricted or prohibited

Legal, medical, financial, or safety-critical content. Anything involving personal data of customers or employees. Anything presented as personal testimony or original research. Anything where a hallucinated fact creates liability. Requires explicit sign-off from a named owner, or is simply not permitted.

The non-negotiable clauses

  • Accountability does not transfer. The person who ships the work owns every claim in it. "The model said so" is never a defence. This single clause solves most edge cases by itself.
  • No confidential data in third-party tools unless the tool is on an approved list with a data-processing agreement. Name the approved tools explicitly and keep the list current.
  • Verify before publishing. Every statistic, citation, quote, name, and date must be checked against a primary source. Models fabricate references fluently.
  • Disclose where it is material. Not for a grammar fix; yes for a substantially drafted article, and always where a reader would reasonably want to know.
  • No AI-generated personal claims. Testimonials, reviews, case studies, and first-person experience must be real. This is both an ethics and a regulatory issue in many jurisdictions.

Quality gates worth adding

Policies fail when they are only prohibitions. Pair them with practical checks that improve output:

  • The substance test. Does this page contain something a model could not have produced — your data, your test, your judgement? If not, question whether it should ship at all. This is the same standard search engines apply, as we cover in E-E-A-T for AI-assisted content.
  • The style pass. Unedited model output reads uniformly and signals "generic" to readers. A style check flags which passages are flattest so an editor knows where to spend effort; where the substance is sound but the rhythm is mechanical, the humanizer is a reasonable fix.
  • The byline rule. Every published piece carries a real human name. Accountability becomes concrete the moment someone''s name is on it.

What to avoid putting in the policy

  • Detector thresholds as pass/fail gates. Tempting and wrong. Detection scores are probabilistic and biased against second-language writers — using a number as an employment or disciplinary trigger is indefensible, as we explain in this guide. Use them diagnostically or not at all.
  • Tool-specific bans that will be obsolete before the ink dries.
  • Percentage limits like "no more than 30% AI-written." Unmeasurable and meaningless.

Rolling it out

  1. Write it in one page. If it needs ten, nobody reads it.
  2. Include three worked examples of real tasks from your organisation, each resolved to a tier.
  3. Name an owner who answers ambiguous cases — and publish how to reach them.
  4. Review it quarterly. This field moves faster than your handbook.
  5. Ask what people are already doing, honestly and without penalty, before you write the rules. You will learn where the real risks are.

The underlying principle

A good AI policy is not about controlling tools. It is about making sure that a human being remains answerable for every claim your organisation puts into the world — and that the people doing the work know exactly where that line sits.

Written by

Mohammad abu Saada

Founder of Sahihly

Founder of Sahihly. I build writing-quality tools for Arabic and English, and write about AI detection and its limits.

All articles by this writer →

Try the detector and humanizer now — free, no account required.

Open the studio
Back to blog