AI governance: how to write an AI policy employees actually follow
Most AI policies sit unread in a shared drive. Here's how to build governance that's practical, EU AI Act compliant, and used in daily decisions.
A working AI governance framework has three layers: an acceptable use policy that channels behaviour, data handling rules employees actually understand, and a governance structure that operationalises oversight. None of the three works without the other two. And all three fail when written without input from the people they govern.
Most organisations that take AI seriously start with good intentions. They form a working group, draft a policy document, get it reviewed by Legal, and post it on the intranet. Six months later, a quarter of employees are using AI outside policy — not deliberately, but because they never read it, or because it doesn't connect to how they actually work.
Why AI policies fail
AI policy almost always fails for the same reason: it's written for compliance, not for people. The document protects the organisation legally but gives the employee at their desk no usable answer to the question "can I summarise this client call with ChatGPT?"
Three pattern failures we see repeatedly:
- Too abstract — 'AI systems will be deployed responsibly in accordance with applicable law.' What does that mean for the employee who needs to write a proposal on Monday morning?
- Too broad — everything in one document, from foundation models to computer vision to robotics. Employees drop off after the table of contents.
- No ownership — the policy was set by Legal or IT, but nobody feels accountable for implementation. Enforcement is zero.
The result: a policy document that is technically compliant and practically invisible. Employees work around it — not out of bad intent, but because the policy doesn't help them do their job.
The three layers of governance
Effective AI governance has three layers that build on each other. Skip one, and the architecture doesn't hold.
| Layer | What it governs | Owner | Review cadence |
|---|---|---|---|
| 1. Acceptable use policy | Which AI use is permitted, restricted, or prohibited | HR / Legal | Annual or after major releases |
| 2. Data handling rules | Which data can enter which AI system, under what conditions | IT / Privacy officer | With each new AI tool |
| 3. Governance structure | Who decides what, who oversees, who reports | CTO / COO | Quarterly review |
Order matters. Start with the acceptable use policy — it gives employees a clear framework. Add the data handling rules so the policy is actionable. Finally, the governance structure ensures the whole thing doesn't go stale.
Acceptable use policy: concrete or useless
An acceptable use policy (AUP) answers one question for employees: what can I do with AI and what can't I? The best AUPs are built around use cases, not legal principles.
The structure that works:
- Permitted — use cases with no restrictions: summarising internal documents, code reviews, brainstorming, writing assistance for your own texts.
- Permitted with conditions — use cases that are allowed if you follow certain steps: client communications with mandatory review, data analysis without personal data, external communications with manager approval.
- Prohibited — use cases that are never allowed, regardless of tool: client data in public AI tools, medical or legal advice without human validation, generating misleading content.
Add a decision tree alongside the AUP: two pages, seven questions, and an employee knows whether a specific use is allowed. That decision tree is what colleagues will actually open. The full policy document is for Legal.
Data handling rules: the core of AI policy
Most AI incidents are data incidents. Customer data entered into a public AI system. Personnel files passed as context to an external API. Unpublished financial figures processed by a cloud service that doesn't exclude retention.
Data handling rules must be set per data class, not per AI tool. Tools change. Data classifications don't.
| Data class | Description | Rule | Example |
|---|---|---|---|
| Public | No confidential information | Free to use in all approved AI tools | Summarising a public press release |
| Internal | Company information not for outside | Only in approved tools with a data processing agreement | Analysing an internal report with Claude Enterprise |
| Confidential | Client and contract data, strategy | Only in controlled environments, anonymise where possible | Transcribing a client call after anonymisation |
| Strictly confidential | Personal data, financial results, M&A | Not in AI tools unless specifically approved | National insurance numbers, unpublished quarterly results |
Publish this table as a standalone A4. Laminate it. Put it next to every workstation. Employees should be able to consult it without opening the full policy document.
Also add which AI systems are approved per data class. Employees then choose not between 'AI or no AI' but between 'approved tools for this data type'. That makes compliance structurally easier.
EU AI Act Article 4: AI literacy as a legal obligation
Article 4 of the EU AI Act requires organisations deploying AI systems to ensure employees have sufficient AI literacy. This is not a soft requirement — it is an enforceable obligation that applies from August 2026 for all high-risk AI applications.
What Article 4 concretely requires:
- Demonstrable training for employees who work with or make decisions based on AI output.
- Documentation of that training, so you can show an auditor who completed what.
- Periodic refresher training when AI systems or their use changes significantly.
In practical terms: your AI policy must include a training requirement. Not as an option, but as part of onboarding for new employees and as an annual refresh cycle for existing ones. Organisations that haven't set this up are carrying a legal risk that grows as AI use increases.
“Article 4 of the EU AI Act is not new law. It codifies what responsible organisations already do: making sure employees understand what they're working with.”— Productized interpretation, EU AI Act
From policy to behaviour: the implementation step organisations skip
The biggest gap in AI governance is not the policy itself — it's the translation from policy into daily behaviour. A policy document on the intranet doesn't change habits. Habit change requires repetition, relevance, and positive feedback.
What works in practice:
- Embed AI behaviour rules in existing onboarding — not as a separate module, but as part of the first week. Employees who start correctly have no bad habits to unlearn.
- Manager enablement — line managers are the governance interface for most employees. Train them on the three most common questions they'll receive. A manager who knows the answer doesn't need to escalate to Legal.
- Positive enforcement — publicly name good examples of responsible AI use. Compliance policy that's only visible when something goes wrong reinforces negative associations with AI governance.
- Annual policy review — invite representative employees to give feedback on the AUP. Policy that doesn't evolve quickly loses touch with practice.
According to research from Stanford HAI (2025 AI Index), the primary barrier to responsible AI use in organisations is not technology but unclear expectations. Employees want to use AI responsibly — they just don't always know what that means in their specific role.
What a complete AI governance package includes
A complete AI governance package for an organisation of 50–500 employees includes: a tailored acceptable use policy with decision tree, data handling rules per classification level, a governance structure with clear ownership, EU AI Act Article 4-compliant training materials, an onboarding module, and an annual review cycle.
We build this in four weeks, including alignment with Legal and HR, and deliver it in formats ready to deploy: intranet page, A4 reference cards, e-learning with certification, and a governance dashboard for reporting.
Already have a first version of an AI policy and wondering if it holds up? Or starting from scratch and want to get it right first time? Get in touch — we'll review it at no cost and give you an honest assessment within one business day.