How to write an AI usage policy your staff will actually follow
Your team is already using AI — the only question is whether it is governed. Most AI policies fail because they are written as bans, filed after one all-staff email, and never enforced. Here is what a policy that changes behaviour looks like.
Our AI governance serviceThe policy gap is a data gap
In most firms, AI arrived through the side door: a chatbot here, an AI feature switched on inside a SaaS tool there, a copilot trial someone forgot to cancel. Each is individually reasonable. Collectively they mean client records, financial details and privileged material flowing into tools nobody has assessed — with no record of what went where.
For regulated firms the stakes are higher again. The FCA has chosen not to write a bespoke AI rulebook; instead, existing obligations — the Consumer Duty, the Senior Managers regime, operational resilience and data protection — already apply to AI use. A named senior manager can already be held accountable for AI-related harm. The usage policy is where that accountability becomes something staff can actually act on.
The seven sections every AI usage policy needs
- 01
An approved tools list
Name the AI tools staff may use, in which plans or tiers, and who approves additions. "Approved" should mean someone has actually looked at where the data goes — not that the tool is popular.
- 02
Permitted and prohibited data
Be concrete. Client names, financial records, case details and anything personal or privileged should be explicitly addressed — not left to a general instruction to "use good judgement".
- 03
Human sign-off points
Define where AI output must be reviewed before it is acted on or sent: client communications, advice, anything regulated. The policy should say who signs off, not just that someone should.
- 04
Connector and integration rules
AI features that plug into mailboxes, drives and CRMs are where the real exposure lives. Require approval before any AI tool is connected to firm systems, and review the permissions it asks for.
- 05
Supplier requirements
What you expect of AI vendors: where data is processed, whether it trains models, retention, and security assurances. This is what lets you answer client due diligence questions honestly.
- 06
Incident reporting
What staff should do when something goes wrong — data pasted somewhere it should not have been, an odd output, a suspicious request. Make reporting easy and blame-free, or you will simply never hear about it.
- 07
Ownership and review
Name the senior owner and set a review cadence. AI tools change monthly; a policy written once and filed will be out of date before the year ends.
A policy is a promise. Enforcement is what keeps it.
The document on its own changes nothing. Three things turn it into practice:
A better legitimate route
Approved tools that are genuinely good and paid for by the firm. If the sanctioned option is worse than the workaround, the workaround wins every time.
Technical enforcement
Access controls, connector permissions, and logging that make the policy real. Treat AI tools like the privileged applications they are.
Short, real training
Fifteen minutes with examples from your own firm beats an hour of generic slides — repeated as the tools change, because they will.
AI usage policies — what firms ask us
How long should an AI usage policy be?
Short enough that people actually read it — for most SMEs that is two or three pages, not twenty. The detail lives in the approved tools list and the data rules, which are the parts staff genuinely consult. A long policy that nobody opens protects no one; a short one that answers "can I use this tool for this task?" changes behaviour.
Shouldn't we just ban AI tools until the rules are clearer?
Bans mostly drive usage underground: staff switch to personal devices and personal accounts, and the firm loses the visibility it had. The regulatory position is also clearer than it looks — the FCA already expects firms to govern AI under existing obligations rather than waiting for bespoke rules. Governed adoption, with a short approved list and clear data rules, is safer than a ban that is quietly ignored.
What makes staff actually follow a policy?
Three things. First, a legitimate route that is genuinely easier than the workaround — approved tools that are good, available and paid for. Second, technical enforcement: access controls, connector permissions and logging that make the policy real rather than aspirational. Third, brief practical training with real examples from your firm, repeated as tools change — not a one-off slide deck.
Does a small firm really need this, or is it a big-company thing?
Smaller firms often have more exposure, not less: the same sensitive client data, none of the enterprise controls, and staff who quite reasonably reach for whatever tool helps. A proportionate policy for a 15-person firm can fit on two pages and take days, not months, to put in place — and it is increasingly what clients, insurers and due diligence questionnaires ask to see.
Start with an honest picture of what's already in use.
Our AI governance service begins with a readiness assessment — what AI your firm is really using, what data it touches, and the proportionate policy and controls to govern it. Related reading: AI security risks in financial services.