AI policy (example)¶
This is a template. Adapt to your organization’s security and compliance standards.
Allowed¶
- Drafting and rewriting from approved sources
- Summarizing public or already-approved internal content
- Creating checklists and templates for human review
Not allowed¶
- Pasting confidential data into external tools without approval
- Generating “facts” that are not present in a trusted source
- Auto-publishing AI output without a review lane
Required controls¶
- Data classification label for every AI workflow
- Prompt versioning + change review (PromptOps)
- Documented evaluation + periodic audits