Back to Blog
AI GovernanceLeadershipSecurityAI Training

Your First 10 AI Policies: A Starter Pack for Leaders

If you had thirty minutes to draft the AI policies your organisation most urgently needs, what would you include? Here is a practical starting point.

April 1, 2026· Andres Fonseca

Your First 10 AI Policies: A Starter Pack for Leaders

Most organisations launch AI pilots without defining any guardrails at all. Employees share sensitive data with tools whose data handling practices are unknown. Vendors retain prompts for model training without users realising it. Practices diverge across departments because no one’s established a common standard.

The longer this continues, the harder it becomes to establish consistent governance retroactively - which is why a starter set of policies, even an imperfect one, is more valuable than waiting for a comprehensive framework that never quite arrives.

Here’s what I’d include if I had thirty minutes to draft the policies your organisation most urgently needs.

Access and data: the first three

1. Authorised tools and access. Maintain a register of approved AI tools and models. Require a business justification and brief risk assessment for any new addition. Unapproved tools are not permitted until they go through the process. This single policy closes the largest gap in most organisations - the anything-goes approach that nobody officially sanctioned but everyone quietly accepted.

2. Role-based permissions. Define which roles can access which models and what data those models can touch. Map permissions to your existing identity management systems. Audit access regularly. A junior analyst shouldn’t have the same AI access as your head of finance, and stale permissions are a silent risk that grows quietly over time.

3. Data classification and privacy. Classify data by sensitivity, restrict its use in AI systems accordingly, and prohibit the use of confidential or personal data in language models unless it’s been anonymised or masked. This policy is what makes all the others enforceable.

Day-to-day use: the next three

4. Prompt security and safe use. Educate users on injection and leakage risks. Provide approved prompt templates. Include defensive instructions in high-risk interactions. This is the policy most organisations think they don’t need until something goes wrong.

5. Human oversight for high-impact decisions. Require human review for any AI-assisted decision that affects customers, employees, or other significant stakeholders. Document the approval workflow. High stakes require human accountability - full stop.

6. Model evaluation and bias monitoring. Establish criteria for accuracy, fairness, and reliability. Schedule periodic reviews. Document results and corrective actions taken. What you don’t measure, you can’t improve - and regulators will ask.

The broader governance ecosystem: the final four

7. Vendor due diligence. Use a structured questionnaire to assess vendors on data security, model performance, and compliance before any tool is approved. Ensure contracts address data usage and model update practices. Your vendor’s risk is your risk.

8. Incident reporting and response. Define how to report AI incidents - misleading outputs acted upon, data leaks through prompts, bias complaints. Assign owners for each category. Include escalation procedures and remediation steps. The first time something goes wrong is not the moment to figure out your escalation path.

9. Training and literacy. Require AI literacy training for all users, tailored by role, with hands-on practice rather than passive consumption. The EU AI Act requires staff to have sufficient AI literacy - this policy is how you meet that requirement.

10. Policy review and evolution. Set a regular cadence - quarterly is a reasonable starting point - to review and update policies as technologies and regulations develop. A policy that doesn’t evolve becomes a liability.

One final thing

Policies stifle innovation only when they’re applied too rigidly or without contextual judgment. Allow documented exceptions for experiments, provided associated risks have been assessed and recorded. A policy framework that can’t accommodate innovation will be worked around rather than followed. Good AI policies enable teams to experiment with confidence - because everyone understands the boundaries and trusts that they exist for good reasons.

Want more like this?

Get the latest AI marketing and automation insights delivered to your inbox.

Subscribe to the Newsletter →