Keywordsworkplace ai policy for small teamsBlogai for workai at workworkplace aiai for professionalshow to use ai at workai productivity
Related searchesworkplace ai policychatgpt policy for teamsai acceptable use policysmall team ai policychatgpt acceptable useworkplace ai policy for small teams
Two pages, four decisions, one named owner
A workplace AI policy for a small team can fit on two pages. It does not need a framework diagram. It needs allowed tools, data classes, review rules, and a named owner. Without those, people will invent a practice in private chats: paste the client file, send the fluent draft, hope. With those, you can say yes to useful work and no to a leak without a meeting every time. ChatGPT does not care whether you wrote the rule. Your customer, your insurer, and the person whose name is on the email will. The policy is not theatre. It is the minimum written judgement a team can share.
If you cannot name the allowed tools, the banned pastes, and the owner, you do not have a policy. You have a hope that people will be careful.
What the two pages actually have to say
Page one: purpose, allowed tools, data classes, and the default no. Public ChatGPT is not the same as an enterprise workspace. Internal notes are not the same as customer files. If a class is not listed as allowed in a tool, it is not allowed. Page two: review rules, examples, and how to ask. Who signs client copy. Who may not use a model on HR files. What to do after a bad paste. Name the owner and a deputy. Date the document. Give it boring examples from your actual work, not a bank's appendix. Write the rule you will actually apply on a Thursday.
| Section | What to write | Weak version |
|---|---|---|
| Tools | Named products and who may use them | People may try AI |
| Data classes | Public, internal, restricted, secret | Do not share anything sensitive |
| Review | What a human must check before send | Use judgement |
| Owner | Name, deputy, and review date | The leadership team |
Write the rule from last month's actual work
List the five artefacts the team sends most. For each, write the tool, the class, and the reviewer. That list is the policy's spine. Add the banned pastes from real close calls, not from a vendor blog. Ban secret scoring of people unless you have a lawful, approved process, which most small teams do not. Say how to report a bad paste. Then put the two pages where onboarding happens. Walk through one example in a fifteen-minute meeting. Keep a saved brief for updating the policy when a new tool appears: name, class, owner, yes or no. A policy that is not updated is a decoration. A policy that is used in the stand-up is a control.
Role: You are drafting a two-page workplace AI policy I will own.
Task: Turn the decisions I paste into a short policy a new joiner can follow.
Context: Team size, tools we already pay for, and the artefacts we send most.
Constraints:
- Do not invent legal clauses, regulators, or tools I did not name.
- If a decision is missing, write [missing] instead of guessing.
- No slogans. Name tools, classes, reviewers, and one owner.
Output: Two pages: tools and classes, then review, incidents, and owner.
Quality checks: Which lines a hurried person could still read as permission to paste a client file.If the critique list shows a slogan or a missing owner, you have already been saved a fake policy. That list is the point of the prompt. Save the two pages where onboarding happens so the next joiner does not need a call. Keep the draft they could follow, and retire the one that sounded like a bank and would never be opened. A dated owner beats a values poster.
Poster policies, shadow tools, and an owner who is everyone
Poster policies are the common failure. A page of values with no tool names will be ignored on the first deadline. Shadow tools are worse: the policy names Copilot and everyone still uses a personal ChatGPT account on the client file. The third failure is an owner who is everyone, or the leadership team, which means nobody. Fluency in the document is not governance. Governance is a named person who can say that class does not go in that box, and a review rule that still applies when the client wants the deck tonight. Write the short version. Use it. Date the next review. That is a workplace AI policy for a small team.
| Mistake | What it looks like | What to do instead |
|---|---|---|
| Use AI well | No tools, no classes, no owner | Two pages with names and dates |
| Shadow chat | Personal account, client file | Named tool or do not paste |
| Owner is everyone | Leadership will decide | One name and a deputy |
| Never updated | A PDF from last year | Review date and a yes or no on new tools |
A policy with no owner and no banned paste is not a control. It is a document you will point to after the leak. Name an owner first.
Related reading on StudyGrid
Read next: Risk, Security and Governance How to Keep a Human in the Loop What Not to Paste into ChatGPT. Those essays sit beside this one. Use them when you need the neighbouring skill, not as a substitute for the check you still have to make.
What to do this week
Write the two pages this week from five real artefacts. Name the tools, the classes, the reviewers, and one owner, with a review date on page one. Walk the team through one example in fifteen minutes. Kill one shadow path. Keep the policy if a new joiner can follow it without a call, and put it where onboarding happens. Date the next review now. That is enough governance to start.