Business practice
AI use policy.
Answer the question your insurer, your auditor, and your largest client are all starting to ask, in one document your team has actually signed.
The renewal form asks whether your firm has a written AI acceptable use policy. There is no box for "we are working on it."
The question arrived without warning and it is now on cyber renewals, professional liability applications, client security reviews, and the due diligence packet in any transaction. It is a yes or no field. Firms that answer no do not fail immediately, they simply move into a category with more questions, higher scrutiny, and occasionally a different premium.
Within a few weeks the answer is yes, and it holds up when someone reads past the first page. Tools are tiered, data classes are defined, every member of staff has acknowledged the document in writing, and you can hand the whole thing to an underwriter or a client without a covering explanation. The anxiety attached to that question is gone, permanently.
The approach
Tier, classify, sign.
Tier.
Tools land in one of three tiers: sanctioned, permitted with conditions, and prohibited. A policy that bans everything gets ignored within a month, and an ignored policy is worse than none because it proves the rule is optional.
Classify.
The real question is never which tool. It is which data. Client identifying information, financial records, health information, privileged material, and internal working documents each get an explicit rule, written in language a new hire understands on the first read.
Sign.
A policy nobody acknowledged is a draft. Every member of staff signs, the acknowledgements are filed, and the document enters onboarding so the next hire signs it in their first week without anyone remembering to ask.
Recognise this
The question is already in your inbox.
- A renewal application or client questionnaire asked about AI use and you answered carefully.
- You have a policy template saved somewhere that nobody has finished or circulated.
- Your professional body has issued guidance and you have not mapped your firm against it.
- Staff ask which tools are allowed and get a different answer depending on who they ask.
- A client has started including AI terms in their engagement letters.
The work
Four parts, and none of them optional.
The written policy
Scope, definitions, permitted and prohibited uses, review obligations, and what happens when the rule is broken. Written for your firm and your obligations, not a template with a name swapped in. Short enough that people finish it.
Tool tiering
A named list of the tools your firm sanctions, the ones permitted under conditions, and the ones that are not to be used with client information. The list has an owner and a date, because a tiering that is never revisited becomes wrong within two quarters.
Acknowledgement and rollout
A signature page, a filing process, and a working session with the team so the document is understood rather than merely distributed. Adoption is the deliverable. A signed page from someone who did not read it protects nobody.
The review cadence
A named owner and a scheduled review, so the policy stays accurate as tools change. This is the part that turns a document into governance, and it is the part almost every firm leaves out.
Related reading.
All insights
Governance
The AI policy your insurer is about to ask about
Cyber and professional liability renewals added a question this year, and most firms cannot answer it yet. A defensible answer is shorter than people expect, but it has four specific parts, and a policy missing any one of them will not survive the follow up question from an
Governance
Shadow AI is already in your firm. Here is the map.
The median hundred person company shows between fourteen and twenty two distinct generative AI services in its browser telemetry. One or two of them are approved. The gap is not a technology problem and it is not solved by blocking domains, because the work that drove people to those tools does not go away when
Questions
Asked before, answered plainly.
No, and that is stated on the first call and inside the document itself. This is an operational policy covering which tools are sanctioned, what data may enter them, and how staff acknowledge the rules. Your attorney should review it. It is written so that review is fast and inexpensive rather than a rewrite.
You can, and a template is better than nothing. The difference shows up in the follow up question. A generic policy does not name your tools, does not match your data classes, and does not survive the moment an underwriter or a client asks how it is enforced. The document is the easy half. Tiering, acknowledgement, and cadence are the half that makes it defensible.
Good, because a prohibition policy fails. The tiering exists precisely so that useful work continues under conditions that are safe and written down. The goal is to move usage from invisible to sanctioned, not to remove it. Firms that ban outright simply push the same activity onto personal devices where nobody can see it.
It is not required, and it makes the policy considerably better. Writing rules for tools you have not confirmed are in use produces a document aimed at the wrong things. Most firms do the exposure review first for that reason, and the findings become the tiering list.
The document and the tiering come together quickly. The gate is acknowledgement, because you cannot claim a policy is in force before your team has signed it. Firms that schedule the rollout session promptly are answering yes within a few weeks, with the signature file to back it up.