Back to Blog
AI GovernanceLeadershipAI TrainingSecurity

How to Create an AI Policy Employees Will Actually Follow

Telling employees not to feed confidential data into ChatGPT isn't enough. Without context and practical guidance, they'll ignore you - or find workarounds.

April 1, 2026· Andres Fonseca

How to Create an AI Policy Employees Will Actually Follow

Here’s the AI policy nobody writes: “Use AI however helps you, we trust your judgment.” Here’s what most organisations write instead: three pages of legalese, a list of things not to do, and no guidance on anything useful.

Wonder why people ignore it? I don’t.

Let me be real about what a policy that actually works looks like - and why most organisations are so far from it.

The problem with standard AI policies

Blanket bans and vague warnings breed exactly one outcome: people work around them. Employees want to experiment with AI because it saves them genuine time. When you give them unclear rules, two things happen. Some avoid AI entirely and miss real productivity gains. Others use it without guardrails and create risk that compounds quietly in the background.

Neither outcome is what you want. And the compliance pressure is real - the EU AI Act requires staff to have sufficient AI literacy, and NIST’s framework treats training and documentation as core governance requirements. When organisations fail to provide that guidance, they’re creating both a capability gap and a compliance exposure.

Trait one: context, not just prohibition

A good policy doesn’t just say “don’t do X.” It explains why. This is the difference between a policy people understand and one they resent.

Include examples of proper and improper use, referencing your actual data classifications and the specific regulations that apply to your industry. Remind users that AI tools don’t retain memory between interactions unless they explicitly provide context - and explain why that matters for how they structure their prompts. That single piece of education prevents a significant category of data exposure.

Trait two: practical standards people can actually use

This is where most policies completely fall short. Provide employees with a prompt library tailored to their common tasks - not generic examples, but real workflows they recognise.

Show a marketing manager how to generate a campaign brief without exposing confidential data. Show a finance analyst how to use AI for modelling without pasting sensitive figures into an unvetted tool. Offer standards for tone, style, and ethics that make good behaviour the path of least resistance. When doing the right thing is also the easy thing, compliance follows naturally.

Trait three: positive reinforcement and real feedback loops

A policy is a living document or it’s a dead one. Recognize teams that follow the policy and share those success stories internally. Encourage employees to flag gaps in the guidance. Update the policy regularly based on what you learn.

A document that evolves with the organisation earns trust. A static decree erodes it. When rolling out the policy, run interactive sessions where employees can ask questions and practise in a safe environment - not just read the document and sign an acknowledgement.

One more thing: different functions need different policies

A legal team needs stricter guidelines than a marketing team. A customer-facing support agent has different risks than an internal analyst. No single policy can cover every scenario, so build in explicit judgment calls and provide a clear channel for questions when people aren’t sure.

Overly prescriptive rules discourage the thoughtful experimentation that produces real productivity gains. The goal is employees who are your first line of defence - not your biggest compliance risk. Give them the context, examples, and support they need to be that.

Want more like this?

Get the latest AI marketing and automation insights delivered to your inbox.

Subscribe to the Newsletter →