An AI policy is a reasonable goal. It is just not always the first step.
Before a business can set useful rules, it needs a clear picture of what is already happening. Someone is likely using AI to draft client emails. Someone else may be pasting notes into a chatbot, using an AI meeting recorder, or connecting an AI tool to the CRM. None of that is automatically a problem. But it is hard to manage what nobody has named.
Start with a short inventory, not a big audit. Ask each team which AI tools they use, what job each tool helps with, and whether it touches customer, employee, financial, or internal business information.
The goal is not to catch people doing something wrong. It is to understand where useful experiments are happening and where the risk is different than it first appears.
For each tool, answer five plain-language questions: What data goes in? What comes out? Can it take action in another system? Who reviews its work? What happens if the tool is wrong?
Those questions quickly reveal the difference between a low-risk writing assistant and a workflow that can affect a customer record, a contract, or a payment. They also make it easier to identify duplicate subscriptions and shadow processes that could be replaced with a safer, approved option.
Keep the inventory somewhere the right people can update it. A shared spreadsheet is enough to begin. Include the tool name, business owner, use case, data type, connected systems, approval status, and next review date.
This is not about slowing down the team. It is how you make the good uses of AI easier to support while putting guardrails around the ones that need them.
Once you can see the work, you can make better decisions about access, training, vendors, and human review. That is a much stronger starting point than a generic rule telling everyone to be careful.
The first useful AI policy is often a list of what is actually happening.
Not sure what your website should be asking people to do?
Let's figure it out →