An AI policy people actually follow fits on one page.
Most AI policies fail because they are too long to read. A usable one fits on a page and answers four plain questions your team can actually hold in their head.
Most AI policies fail the same way. They are long, written mostly to cover someone, and nobody reads past the second heading. So people keep pasting client data into whatever tool is open, and the document sits in a folder doing nothing.
A policy only works if people can hold it in their head. That means one page, in plain language, answering the questions they actually have.
The questions a useful policy answers
What can I put into AI tools, and what must never go in. Which tools are approved, and who to ask if mine is not on the list. When a human has to check the output before it goes anywhere. And who to tell if something goes wrong, without fear of being blamed for raising it.
That is most of it. If your team can answer those four things from memory, you have a working policy. If they cannot, the length of the document will not save you.
Why the short version is safer, not riskier
The instinct is that more rules mean more protection. In practice the opposite holds. A long policy gets skimmed and ignored, so the real behaviour becomes whatever people improvise. A short policy that everyone has actually read shapes what happens on a Tuesday afternoon, which is where the risk really lives. Australia's privacy reforms are raising the stakes on data handling and automated decisions, and "we had a policy no one read" is not much of a defence.
Start with what is already happening
Before writing a word, find out how your team uses AI today. You will usually discover it is already in the building, just unmanaged. Write the page to fit that reality, draw the few lines that genuinely matter, and make it easy to do the right thing. A policy people follow beats a thorough one they do not.