This template is a starting point, not a finished governance program — frameworks like NIST's AI guidance go deeper. Adapt it with whoever owns legal/compliance risk for the org. It is not legal advice.

Fill in the bracketed blanks. Keep each section to 1–3 sentences.

1. Purpose — We enable AI use safely, not ban it.

2. Approved tools — See the [AI Tool Inventory](AI Tool Inventory) ✅/🟡 views. Anything not listed = ask first, not never.

3. The one rule that matters[Client/customer data, credentials, and regulated data (PHI/PCI/PII) go ONLY into tools on the approved list marked for that data class.]

4. Meeting bots — Recording/notetaker tools require disclosure and client consent on client calls.

5. Accounts — Work AI use happens on work accounts/workspace tiers [where available]; no personal-account processing of company data.

6. Output responsibility — The human who ships it owns it. AI output gets reviewed like an intern's first draft.

7. Review cycle — Inventory and policy re-checked quarterly, owned by [owner name].

8. Report, don't hide — Found a useful tool? Submit it for approval — the default answer is "yes, with rules."