This template is a starting point, not a finished governance program — frameworks like NIST's AI guidance go deeper. Adapt it with whoever owns legal/compliance risk for the org. It is not legal advice.
Fill in the bracketed blanks. Keep each section to 1–3 sentences.
1. Purpose — We enable AI use safely, not ban it.
2. Approved tools — See the [AI Tool Inventory](AI Tool Inventory) ✅/🟡 views. Anything not listed = ask first, not never.
3. The one rule that matters — [Client/customer data, credentials, and regulated data (PHI/PCI/PII) go ONLY into tools on the approved list marked for that data class.]
4. Meeting bots — Recording/notetaker tools require disclosure and client consent on client calls.
5. Accounts — Work AI use happens on work accounts/workspace tiers [where available]; no personal-account processing of company data.
6. Output responsibility — The human who ships it owns it. AI output gets reviewed like an intern's first draft.
7. Review cycle — Inventory and policy re-checked quarterly, owned by [owner name].
8. Report, don't hide — Found a useful tool? Submit it for approval — the default answer is "yes, with rules."