Unit 2 / 12

How to Write a Corporate AI Use Policy

Gains:

  • Generate a draft using the eight-part policy template
  • Write usage rules based on four-level data classification
  • Implementing the policy and following the enforcement checklist

When the task of “drafting an AI policy to be presented to the board next Friday” lands on a compliance officer's desk, many fear the blank slate. However, a good AI policy is architecturally standard: it has a predictable eight-part framework. In this unit, we will build that skeleton section by section, delve into the data classification that is its heart, and see the steps to put the draft into effect. The aim is to produce a concrete document that can be presented on Friday.

The golden rule of policy writing

The one-sentence test of a good policy is: "Can an employee read this document in 10 minutes and clearly answer the question 'what can I do and what can't I do?'" If the document is 30 pages long, written in legal language and does not contain concrete examples, the test fails. The policy should be short, exemplary and action-oriented.

Eight-part skeleton

The table below is a proven AI policy framework. Each institution adapts this to its own context.

#

Section

What answers?

1

Purpose and scope

Who and what tools does the policy cover?

2

Definitions

What do terms like AI, shadow AI, personal data mean?

3

Roles and responsibilities

Who approves, who inspects, who is responsible?

4

Data classification and usage rules

What data can be entered into which tool?

5

Approved vehicles and approval process

Which vehicles are free, how is a new vehicle approved?

6

Prohibited uses

What should not be done under any circumstances?

7

Human inspection and verification

How to control the output, who is responsible?

8

Violation, sanction and enforcement

What happens if the rule is broken, when is the document updated?

Tip: Aim to fit the policy on one page with these eight headings first. Post-link as adds detail (approved vehicle list, classification guide). The shorter the main text, the more readable it is.

Heart: four-level data classification

The most critical part of the policy is data classification, which determines which type of data can be entered into which AI tool. Four levels are common and sufficient:

Level

sample data

Usage rule in AI

open (public)

Published brochure, press release

Free; Any approved vehicle can be entered

in-house

Internal procedure, meeting note (personal/non-confidential)

Only on corporate (contract) vehicles

Confidential

Customer list, contract, financial data

Approved corporate vehicle + masking only; personal vehicles prohibited

Special/critical

Health, race, religion, biometrics, criminal data

As a rule, it is not entered; only with special approval and legal basis

Special personal data is the category of sensitive data for which KVKK provides extra protection: health, sexual life, race, ethnicity, political opinion, philosophical belief, religion, sect, dress, association/foundation/union membership, criminal conviction and biometric/genetic data. The processing of this data is subject to much stricter conditions; Breaking into an AI tool almost always requires special legal consideration.

Three mini cases: classification decisions

Case 1 — Payroll. The HR specialist wants to give the payroll of 120 employees to an AI so that it can "analyze and produce a salary inequality report". Payroll is both confidential and contains personal data as it contains name and surname. Right decision: anonymize data (code names like "Employee-001", preserve department), enter only in approved corporate tool. Anonymized 120 lines of analysis are done with confidence; raw payroll never goes into the personal vehicle.

Case 2 — Patient history. A nurse in a healthcare facility wants to use AI to summarize a patient history. This is special quality data. By policy, this type of data is strictly prohibited in a personal vehicle; However, it can only be processed in a system approved by the institution, which has a special contractual and legal basis for health data. The classification table shows this distinction at a glance.

Case 3 — Press release. Marketing gives AI a published press release to “transform into 5 different versions for social media.” Because the data is open, there are no restrictions; The employee works in the approved vehicle without hesitation. A good classification also eliminates unnecessary friction: it doesn't say "no" for open data, it says clear "stop" for private data.

Attention: When classifying a data, "Is there even a single piece of personal data in it?" and “will it harm the institution?” Ask your questions together. If a document is clear from a business perspective but has a customer name in it, that document now carries personal data and is upgraded.

Prohibited uses section

The most read part of the policy is usually the bans. It should be concrete and exemplary. Typical prohibitions:

  • Entering sensitive personal data (health, biometrics, etc.) into the vehicle without approval.
  • Entering confidential data or company secret into individual/personal AI accounts.
  • Using AI output as legal, medical, financial decisions without verifying it.
  • Leaving decisions affecting people, such as recruitment, promotion, and credit, solely to AI.
  • Using AI to impersonate a person, produce false content or misleading information.
  • Producing and publishing copyrighted content without permission.

Copiable templates

TEMPLATE 1 — Purpose and scope section outline: "Write the 'Purpose and Scope' section of an AI policy for an [industry] company. Make it clear: who the policy covers (all employees, consultants) and which tools (generative AI, code assistants); state the purpose as 'enable responsible and compliant use.' 150 words or less, plain language."

TEMPLATE 2 — Generate a data classification table: "Classify the following data types as public / on-premises / confidential / proprietary and suggest AI usage rule for each: [list data types]. Make the output a 3-column table: data type, class, AI rule. Put a '*legal confirmation' mark on the type you are not sure about."

TEMPLATE 3 — Prohibited uses list: "Write the 'Prohibited Uses' section item by item for an institution subject to KVKK. Each item should include a concrete example ('For example: ...'). At least 8 items. Tone: clear and imperative, but reasoned."

TEMPLATE 4 — Employee summary (one-page): "Reduce this 20-page AI policy into a one-page summary to hang on employees' desks: 'You can' and 'You can't' columns + 5 golden rules + person to ask questions. Simple, visual, memorable."

Weak prompt / Strong prompt

WEAK: “Write an AI policy for my company, it should cover everything.”-> The model produces 15 pages of generic text that no one reads and does not fit the organization; data classes and approval process remain unclear. STRONG: "We are an e-commerce company of 80 people, processing customer address and order data. Produce a 4-level data classification table, 6 prohibited items and a one-page employee summary of the AI ​​policy. Include the masking rule for personal data. Tick the legal points you are not sure about, let me decide." -> The model gives concise, applicable, contextual and verifiable output.

Steps to enact the policy

Writing is half of it; The real job is to turn the policy into a living rule. Steps:

  1. Draft: Complete eight chapters, prepare appendices.
  2. Stakeholder opinion: Get written feedback from legal, IT, HR and business units.
  3. Legal approval: Legal/compliance signature for KVKK and legislation compliance.
  4. Senior management approval: Signature that makes the document an official corporate policy.
  5. Announcement and education: A short session for everyone; Distribute a one-page summary.
  6. Approval record: Keep employees' "I have read, I understand" approval in the system.
  7. Review schedule: Set an update date at least every 6 months.
Tip: Put a "version and date" box on the last page of the policy. AI and legislation change very quickly; Knowing which version is valid saves lives in an audit.

Common mistakes

  • Writing the policy in very long and legal language and making it unreadable.
  • Skipping data classification and passing in vague phrases like “be careful.”
  • Confusing a special category of data with normal confidential data.
  • Writing bans without creating an approved vehicle list and approval process.
  • Writing prohibitions abstractly without giving concrete examples.
  • Skipping the employee training and approval registration step and saying "I announced it via email."
  • Not setting a review schedule and writing the policy once and forgetting about it.

In summary

  • A good policy consists of eight standard parts; It should be short, exemplary and action-oriented.
  • Its heart is the four-level data classification that determines which data goes into which tool.
  • Special categories of personal data (health, biometrics, etc.) are subject to the strictest rule; As a rule, AI is not included.
  • Prohibited uses must be concrete and exemplary; It should be defined along with the approved tools and approval process.
  • Once the policy is written, it is kept alive through stakeholder opinion, legal and management approval, training and regular review.

Application task

Concretely fill out at least three sections of the eight-section skeleton (Purpose and Scope, Data Classification, Prohibited Uses) for an institution of your choice. Set up a data classification table with four levels and place at least eight actual data types your organization processes into it; Write an AI rule for each. Then boil those three sections down to a one-page "You Can/You Can't" summary that can be posted on employees' desks. Finally, note which two of the policy implementation steps you find most difficult for your organization and how you will overcome them.

checklist

  • [ ] I adapted the eight-part framework to my institution.
  • [ ] I filled out the four-level data classification table.
  • [ ] I have bound special data to a separate and strictest rule.
  • [ ] I wrote the prohibited uses with concrete examples.
  • [ ] I described approved tools and the approval process.
  • [ ] I prepared a one-page employee summary.
  • [ ] I planned a legal approval and review schedule.