Blog September 11, 2026

A generative AI policy people will actually follow

A long policy gets acknowledged and ignored. Here is the version that fits on one page and holds up, plus what role-based training has to cover.

Long policies fail. We have watched a twenty-four page acceptable-use document get formally acknowledged by an entire company and change nobody's behaviour, because almost nobody read past the second page.

Short and enforceable beats thorough and ignored.

What has to be in it

Which tools are approved, listed by name. Not "enterprise-grade tools" but the actual list, plus what someone does when they want to add one.

What customer data may go in, written as plainly as you can manage. Most teams need a sentence here, not a taxonomy.

How long conversations are kept, and where they live.

Which outputs need a human signature before they leave the building or touch a payment.

Who to tell when something looks wrong. A name, not a shared inbox.

That fits on a page, and people will read a page.

Train for judgment, and train by role

Generic AI training produces generic results. Finance, support and engineering do different work, carry different risk, and need different examples.

Support needs to recognise what a plausible and wrong answer looks like when it concerns a customer's contract. Finance needs to understand what happens when a model is asked to reconcile something it cannot actually see. Engineering needs the rules on code and secrets, in writing.

Use real examples from your own business, including the ones that went badly. Especially those.

Measure use, then decide

Track how many people use it in a given week, how long the targeted task takes now, and whether incidents went up.

If those numbers are flat after a quarter, the workflow is wrong. Swapping model rarely fixes a workflow problem, though it is almost always the first thing people try.

We deploy this and train the teams who have to live with it, including Copilot rollouts.