A policy only works when people can recognise the decision in front of them, find the right rule and act without unnecessary friction.
This playbook supports the Foundation AI Use Policy and assumes the policy has been adapted and formally approved.
What good implementation produces
At the end of the first implementation cycle, people should know which tools they can use, which information is permitted, when review is required and where to ask for help. Leaders should be able to see where AI is used, who owns higher-risk cases and what evidence supports approval.
Start with the decisions people face most often. A usable approved-tool list and review route will do more than a large framework nobody can navigate.
Before you begin
- Name an executive sponsor and a day-to-day owner.
- Confirm who may approve tools, higher-risk uses and exceptions.
- Identify the teams already using AI and the work they use it for.
- Create two approved starting prompts for familiar, low-risk work.
- Agree the reporting route for questions, near misses and incidents.
- Adapt and approve the Foundation AI Use Policy for your organisation.
A practical 30-day plan
Days 1–5 · Name the decisions
Interview a small cross-section of people. Collect real examples of AI-assisted work, information being entered, outputs being relied upon and areas of uncertainty. Group them by impact rather than by novelty.
Days 6–10 · Set the route
Publish one place for the policy, approved tools, permitted information, higher-risk approval and incident reporting. Use language people already recognise from their work.
Days 11–15 · Test with real work
Run the policy against five to ten genuine scenarios. Include ordinary uses, such as using AI in Canva or using an approved writing assistant to improve a draft for LinkedIn, so the policy is not tested only against exceptional risk. Ask people to find the answer without coaching. Note hesitation, disagreement and missing information.
Days 16–20 · Equip reviewers
Nominate reviewers for subject accuracy, privacy, rights, risk and brand. Give them a short checklist, clear authority to reject and a route for escalation.
Days 21–25 · Launch in context
Brief managers first, then teams. Use examples from their work: a safe use, a use needing stronger review and a use the organisation will not permit.
Days 26–30 · Check and improve
Review questions, approval time, tool use, near misses and confusing clauses. Publish the first changelog and set the next review date.
The everyday workflow
Define the purpose
What is AI helping with, who will use the result and what happens next?
Check the tool and information
Is the tool approved for this work? Is every input permitted?
Judge the impact
What could happen if the output is wrong, biased, disclosed or misunderstood?
Create and verify
Use clear instructions, then check facts, sources, assumptions, rights and omissions.
Review and approve
Use a reviewer with the right knowledge, independence and authority.
Keep proportionate evidence
Record more when the possible impact is greater.
AI can sound confident while inventing details, missing context or smoothing over uncertainty. Treat fluency as presentation, not evidence. If a result matters, check it against reliable sources. If the evidence is missing, narrow the task, label the gap or stop and ask someone who knows the context. A longer prompt will not fix every problem.
Give people a better starting point
A policy tells people what is permitted. An approved prompt pack turns brand, quality and review expectations into a useful starting context. It reduces blank-page anxiety and helps ordinary work begin well.
Create within the brand.
Pair this with the approved Brand Kit, templates and asset library. Do not paste confidential brand strategy into an unapproved account.
Strengthen the author’s voice.
Use this in an approved writing assistant. The named author checks every claim, restores personal judgement, approves the final version and then publishes it on LinkedIn.
Give it an owner, version and review date. Update it when the brand, evidence or tool changes. The aim is not to automate taste. It is to give people a stronger place to begin.
Evidence worth keeping
Do not retain everything by default. Keep enough to explain important decisions and meet existing record-keeping duties.
- purpose, owner and intended audience;
- tool and material settings used;
- information category, without duplicating sensitive inputs unnecessarily;
- risk or impact judgement;
- checks completed, material sources and corrections made;
- reviewer, approval and date;
- exceptions, incidents and lessons learned.
Measures that reveal whether it works
Prefer a small set of useful signals to vanity totals.
- Findability: can people locate the rule and approved-tool answer quickly?
- Understanding: can they explain when human review or approval is needed?
- Application: are higher-risk uses identified before release rather than after?
- Friction: how long do routine questions and approvals take?
- Learning: do questions and near misses lead to visible improvements?
If people work around the process, investigate the decision environment. The route may be hard to find, slow, vague or disconnected from how work actually happens.
Check you’re using the current version
This playbook is Version 1.0, reviewed 2 August 2026. Material changes are recorded in the Foundation release record.
View the Foundation release record