2-sec AI practice / AI Policy Development

Give Your People AI Rules They Can Actually Follow

Make it clear which AI tools people can use, what information they can share and when human judgement or approval is needed.

2-sec develops practical AI policies around the way your organisation works, helping you protect systems and data while supporting useful AI adoption.

Part of the 2-sec AI practice for securing AI systems and data through AI governance.

Plain languageRules people can understand
Relevant examplesGuidance grounded in real work
Clear ownershipDefined approvals and escalation
Practical adoptionSupport for putting policy into use
The policy gap

People should not have to guess what responsible AI use means

When guidance stops at broad principles, employees still have to make the difficult decisions themselves. A practical policy connects those principles to the tools, information and tasks in front of them.

Clarity

Remove uncertainty from routine work

Explain what is permitted, what needs approval and what is prohibited, so people can recognise the boundaries before they start.

Protection

Make safer information handling easier

Give teams usable rules for confidential material, personal information and business data, matched to the tools and environments they use.

Consistency

Give managers a shared basis for decisions

Define who can approve new uses and exceptions, helping teams apply consistent rules without escalating every everyday task.

What Is AI Policy Development

AI policy development defines an organisation’s rules, responsibilities and approval requirements for using AI. It translates business priorities and risk decisions into guidance that employees and managers can apply in their work.

Acceptable Use

Defines which AI tools and activities are permitted, restricted or prohibited, with clear conditions for using approved services and a route for requesting new uses.

Information Protection

Sets rules for the information people may enter, upload or connect to AI tools, reflecting data sensitivity, approved environments and the purpose of the task.

Human Oversight

Specifies when AI outputs need checking, who remains responsible for their use and which decisions require human review before action is taken.

Ownership and Review

Assigns responsibility for approvals, exceptions and policy updates, with clear reporting routes and review triggers that keep the guidance aligned with changing AI use.

What the policy covers

Turn AI principles into clear working rules

The scope reflects your AI use, risk priorities and existing policies. We agree the areas to cover and the level of detail each audience needs.

Tools and use cases

Define acceptable AI use

Set out approved tools and purposes, prohibited activities and the route for requesting a new tool or a change in how an existing one is used.

Information handling

Set boundaries around business data

Clarify which information may be entered, uploaded or connected to AI services, including differences between approved business environments and personal accounts.

Outputs and oversight

Specify when people must review

Define the checks needed before AI outputs are shared or relied on, with additional review for decisions that could materially affect people or the business.

Ownership and approval

Make decision routes explicit

Identify policy owners, approvers and user responsibilities. Set criteria for escalating higher risk uses and documenting authorised exceptions.

Incidents and concerns

Explain how to raise a problem

Tell people what to do if they share restricted information, notice unexpected behaviour or suspect misuse, connecting the guidance to existing reporting channels.

Review and change

Keep the rules useful as AI evolves

Set review responsibilities and triggers for changes in tools, use cases or risk. Explain how updates are approved and communicated to affected teams.

What you receive

A policy package built for use across your organisation

Agree the deliverables before work starts, with enough detail for policy owners and a clear way for employees to find the guidance they need.

Policy document

A tailored AI policy

A policy covering the agreed scope, permitted and restricted uses, responsibilities, approval routes and review arrangements, prepared for your internal approval.

Employee guidance

A practical quick reference guide

A concise companion with realistic examples, key checks and escalation routes, helping employees apply the policy without working through the full document each time.

Adoption and ownership

A rollout and maintenance plan

Recommended steps for communicating the policy, briefing managers, recording acknowledgement where appropriate and assigning responsibility for future updates.

Illustrative policy guidance

Before uploading a customer document to an AI tool

Check that the tool and account are approved for the task and the document’s information classification. If either is unclear, pause and contact the designated owner before uploading. Review any output before sharing it.

The final guidance names your actual approval route and reflects your agreed data rules.

How we work

Build the policy around real decisions your people face

We work with relevant business, technology, security, privacy and people teams to make the policy clear, proportionate and workable.

1

Understand current use

Review known AI tools, common tasks, existing policies and points of uncertainty. Agree the audiences, scope and decisions the policy needs to support.

2

Agree the boundaries

Work through permitted uses, data restrictions, review requirements and approval responsibilities with the people accountable for those decisions.

3

Draft and test the guidance

Develop the policy and supporting guidance, then walk through realistic scenarios with stakeholders to identify ambiguity or rules that are difficult to apply.

4

Prepare for adoption

Refine the documents for internal approval, confirm ownership and provide a practical rollout plan with review triggers and communication priorities.

Employee training delivery, technical configuration and ongoing policy management can be scoped separately where needed.

Connected to your security programme

Make the policy fit the controls around it

A policy needs to reflect what your organisation can approve, enforce and monitor. The work connects AI rules with existing security, information governance and operational processes.

Existing policies

Build on the rules you already have

Connect AI guidance with acceptable use, data classification, access management and supplier review, reducing conflicting instructions and unnecessary duplication.

Practical controls

Identify what needs to support the policy

Highlight where permissions, approved tool settings or reporting processes need attention so employees have the means to follow the agreed rules.

Shared accountability

Give each decision a clear owner

Connect employee guidance with management responsibilities so approvals, exceptions and concerns reach people who can act on them.

The wider AI practice

Connect your AI policy to governance and risk

AI Policy Development gives your people the rules for everyday use. AI Risk Assessment helps establish which exposures those rules need to address, while AI Governance provides the wider responsibilities and oversight.

For organisations pursuing ISO 42001, policy development can contribute to the broader management system. Certification readiness involves additional work beyond the policy itself.

A useful starting point when

  • Teams are using AI without consistent guidance.
  • You are preparing to introduce an approved AI tool.
  • Your current policy is too broad or difficult to apply.
  • Managers are handling similar requests differently.
  • You need to bring existing AI rules into a wider governance programme.
Questions before you start

Know what to expect from AI policy development

The initial discussion establishes what you already have, where guidance is missing and what a useful policy package needs to include.

Can you improve an existing AI policy

Yes. We can review existing documents for gaps, unclear language and practical usability, then agree whether a targeted update or a more substantial revision is appropriate.

Is this relevant if we only use tools such as Copilot or ChatGPT

Yes. The policy can focus on how employees use third party tools, including approved accounts, information handling, output checks and requests for new uses. You do not need to develop your own AI systems.

Will we need a separate policy for every team

Not necessarily. A shared policy can establish the core rules, with role specific guidance where tasks, data or decision responsibilities differ. We agree the simplest structure that covers those differences clearly.

How do you make the policy easy for employees to follow

We use plain language, clear decision routes and examples based on real work. Scenario reviews help reveal missing information or ambiguous rules before the policy is prepared for rollout.

Does this include employee training and technical changes

The engagement can include supporting guidance and rollout planning. Training delivery, changes to tool settings and ongoing management are separately agreed so responsibilities and deliverables are clear.

How long does the work take and what does it cost

This depends on your AI use, existing documentation, stakeholder availability and the scope of the policy package. The proposal sets out deliverables, timing and cost before work begins.

Your next step

Give your people a clearer way to use AI

Tell us how your teams use AI and where the rules are missing or unclear. We’ll help define a policy package that fits your organisation and the decisions your people need to make.

Discuss Your AI Policy Needs →

Bring your existing policy or start with the questions your teams are asking.