Remove uncertainty from routine work
Explain what is permitted, what needs approval and what is prohibited, so people can recognise the boundaries before they start.
Make it clear which AI tools people can use, what information they can share and when human judgement or approval is needed.
2-sec develops practical AI policies around the way your organisation works, helping you protect systems and data while supporting useful AI adoption.
Part of the 2-sec AI practice for securing AI systems and data through AI governance.
When guidance stops at broad principles, employees still have to make the difficult decisions themselves. A practical policy connects those principles to the tools, information and tasks in front of them.
Explain what is permitted, what needs approval and what is prohibited, so people can recognise the boundaries before they start.
Give teams usable rules for confidential material, personal information and business data, matched to the tools and environments they use.
Define who can approve new uses and exceptions, helping teams apply consistent rules without escalating every everyday task.
AI policy development defines an organisation’s rules, responsibilities and approval requirements for using AI. It translates business priorities and risk decisions into guidance that employees and managers can apply in their work.
Defines which AI tools and activities are permitted, restricted or prohibited, with clear conditions for using approved services and a route for requesting new uses.
Sets rules for the information people may enter, upload or connect to AI tools, reflecting data sensitivity, approved environments and the purpose of the task.
Specifies when AI outputs need checking, who remains responsible for their use and which decisions require human review before action is taken.
Assigns responsibility for approvals, exceptions and policy updates, with clear reporting routes and review triggers that keep the guidance aligned with changing AI use.
The scope reflects your AI use, risk priorities and existing policies. We agree the areas to cover and the level of detail each audience needs.
Set out approved tools and purposes, prohibited activities and the route for requesting a new tool or a change in how an existing one is used.
Clarify which information may be entered, uploaded or connected to AI services, including differences between approved business environments and personal accounts.
Define the checks needed before AI outputs are shared or relied on, with additional review for decisions that could materially affect people or the business.
Identify policy owners, approvers and user responsibilities. Set criteria for escalating higher risk uses and documenting authorised exceptions.
Tell people what to do if they share restricted information, notice unexpected behaviour or suspect misuse, connecting the guidance to existing reporting channels.
Set review responsibilities and triggers for changes in tools, use cases or risk. Explain how updates are approved and communicated to affected teams.
Agree the deliverables before work starts, with enough detail for policy owners and a clear way for employees to find the guidance they need.
A policy covering the agreed scope, permitted and restricted uses, responsibilities, approval routes and review arrangements, prepared for your internal approval.
A concise companion with realistic examples, key checks and escalation routes, helping employees apply the policy without working through the full document each time.
Recommended steps for communicating the policy, briefing managers, recording acknowledgement where appropriate and assigning responsibility for future updates.
Check that the tool and account are approved for the task and the document’s information classification. If either is unclear, pause and contact the designated owner before uploading. Review any output before sharing it.
The final guidance names your actual approval route and reflects your agreed data rules.
We work with relevant business, technology, security, privacy and people teams to make the policy clear, proportionate and workable.
Review known AI tools, common tasks, existing policies and points of uncertainty. Agree the audiences, scope and decisions the policy needs to support.
Work through permitted uses, data restrictions, review requirements and approval responsibilities with the people accountable for those decisions.
Develop the policy and supporting guidance, then walk through realistic scenarios with stakeholders to identify ambiguity or rules that are difficult to apply.
Refine the documents for internal approval, confirm ownership and provide a practical rollout plan with review triggers and communication priorities.
Employee training delivery, technical configuration and ongoing policy management can be scoped separately where needed.
A policy needs to reflect what your organisation can approve, enforce and monitor. The work connects AI rules with existing security, information governance and operational processes.
Connect AI guidance with acceptable use, data classification, access management and supplier review, reducing conflicting instructions and unnecessary duplication.
Highlight where permissions, approved tool settings or reporting processes need attention so employees have the means to follow the agreed rules.
Connect employee guidance with management responsibilities so approvals, exceptions and concerns reach people who can act on them.
AI Policy Development gives your people the rules for everyday use. AI Risk Assessment helps establish which exposures those rules need to address, while AI Governance provides the wider responsibilities and oversight.
For organisations pursuing ISO 42001, policy development can contribute to the broader management system. Certification readiness involves additional work beyond the policy itself.
The initial discussion establishes what you already have, where guidance is missing and what a useful policy package needs to include.
Yes. We can review existing documents for gaps, unclear language and practical usability, then agree whether a targeted update or a more substantial revision is appropriate.
Yes. The policy can focus on how employees use third party tools, including approved accounts, information handling, output checks and requests for new uses. You do not need to develop your own AI systems.
Not necessarily. A shared policy can establish the core rules, with role specific guidance where tasks, data or decision responsibilities differ. We agree the simplest structure that covers those differences clearly.
We use plain language, clear decision routes and examples based on real work. Scenario reviews help reveal missing information or ambiguous rules before the policy is prepared for rollout.
The engagement can include supporting guidance and rollout planning. Training delivery, changes to tool settings and ongoing management are separately agreed so responsibilities and deliverables are clear.
This depends on your AI use, existing documentation, stakeholder availability and the scope of the policy package. The proposal sets out deliverables, timing and cost before work begins.
Tell us how your teams use AI and where the rules are missing or unclear. We’ll help define a policy package that fits your organisation and the decisions your people need to make.
Bring your existing policy or start with the questions your teams are asking.