Where to Start With AI? Write a Personal-Use Policy First
Most teams don't know where to start with AI. The best first step involves no new tools: a personal-use policy for shadow AI. Here's what to include.
With everything surrounding AI today, the commonly believed starting point is to find a tool or use case that AI can be applied to. It can be overwhelming and feel like a completely impossible task to accomplish, but there is a better jumping off point: writing a policy for the AI that is already present. It is a $0 investment and helps provide guidance around a major risk.
Employees are already using personal AI models at work. But as companies wait to figure out which tool to adopt, this usage remains completely unrestricted. You don't need an enterprise-wide tool to provide guidance.
Key Takeaways
- Your employees are almost certainly already using personal AI tools for work. This is called shadow AI, and it is happening in most companies right now.
- A policy is the cheapest and fastest first step in AI. It requires no procurement, no engineering, and no big transformation.
- A policy should give people a safe, sanctioned path so they stop routing around the company. Banning AI outright does not work and is not the point.
- A good policy is unambiguous, answers the questions people already have, and names one person to ask.
- Six things every personal-use policy should cover: defined terms, a data rule, human oversight, ethical and legal compliance, an unapproved-tools rule, and a point of contact.
Your employees are already using AI at work. It's called shadow AI.
Shadow AI is the use of personal, unapproved AI tools for work, without sign-off from IT or leadership. Someone pastes a client email into a free chatbot to rewrite it, or an analyst runs numbers through a tool the company never vetted. Either way, it is unmonitored and unrestricted.
The scale is larger than most leaders assume. In Microsoft and LinkedIn's 2024 Work Trend Index, 75% of workers said they use AI at work, and 78% of them are bringing their own tools rather than using anything the company provided. That figure is even higher at small and medium-sized businesses.
The bigger issue is that people are using these tools without asking for any guidance first.
Why your first AI step should be a policy, not a tool
When a company decides to get serious about AI, the assumption is that the first step is technology. The more useful first step is governing the AI that is already in the building.
A policy needs no budget, so no one has to defend a line item, and no engineering, so nothing sits in a backlog. One person can draft it and circulate it without waiting on permission from several layers of management.
It also does real work. The cost of not having one is well documented. IBM's 2025 Cost of a Data Breach Report found that breaches involving shadow AI carried roughly $670,000 in added cost, and that most organizations still lack an AI governance policy or are only now developing one. KPMG's 2025 research on shadow AI reported that only 41% of employees say their organization has any policy guiding generative AI use at all.
There is a strategic point here too. A policy is the wedge that helps build a clean foundation for AI adoption going forward. Once you can see how people are actually using AI, and once usage is happening in the open, you have the information you need to pick real tools and make a real plan.
What makes an AI policy actually good?
A policy people ignore is worse than no policy. It creates the appearance of a guardrail while usage keeps moving further into the dark. The difference between a policy that changes behavior and one that gets skimmed and forgotten comes down to a handful of traits.
It lacks ambiguity. No hedging, and no "use good judgment" standing in for an actual rule. Every line should hold up when read by someone looking for a loophole. Vague policies get interpreted in whatever way is most convenient in the moment, which is the same as having no rule.
It answers the questions people are already asking. "Can I paste this into ChatGPT?" "Do I have to tell the client I used AI?" "Which tools are okay?" If your team is already wondering it, the policy should already answer it, not send them to go ask someone or guess.
It enables more than it forbids. A wall of "don'ts" reads as a ban, and people route around bans. Software AG's research found that 46% of workers said they would refuse to give up their personal AI tools even if their company banned them outright. A policy works better when the safe path is also the easy one.
It is short enough to be read. A one-page document people finish does more than a thirty-page document nobody opens. Length tends to signal legal caution more than clarity, and a page people finish changes behavior more than a chapter they skip.
It is written in plain language. Concrete words over jargon. If someone needs a glossary to follow the policy, they will stop following it.
It has an owner. A living document with a name attached, not a file that goes stale the week after it is published.
What to put in your AI policy: 6 must-haves
Once you know what "good" looks like, here are six items you should include.
- Clearly defined terms. Don't assume everyone means the same thing by "AI." Define the terms you use, including model, prompt, public versus enterprise tool, and PII, up front, so the rest of the policy can't be misread. Misconceptions are where bad decisions start.
- Keep company data out of public tools. This is the most important line in the policy, so leave no room for interpretation. No client data, no PII, nothing under an NDA, and no financials go into public AI tools. Approved, secure tools are a different matter, and that is what an enterprise rollout is for. This is not a hypothetical risk. In 2023, Samsung restricted employee use of ChatGPT after engineers pasted confidential source code and internal notes into it, and that information left the company's control the moment it was entered.
- Human oversight. AI states wrong things with total confidence, and the liability lands on the person, not the tool. Every output gets verified by a human before it is used, shared, or shipped. That means facts, numbers, quotes, and code checked against a real source.
- Ethical and legal compliance. When people use AI on their own, they are not thinking about company policy, so spell out what they have to follow. Cover the ethical line, the legal requirements, and exactly when and how AI use must be disclosed in client work and deliverables.
- Unapproved tools, and a default-deny rule. Name the tools that are off-limits under any circumstance. Then close the gap a ban leaves open: anything not explicitly cleared has to be approved before use. A blocklist on its own permits every tool you didn't think to name, and a new one launches every week.
- Who to ask. Give people one named person or channel that owns the policy, answers questions, and fields requests for new tools. A "no" with no outlet is what sends people back to shadow AI in the first place. The request path is the pressure-release valve that makes the rest of the policy hold.
How to put a policy in place without slowing anyone down
Keep it to one page to start. A short document that people actually read and follow does more than a long one that sits unread in a shared drive. You can add detail later, once you see which questions keep coming up.
Communicate it as something that helps people, rather than a crackdown. The framing matters. People who feel policed go quiet and keep using their own tools anyway, which is the exact outcome you are trying to avoid. People who feel supported bring their usage into the open, and that visibility is the whole point.
Make the request path frictionless. If asking to use a new tool takes a week and three emails, people will skip it. If it takes a message to one channel and a same-week answer, they will use it. The easier the sanctioned path, the less shadow AI you have.
Then treat the policy as a first step. Once usage is in the open and you can see what people actually reach for, you have what you need to choose secure tools and build a real plan. That is the point where a small, ownable first move turns into something you can scale across the organization.
AI personal-use policy FAQs
What is shadow AI?
Shadow AI is the use of personal or unapproved AI tools for work without the knowledge or sign-off of IT or leadership. It ranges from drafting emails in a free chatbot to running company data through a tool no one vetted. The defining trait is that it happens outside any official oversight.
Do we really need an AI policy if we haven't adopted any AI tools?
Yes, and arguably more so. When a company has no tools of its own, employees use their own instead, without any guidance on what data is safe to enter or what has to be checked. A policy is worth writing precisely because the company tools are not there yet.
What should a personal AI use policy include?
At a minimum: clearly defined terms, a firm rule against putting company or client data into public tools, a human-oversight requirement, ethical and legal compliance including disclosure, a rule for unapproved tools with a default-deny default, and one named person or channel to ask.
Can employees use ChatGPT or other public tools at work?
That is for your policy to decide, but the common approach is to allow general use while drawing a hard line at sensitive data. No client information, PII, NDA-covered material, or financials in public tools. Approved, secure tools can be handled separately through a proper rollout.
Who should own the AI policy?
Assign one named person or channel with a clear point of contact. Whoever owns it answers questions, reviews requests for new tools, and keeps the document current. When ownership is vague, the policy goes stale and people go back to figuring it out on their own.