Here is a fact worth sitting with: your employees are already using AI at work. Surveys keep putting unsanctioned "shadow AI" use above half of employees, and in practice, if your company has quoted a job, answered a customer email, or written a job posting this quarter, some of it probably touched a chatbot. The only question is whether that happens inside rules you wrote or in the dark.

That is the case for an AI policy, and it is also the argument against the wrong kind: a ten-page prohibition nobody reads is not governance, it is liability theater. The goal is one page people can actually follow.

What the one page needs to cover

1. What is allowed, by name. Approve specific tools for specific uses: drafting internal documents, summarizing meetings, first-pass research, code assistance, whatever fits your business. A policy that only forbids pushes usage underground; a policy that approves gives people a legal route, which is what actually kills shadow use.

2. What never goes in, period. The bright line, in plain words: customer data, employee personal information, pricing and contract terms, financials, anything covered by an NDA. Employees remember one test. If you would not paste it into a public website, do not paste it into a chatbot. Paid business tiers with data-training turned off widen what is safe internally, but the customer-data line should stay bright.

3. A human owns every output. AI drafts; a named person ships. Whoever sends the proposal, posts the content, or books the journal entry owns it exactly as if they wrote it. "The AI got it wrong" is not a defense you want normalized, and this single rule prevents most of the quality and accuracy risk.

4. Where the stakes are too high for drafts. Anything legal, anything safety-related, anything going to a regulator, final financial statements. These get the old-fashioned process, full stop.

5. Who to ask. One named person or channel for "can I use this tool for this?" Governance that answers in a day beats governance that schedules a committee.

Why this belongs on the CFO's desk

The risks a policy manages are financial risks wearing a technology costume: confidential data in a vendor's training set is a customer-trust and legal exposure; an unreviewed AI-drafted quote with the wrong price is a margin leak; a proliferation of $30-a-month subscriptions across the company is spend nobody approved. The same discipline that governs whether AI spend pays at all should govern how it is used.

And the buyer angle, because there always is one: diligence teams have started asking mid-market targets about AI usage and data handling. "Here is our one-page policy, here is the approved-tool list, here is who owns it" is becoming one more boring answer that protects value.

Rolling it out without the eye-rolls

Announce it as permission, not prohibition: here is what you can now officially do, here is the short list of what you cannot, here is who to ask. One page, one meeting, one owner, reviewed twice a year. Building exactly this, along with the approved-tool assessment behind it, is part of our AI advisory work, and the free AI-Readiness Scorecard will tell you in two minutes whether governance is one of your gaps.

The companies getting real returns from AI are not the ones with the strictest rules. They are the ones whose rules are clear enough to say yes quickly and safely.