An AI policy template allows organisations to uphold the AI governance principle of Transparency. When customised, it communicates to the outside world how your organisation uses AI, which data is involved, and what safeguards are in place. This is different from a national AI policy framework. For example, the South African National AI policy outlines how a country plans to govern AI to advance its national interests.

AI Policy Templates are not one-size-fits-all

Organisations can use AI policy templates as a helpful starting point, but they must customise them. Your AI policy should clearly outline to customers and stakeholders how you use AI to deliver a service or product, and how you manage the risks AI poses to them. Just like how your privacy policy communicates what data you collect, why, and your users’ rights. The better the AI policy fits your organisation’s AI practices, the more effective it will be in shielding you from liability.

Your AI governance officer is responsible for setting your AI policy, and in smaller organisations, the AI governance officer is the same person who serves as the DPO or IO. However, in larger companies, the CEDPO recommends separating these roles. By joining our AI governance programme, your teams will be empowered to leverage existing governance structures to innovate confidently while maintaining compliance with evolving regulatory expectations.

An AI policy template must be customised to reflect your organisation’s structure and role in the AI value chain.

How should you customise an AI Policy Template?

Effective AI governance requires a holistic approach that aligns the AI policy with information security, risk management, data protection, and broader compliance structures. Integrating your AI policy into existing governance reduces duplication and ensures consistent oversight. It may be helpful to incorporate some of your other policies by reference, if you use a modular structure as we do. For example, where AI processes personal information, you can direct your customers to your privacy policy so you do not have to duplicate what is already there. When customising an AI policy template, it is importsnt to align it with your exisiting poicies and also consider aligning it with established international frameworks such as:

  • ISO/IEC 42001:2023 (AI Management System Standard)
  • NIST AI Risk Management Framework
  • OECD AI Principles
  • Microsoft also provides detailed guidelines for implementing AI policies and standards responsibly.

Aligning your AI policy with international standards helps you build governance that is scalable across jurisdictions and recognisable in global markets.

What type of AI Policy Template should you use?

Quite a few AI policy templates are floating around online. But not all templates are equal, as some are more equal than others. So when choosing a template, several factors should be considered. For example, does the organisation that has provided the template have a principle-based approach to AI governance, and does the policy use or refer to a specific legal system that does not apply to me? Since the template is the blueprint for your bespoke AI policy, it must have the foundational characteristics that align with your business reality and strategic objectives. There are some policies worth looking at, and those policies have a few things in common.

  1. The AI policy template must be written in plain language and adaptable for all organisations.
  2. A good template will provide guidance and support for implementing the practices outlined in the policy.
  3. The AI policy template must bridge ethical principles with operational implementation and be accompanied by implementation resources, such as AI glossaries, AI screening tools, and AI inventories. This will help organisations document the AI systems they deploy and classify them by risk so that resources can be prioritised.
  4. The AI policy template should align with international best practices and standards such as ISO/IEC 42001, the NIST AI RMF, and the OECD principles. This helps organisations scale across global markets without delay.

Unlike the EU, where the AI Act prescribes binding, linear rules for AI governance, surveying AI laws worldwide shows that most countries have adopted a more flexible approach to AI regulation. This means organisations will need practical tools to close AI governance gaps without disrupting internal processes. So adopting an AI policy template along these lines will help organisations adopt responsible AI without unnecessary complexity.

Using an AI policy template is a great way to start thinking about AI governcan in your organsiation.

Action steps for your organisation

To implement effective AI governance using an AI policy template, organisations should take these practical steps:

  1. Brief your governing body so they can make informed strategic decisions about AI tools to set the tone for your AI policy. Download the template for motivation for a board briefing on AI governance and attend one of our events.
  2. Establish clear accountability structures across teams and appoint responsible owners. Empower those teams to perform their duties by joining our AI governance programme.
  3. Assess current AI usage and associated risks through a gap analysis to identify areas for improvement.
  4. Leverage existing policies and frameworks in information security, data protection, and risk management. Instruct us to align these policies in plain language.
  5. Maintain a record of all AI systems, their purposes, risk levels, data sources, accountable owners, and compliance status. Join our programme for access to AI inventory templates and more.

You can download a free Michalsons’ AI Acceptable Use Policy template, written in plain language and adaptable for all organisations. This template is not a strategic policy; it’s an AI Acceptable Use Policy for your employees.