← Research
Research

How do you write an AI use policy that works?

Most policies prohibit what cannot be detected and record decorative verification as a control.

Last reviewed: 26 August 2026

Why the standard policy fails, six elements that survive every model release, what EU law now makes auditable, and the test that tells you whether it changes anything.

Most AI use policies are unenforceable, and everyone involved knows it. They prohibit things nobody can detect, require approvals nobody seeks, and are written by people who will never do the work they govern. Their real function is to establish that a document exists, which is a legitimate purpose and should be named rather than dressed up as governance.

An enforceable policy looks different. It is shorter.

Why the standard policy fails

It prohibits what cannot be observed. Detection does not work reliably, and a rule with no detection mechanism is a statement of preference. The University of Sydney says this openly in its own guidance: an unsecured no-AI condition is a temporary measure because it cannot be enforced. Most organisations have not reached that honesty yet.

It governs tools rather than decisions. Tool lists date within months. The decisions that matter, what may be delegated, who verifies, who is accountable, do not change when the vendor does.

It has no stated consequence. A rule without a consequence is guidance, and staff read it correctly as such.

It assumes the reviewer can review. Almost every policy requires human review of AI-assisted output without asking whether the named reviewer could detect an error. Where they could not, the control is decorative and the policy has recorded it as satisfied.

Six things an enforceable policy contains

1 · Consequence tiers, not tool categories. Classify work by what happens if the output is wrong, from trivially reversible to irreversible or externally consequential. Rules attach to tiers. This survives every model release.

2 · A named accountable person per tier. A person, not a function, identified before the work rather than after an outcome. The Delegation Boundary Map makes the gaps visible in about ninety minutes.

3 · A verification requirement that passes the capability test. For each tier, who checks, and could that person detect the error? If not, say so and either move the work down a tier or accept the exposure explicitly. Recording decorative verification as a control is the single most dangerous line in most policies.

4 · A written override rule. On what grounds may someone disregard the system, and on what grounds must they defer? Unspecified, it collapses into whoever is more confident. See when should I override AI.

5 · Disclosure rules by audience. What must be disclosed to clients, to regulators, internally. Vague or absent, people guess, and they guess differently.

6 · What the organisation will keep doing itself, and why. The clause almost no policy contains. Which capabilities are being maintained deliberately, and what practice protects them. Without it, a policy governs usage while capability erodes underneath it, which is capability debt with a compliance document on top.

What the law now requires

In the European Union this stopped being discretionary. Article 4 of the EU AI Act has required a sufficient level of AI literacy since February 2025, at every risk tier, with enforcement from August 2026. Article 14 requires that people overseeing high-risk systems can detect anomalies, remain aware of automation bias, interpret output correctly, and disregard or stop the system.

Read together, they make capability claims auditable. A policy asserting human review, supported only by a completion rate and a seat count, is not evidence that any of those five conditions are met. This is not legal advice, and organisations should take their own.

No study has compared policy designs

No study has compared policy designs for effectiveness. The six elements are constructed from the evidence on oversight failure and from practitioner research, not validated as a framework. There is no case law and no guidance yet defining what sufficient means under either Article. Treat this as a reasoned structure rather than a compliance guarantee.

The test

Give the draft to three people who actually do the work and ask one question: what would you do differently on Monday? If the answer is nothing, the policy is documentation rather than governance. That takes an afternoon and is more informative than legal review, which tests whether the document is defensible rather than whether it changes anything.

Related SuperSkills research

On the practical tool, the Delegation Boundary Map. On the legal duties, meaningful human oversight and AI literacy for leaders. On accountability, who owns verification. On the board test, what should a board ask about AI.

Key sources

About this research

Rahim Hirji is the author of SuperSkills (Kogan Page, 2026) and founder of The SuperSkills Intelligence Company. The six elements are a constructed framework rather than a validated one, which the page states. Not legal advice. Free to use and adapt with attribution. Reviewed quarterly.

Cite this

Hirji, R. (2026). How do you write an AI use policy that works? The SuperSkills Intelligence Company. Last reviewed 26 August 2026. thesuperskills.com/research/how-do-you-write-an-ai-use-policy-that-works

In this hub

AI and Human Judgement

Does AI weaken judgement? The evidence, and what to do about it.

The work

Where the writing comes from.

These essays draw on research across more than 200 organisations in 30 countries. See the wider body of work, or bring it into your organisation.

All research →