What if legal wants a longer, stricter AI policy?
A longer policy no one reads protects no one. The one-page version is not lax; it is the enforceable one.
Take the question seriously, then push back on the premise. A longer, stricter policy that no one reads or can follow does not protect you. It protects the person who wrote it. The one-page version is not lax. It is the only kind that gets followed, which is what protection means.
Give legal the two things that carry all the weight. First, data sensitivity decides the environment: confidential information goes only into contracted, enterprise-secure tools you have approved, and everything else is fair game. Second, accountability is total and human: there is no AI work product, only AI-assisted human work product, and the author of record owns all of it.
If legal wants more, add specifics for the few genuinely high-stakes cases, regulatory, clinical, legal, and stop there. Every clause past a page trades real adoption for the feeling of coverage.
Take the one-page version and adapt it: A Lightweight AI Use Policy.
Cheers,
-Titus
Get it in your inbox.
New Issues, FAQs, and Case Studies as they go out. Each one names something, explains something, or hands you something you can use on Monday. Subscribe, and I will send each as it goes out.
Prefer the tool you already think in? Here is how to read it in your chatbot.