25 May 2026 · 7 min · By Jordan Foord
The one-page AI policy your business needs before any pilot
A policy nobody reads protects nobody. Here's the one page that does the job, template included.
Somewhere right now, a 38-page AI governance framework is being finalised. It has a RACI matrix, a maturity model, and a glossary. It will be approved at a steering meeting, filed on the intranet, and read in full by exactly one person: its author.
Meanwhile, in the same company, someone in finance is pasting customer data into a free chatbot, because no one told them not to in a sentence short enough to remember.
This is the governance gap as it actually exists in small and mid-sized businesses. Not an absence of frameworks, an absence of rules anyone can hold in their head. Our argument: before any pilot, you need an AI policy that fits on one page. Not as a stopgap until the real policy arrives. As the real policy.
Why governance keeps failing in the same direction
Two numbers frame the problem from opposite ends.
Gartner forecast in June 2025 that over 40% of agentic AI projects will be cancelled by the end of 2027, driven by escalating costs, unclear business value, and inadequate risk controls. Note that last one: a large share of cancellations trace to risk and control problems, not technology problems. Projects get killed because nobody can answer “what happens when this goes wrong?” to a board’s satisfaction.
From the other end, BCG found that 32% of companies don’t define or measure AI value KPIs at all. So a third of companies couldn’t tell you what their AI is for, and a wave of projects is heading for cancellation partly because nobody bounded what it’s allowed to do.
Both failures have the same root: the rules either don’t exist or exist in a form nobody operates by. A 40-page framework fails the second way, which is more expensive than the first, because it comes with false confidence.
Why one page beats forty
A policy works when every employee can recall it under mild pressure: when the customer is waiting and the shortcut is tempting. That gives you a hard budget: one page.
One page forces real decisions. You cannot hedge in one page. You must actually decide whether AI can touch customer data, who approves exceptions, and what gets measured. Forty pages let you defer every hard call into a sub-committee; one page is a list of commitments.
One page also gets updated. AI capability shifts quarterly; a document that takes a quarter to revise is permanently out of date. A page can be re-reviewed in a thirty-minute meeting, which is why the template below has a review date built in.
The honest limitation, stated plainly: one page is not sufficient forever. If you’re in a regulated industry, handling health or financial data at scale, or deploying agents that act autonomously, you will eventually need more: data-protection specifics, vendor assessment, audit trails. But “eventually need more” is not an argument for starting with forty pages nobody reads. Start with the page. Add weight only where reality demands it.
The one-page template
Copy this, argue about it for an hour with whoever owns the risk, fill it in, and put a name and a date on it.
[Company] AI Policy, v1.0, [Date]
1. What AI may touch. AI tools may be used for: [e.g. drafting internal documents and customer communications for human review; summarising meetings and research; analysing our own operational data; writing and reviewing code]. Approved tools: [list them: three to five, named]. Anything not listed needs approval under section 4.
2. What AI may never touch. AI tools must never be given: [e.g. customer personal data in unapproved tools; payroll, banking or credentials; legal or HR matters concerning identifiable individuals; anything covered by an NDA]. No AI output goes to a customer, supplier, regulator or bank without human review. No exceptions.
3. Human-in-the-loop rules. Every AI-assisted output has a named human owner who reviews it before it leaves the company and is accountable for it as if they wrote it. “The AI did it” is not a sentence that exists here. Agents and automations may act autonomously only on internal steps; any external action requires explicit human approval.
4. Exceptions. Want to use a new tool or cross a line above? Ask [named person: owner, ops lead, or whoever holds risk]. Decision within [48 hours], recorded in [one shared doc]. Approved exceptions become policy updates at the next review, so the page stays true.
5. Measurement. Every AI tool or agent we run has: an owner (name), a purpose (one sentence), and a number (the metric it should move: hours saved, response time, error rate, days to close). Reviewed [monthly]. Anything with no owner, no purpose or no number gets switched off.
6. Review date. This policy is reviewed every [quarter] by [name]. Next review: [date]. Expired policy is treated as missing policy.
Six sections. Genuinely one page. The deciding hour matters more than the wording, particularly section 2, where you’ll discover the disagreements you didn’t know you had.
The rule we’d argue hardest for
If you keep only one line, keep this one: no unsupervised external actions.
It’s our own operating posture. We run our company on an agent fleet (finance close, onboarding, support triage, marketing production) and the standing rule across all of it is zero unsupervised external actions. Nothing reaches a customer, a bank, or a regulator without a human approving it. Internally, agents run with real autonomy; at the boundary of the company, a human signs.
This costs us supervision time daily, and it has paid for itself repeatedly: stale brand assets caught before a customer mailing, edge-case triage decisions corrected before a reply went out. Errors caught at review cost minutes. The same errors in a customer’s inbox cost trust, and occasionally lawyers.
It’s also, not incidentally, the strongest answer to the Gartner cancellation statistic. Projects die when leadership can’t bound the downside. “Every external action passes a human” is a downside bound a board can understand in one sentence, which makes it easier to approve pilots, not just police them. Good governance is an accelerant wearing a hi-vis vest.
What this policy won’t do
In the interest of not overselling a single sheet of paper: it won’t make anyone use AI well: that’s training and workflow design. It won’t satisfy an enterprise procurement questionnaire on its own. And it won’t enforce itself; section 5’s monthly review is the enforcement, and if you skip it, you own a nicely formatted dead letter: the one-page edition of the forty-page problem.
What it will do is close the gap where most SMB AI risk actually lives: well-meaning people improvising with no rules, and pilots launching with no owner, no number, and no boundary.
Do this next week
Block one hour with whoever owns risk in your business. In a small company, that’s probably you and one other person. Bring the template above. Fill in all six sections, with real names and real dates, and resist the urge to add a seventh.
Then send it to everyone with a one-line covering note: “This is how we use AI here. One page. Read it.” Total elapsed time, under a week. Total cost, one meeting. It will do more for your AI risk than any framework you were never going to finish, and it clears the runway for the pilots actually worth running.