Guide
What belongs in an AI use policy
A one-pager is a start. Diligence asks for pages 2–5.
Why the Google template fails
Most public “AI policy” templates are acceptable-use paragraphs from 2019–2023. They do not name data that never goes in a prompt, do not have an incident path, do not ask vendors anything, and do not attest who was trained. SOC 2 and investor diligence now poke all four.
CASF M0 gets you the one-pager in 90 minutes. Auditors still ask for the rest.
The five pages that get opened
Acceptable use: who may use which tool for which work. Data that never goes in a prompt: source code, customer PII, credentials, unreleased numbers — the Samsung-leak class. Incident report: what to do after a leak, not a slogan. Vendor questionnaire: what you ask a model or AI-feature SaaS vendor. Training attestation: names and dates, not a Slack emoji.
Align language with EU AI Act transparency and NIST RMF so the same packet can travel. You still need counsel for a fight; you do not need counsel to start the draft.
Get the training, not another blank Doc
AI Policy Writer (IN BUILD Q4 2026) is the course that ships those five pages. Join the waitlist if you already have M0 and a reviewer asked for more. If you have nothing, start in the CASF classroom.
Next: AI Policy Writer · All guides