LearnAI in Business Operations

From one working step to the whole team: an AI usage policy

AI in Business Operations2026-08-20

The previous lesson ended with three decisions after measuring: expand, adjust, or stop. This lesson is about the first one. When the numbers show that an AI step is worth keeping, the natural instinct is to roll it out fast: tell the other departments to use the same tool and let them get on with it. That rule-free rollout is the most common way a good result gets ruined: what worked for one person who understood the limits of the task becomes ten different methods, with company data leaving the building unnoticed and quality nobody owns.

Why copying the experiment is not enough

Your trial was protected by three things you never wrote down: a person who knew when not to trust the output, a task with clear boundaries, and a review that happened automatically because whoever ran it cared. Expansion removes all three at once. The new employee does not know which tasks are suitable, which data may be pasted, or who checks the work before it reaches the customer. The result is rarely a loud failure but a quiet decline: uneven output, errors that surface late, and eroding trust.

The bigger risk is undeclared use: with no written policy people do not stop using AI tools, they use them quietly, each picking their own. You then lose the two things that matter most: knowing where your data goes, and the ability to improve what you cannot see.

One page is enough

A usage policy is not a long legal document. One page read in five minutes beats twenty pages nobody opens. It answers six questions:

ItemWhat to write
Approved toolsNamed tools allowed for work; anything else needs approval
Permitted dataWhat may and may not be pasted, in plain non-technical wording
Covered tasksThe tasks you actually trialled and measured, not everything
Human reviewWho checks before work reaches the customer, and whether sign-off is required
DisclosureWhen a customer or authority is told that AI assisted the output
OwnerOne named person who answers questions and keeps the page current

The data item is the heaviest, and an earlier lesson covered it in detail. The practical rule: personal data of customers and employees falls under the Personal Data Protection Law issued by the Saudi Data and AI Authority (SDAIA), and responsibility for it stays with your company even when the tool belongs to someone else. If you are unsure about a specific case, make refusal the default and add exceptions you have verified, not the other way round.

A shared instruction library, not individual guesswork

The lesson on writing clear instructions showed that wording makes the difference. When you expand, do not ask every employee to rediscover it alone. Keep a shared file with the instructions that actually worked for each approved task, written exactly as used, with an example of an acceptable output. That file is the difference between a team reproducing a reliable result and one re-inventing the route every morning, and an instruction that needs changing changes in one place instead of ten people's heads.

A worked example

A small contracting firm trialled AI on one task: drafting the technical proposal sent to a client. After a month of measurement, drafting time had dropped and first-pass acceptance had not fallen, so it decided to expand. The wrong way is a message telling everyone to use the tool for everything. The right way is one policy page naming the approved tool, forbidding customers' personal data and signed contract clauses from being pasted, limiting use to proposal drafts and first replies, and requiring the project engineer to review each draft before it goes out, followed by a half-hour session led by whoever ran the trial. A second task is added only after the first is measured again in its new setting.

Checklist before expanding

  • Is the policy one page an employee will genuinely read?
  • Are the approved tools named explicitly?
  • Is the data section written in language a non-technical person understands?
  • Does every approved task have a reviewer identified by name or role?
  • Does the shared instruction library exist before the rollout, not after it?
  • Is there one owner who answers questions and updates the policy?
  • Is the expansion one additional task, rather than every task at once?
A good policy does not prevent use, it prevents silent use: employees know what is allowed instead of guessing, and you know where your data goes.
Summary: do not generalise a successful trial without rules. Write one page covering approved tools, permitted data, covered tasks, human review, disclosure and a single owner. Collect the instructions that worked into a shared library, train the team in one short session led by whoever ran the trial, then expand one task at a time and measure before adding the next.