Thinking

An AI policy is permission, not implementation

A good AI policy creates permission and boundaries. It becomes useful only when people can recognise the decisions in front of them and apply it in everyday work.

Published

Policy should enable useful work

Organisations often approach AI policy as a defensive exercise. Boundaries matter, but a useful policy should also give people confidence to use approved AI appropriately.

It should help people answer everyday questions:

  • Can I use AI for this?
  • Which tools and information are permitted?
  • When do I need approval?
  • What must I check?
  • Who remains responsible?

Publishing a document does not change behaviour

A policy can be legally reviewed, approved and published while remaining invisible in everyday work. Formal approval is necessary, but it does not by itself change what people do.

People need to recognise when the policy applies, find the answer they need and understand what action to take. Otherwise, rules are likely to be remembered too late, interpreted differently or worked around altogether.

Translate rules into real decisions

AI policy implementation connects broad rules to the work people actually do: research and exploration, drafting and editing, customer communications, analysis, internal support, content and design tools, decision support, and higher-impact or sensitive work.

Plain-English guidance helps people understand whether a use is routine, when an extra check is needed and when they should stop and ask. That is how AI governance becomes part of responsible AI practice rather than a document stored elsewhere.

Define the approved starting point

Implementation is easier when people can quickly find a clear starting point:

  • Approved tools
  • Permitted and prohibited information
  • Named owners
  • Human review requirements
  • Escalation routes
  • Evidence worth retaining

These details turn permission into something people can use with confidence.

Human review must mean something

Human in the loop is too vague on its own. A reviewer should understand why review is required, what they must check, what authority they have, what approval means and when they should stop or escalate.

A meaningful review is more than seeing an output before it is used. It gives a person the context, time and authority to challenge, change, reject or escalate the work. The Human review and approval guidance sets out a practical framework for doing this.

Implementation needs organisational context

Policy and controls must be connected to business ambition, customer and employee needs, brand behaviour, products and services, accessibility expectations and organisational responsibilities.

A policy creates the boundaries. Organisational context helps people and AI systems make useful decisions within them.

Learn from actual use

AI policy implementation should be reviewed through the questions people ask, mistakes and near misses, examples of useful work, changes to tools and provider terms, customer or employee feedback, and evidence about accessibility and understanding.

The policy should evolve through controlled versioning rather than informal drift. Learning from actual use keeps permission, boundaries and review connected to the work they are meant to guide.

How the Foundation resources work together

Foundation by FabUX provides a practical sequence for moving from policy to practice:

  1. Set the rules: AI Use Policy
  2. Put them into practice: Implementation playbook
  3. Check work before it matters: Human review and approval
  4. Protect information and rights: Privacy and intellectual property

The resources work together, but can also be used individually where that is the right starting point.

Useful AI policy implementation makes the right next decision easier to recognise and act on.