Most Chiefs of Staff run without a written AI use policy. The team is already using AI every day; the exposure is real, and the policy keeps sliding down the list because nobody handed you a template.
An AI use policy doesn't need to be long. One page, 5 sections, and you have something your executive will actually sign. Here's what goes in each.
The 5 sections of a one-page AI use policy
1. What AI is approved for. Name the tools and the tasks that are cleared. A short allow-list beats "use good judgment," because it tells your team where the edges are.
2. What data can go in, and what can't. The line that protects you. Client details, financials, anything personal, and anything under NDA stay out of tools that train on their inputs. Say it plainly.
3. Who checks the output. AI drafts; a person owns. Name the review step for anything that leaves the building or carries your executive's name.
4. When to disclose AI use. Decide where a note is expected, like external content or board material, and where it isn't. A team that knows the rule doesn't have to guess.
5. What's off-limits. The short list of uses you won't allow, whatever the upside. Hiring calls, legal interpretation, anything that needs a licensed professional.
Before AI touches your executive's work, my free AI Content Checklist covers the 3 questions to answer first. And if you're still making the case for any of this, here's why AI governance is a Chief of Staff job now.
The template
You can build this from the 5 headings above. If you'd rather start from something grounded and fillable, that's what the AI Use Policy Template is for: the same 5 sections, written against the NIST AI Risk Management Framework, with real examples and language you can drop in. It's a member resource.
Members get the full template.
P.S. The ideas, frameworks, and words in this piece are my own. I used AI to assist with design and file production.

