
Operate
Responsible AI policy
A policy people can actually follow: what is allowed, with which data, under what supervision, and what to do when it goes wrong — written for your organisation rather than adapted from a template describing somebody else's.
Duration
3–5 weeks
Built on
ISO/IEC 42001 · EU AI Act · NIST AI RMF · OECD AI Principles
Indicative price
€8,500–19,000 per engagement
Who this is for
General counsel or compliance officer
Owns the policy and knows the current one is not being followed.
CEO or owner
Wants a position that is defensible to a client and honest internally.
HR director
Is fielding questions about what staff may and may not use.
CISO
Needs data rules that map to the classification scheme already in place.
A policy nobody can follow is a policy nobody follows
Most AI policies fail in one of two ways. Either they prohibit so broadly that complying would stop work — so people quietly do not comply. Or they state principles, fair and transparent and human-centred, that nobody can act on. Both produce the same outcome: usage continues unrecorded, and the policy exists for auditors rather than for staff.
A useful policy answers operational questions. May I paste a client's document into a model. Which tools are approved for which classes of data. What has to be disclosed to a client, a candidate or a patient. Who approves a new use, and how long that takes. What happens when an output turns out to be wrong and somebody had already acted on it.
Approval matters more than prohibition. A policy that bans everything without a route to permission produces shadow usage, which is strictly worse than the usage it prevented — the same risk, with no visibility and no record. Every restriction we write comes with a way to ask.
It also has to describe the company you actually are. A policy promising human review of every output, in an organisation without the staff to do it, will be breached in the second week — and a breached policy teaches people that the rest of it is optional too.
Finally it has to survive its own authorship: a named owner, a review cadence, a change log, and a route for people to ask questions without having to confess first.
How we do it
- 01
Current practice and appetite
1 week
What is actually being used, by whom, on what data — and what leadership is genuinely prepared to permit. The gap between those two is the policy's real subject.
- 02
Principles into rules
3–5 days
Your principles translated into statements a person can act on, each one testable: could an employee read this and know whether what they are about to do is allowed.
- 03
Data classes and permitted use
1 week
Mapped onto the classification scheme you already have rather than a new one. Which tools, for which classes, under what conditions.
- 04
Approval and exception route
3 days
How a new use gets approved, who decides, how long it takes, and how exceptions are recorded. A slow route is a route nobody uses.
- 05
Disclosure and incident handling
3–5 days
What you tell clients, candidates and regulators, and what happens when an output is wrong and has been acted on. Named roles, not a mailbox.
- 06
Rollout and comprehension
1 week
Briefings by role, a short comprehension check, and the record of both — which is also part of your AI literacy evidence.
Named artefacts
What you receive
- AI use policy in plain language, readable in ten minutes
- Data classification mapped to permitted tools and uses
- Approved tool list, with the route to approve a new one
- Role-based one-pagers — what this means for you
- Approval and exception process, with an exception register
- Disclosure guidance for clients, candidates and regulators
- Incident procedure for outputs that turn out to be wrong
- Manager guidance, including what to do about unsanctioned use already happening
- Named owner, review cadence and change log
- Rollout briefings and comprehension check records
What we need from you
- A leadership decision on appetite. We can shape it, but a policy written without a real position drifts back to prohibition.
- Your existing data classification, if you have one. If you do not, we will use a simple scheme rather than build one you will not maintain.
- Honesty about current unsanctioned use. Policy written against an imagined baseline fails at contact.
- A named owner, in post before the policy is published.
What changes
- 01Staff can tell whether what they are about to do is allowed, without asking.
- 02New uses have a route to approval that is quick enough to use.
- 03Unsanctioned use becomes visible because there is now a better option than hiding it.
- 04Client and candidate disclosure is consistent and decided in advance.
- 05The policy has an owner, a cadence and a record of who was briefed.
What it costs
€8,500–19,000 per engagement
All prices exclude VAT.
Questions
Can you just send us a template?
We could, and it would be the policy you already have. The value is in the decisions — appetite, data classes, approval route, disclosure — and those are yours. What we bring is the structure and the questions, not the paragraphs.
How is this different from an acceptable use policy?
Acceptable use covers behaviour with IT assets. This covers a class of system that produces content, influences decisions and affects people outside the organisation, and it has to answer disclosure and incident questions an AUP does not contemplate. Where you have an AUP we extend it rather than compete with it.
Leadership wants to ban AI outright. Is that a position you will write?
We will write it, and we will tell you what it produces — which is unrecorded use on personal accounts and devices, with your data in it and no visibility. If the appetite is genuinely zero, the policy needs enforcement and monitoring to match, and that has a cost we will set out.
Does this satisfy the EU AI Act?
It is part of it. Policy is one component; the Act also requires inventory, role and risk determination, and the literacy obligation. The EU AI Act readiness engagement establishes what you owe, and this delivers the policy piece of it.
Who should own it?
Someone senior enough to approve exceptions and close enough to the work to be asked. Compliance and legal are the usual homes; IT alone tends not to work, because most of the difficult questions are about disclosure and judgment rather than technology.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.