Verified against ChatGPT · 2026-08-13
Draft an internal AI governance policy scoped to how your teams are actually using AI, not a boilerplate framework
Builds a first-draft AI governance policy grounded in your organization's actual tool usage, risk tiers, and approval workflow, explicitly positioned as a starting point for legal and compliance to revise rather than a finished, enforceable policy.
The prompt
Ready to copy — highlighted parts are example details you can swap.
Draft a first-pass internal AI governance policy based on how our organization actually uses AI tools today, structured so legal and compliance have a concrete starting point to revise rather than a blank page. HOW AI IS CURRENTLY USED HERE Marketing uses ChatGPT for draft copy; engineering uses GitHub Copilot; customer support has piloted an AI chatbot for tier-1 tickets; no formal approval process exists yet. RISK AREAS WE'RE MOST CONCERNED ABOUT Concerned about customer PII being pasted into consumer AI tools, and about AI-drafted external communications going out without human review. EXISTING APPROVAL OR PROCUREMENT PROCESS, IF ANY New software generally goes through IT security review, but AI tools specifically haven't been routed through that process consistently. REGULATORY CONTEXT WE'RE AWARE OF We operate in the EU and US and are aware AI-specific regulation is an emerging area we need legal to track. STRUCTURE THE POLICY IN THESE SECTIONS Scope: state plainly what this policy covers (which tools, which use cases, which employees) based on what I've told you is actually happening, not a generic "all AI use" statement that doesn't reflect reality. Risk tiers: sort AI use cases we've described into tiers by consequence if something goes wrong (e.g. AI used for internal brainstorming vs. AI used to draft anything sent externally or make a decision about a person), and state a different approval requirement per tier rather than one blanket rule for everything. Approval workflow: describe, based on what I've told you about our existing process, who needs to approve a new AI tool or use case before it's adopted, and what information that approver needs to see. Data handling rules: state what categories of data should never be input into a general AI tool (based on what I tell you is sensitive here), phrased as a rule for employees to follow, not a restatement of a data protection law's requirements. Incident and misuse reporting: describe how an employee should report a suspected AI-related error, hallucination, or misuse, and who reviews it. WHAT NOT TO DO Do not cite a specific AI regulation, its provisions, or its compliance deadlines unless I've explicitly told you the citation and its content — regulatory frameworks in this space are new, changing quickly, and vary by jurisdiction, so state only in general terms that regulatory compliance is a consideration, and flag it as something legal needs to confirm against current law. Do not present any section of this draft as final or already-approved language — every section header should make clear this is a draft under active development, not a live policy an employee could be told to already follow. OUTPUT FORMAT A structured policy draft with the five sections above, each opening with "DRAFT —" to make its status unambiguous. End with an explicit statement that this entire document is an internal working draft only, has not been reviewed or approved by legal or compliance, must be reviewed by a qualified lawyer for accuracy against current and applicable law before any part of it is adopted, and should not be distributed to employees as an active policy until that review is complete.
Customize
Optional — swap in your own details for the highlighted parts above.
Why this works
Grounding the scope and risk tiers in the organization's actual described AI usage, rather than producing a generic 'responsible AI' template, is what makes this draft something legal can meaningfully edit instead of discard — a boilerplate governance policy pulled from common patterns will describe use cases the organization doesn't have and miss the ones it does (like an unrouted AI chatbot pilot in customer support), and a lawyer reviewing a policy that doesn't reflect reality has to do the harder job of first figuring out what's actually happening before they can even assess whether the policy addresses it. The risk-tier structure, with a different approval bar for internal brainstorming versus AI-drafted external communications or decisions about a person, matters because a single blanket rule for all AI use either over-restricts low-stakes internal experimentation (killing adoption teams actually need) or under-restricts genuinely consequential uses, and GPT-5.1 can meaningfully differentiate these tiers once given real examples of both ends of the spectrum, which a generic prompt without that input could not do credibly. The refusal to cite specific AI regulations or their provisions unless explicitly supplied is the most consequential guardrail in this prompt, because AI-specific regulatory frameworks are genuinely new and actively evolving across jurisdictions as of this writing, and a model asserting 'the law requires X' from general pattern knowledge in this exact space is more likely than in almost any other legal domain to be citing something outdated, proposed-but-not-enacted, or simply invented — the instruction to name regulatory compliance only as a consideration for legal to verify, never as a stated requirement, keeps the document honest about the limits of what an AI-generated policy draft can respons ibly assert. Opening every section with "DRAFT —" and repeating the do-not-distribute instruction is a deliberate redundancy against the specific risk that a policy document, once it exists in a shareable form, tends to get treated as final by whoever finds it first, regardless of what a single closing disclaimer says.
What you get back
DRAFT — RISK TIERS: Tier 1 (internal brainstorming, no external output) — no approval required, general awareness training sufficient. Tier 2 (AI-assisted drafting of anything sent externally, e.g. customer communications) — requires manager sign-off and human review before sending. Tier 3 (AI used to make or materially influence a decision about a person, e.g. hiring screening) — requires legal and compliance approval before any pilot begins. This entire document is an internal working draft only, not reviewed or approved by legal — a qualified lawyer must review it against current applicable law before any part of it is adopted.
Verified against
ChatGPT GPT-5.1 · 2026-08-13
Changelog
- 2026-08-13 — Initial publish, verified against ChatGPT GPT-5.1.
Need this built into your business?
If a prompt isn't enough — what Scult builds, built and maintained for you — that's Scult's day job.
EXPLORE WHAT SCULT BUILDS
