AgenTomte

August 20, 2026 · 7 min read

The One-Page AI Usage Policy: What Matters, What Is Theatre

By Anna, co-founder, build and content

A working AI usage policy fits on one page and answers six questions: which tools staff may use, which data may never go into them, who reviews AI output before it leaves the building, when AI involvement has to be disclosed, who owns the policy, and how fast an incident gets reported. Everything past those six is decoration.

We know it is decoration because the decorated policies are not holding. In IBM’s Cost of a Data Breach Report 2026, published 29 July 2026, security incidents involving shadow AI, meaning staff using unapproved AI tools, more than doubled to 43% from 20% the year before. Those incidents cost an average of USD 5.39 million against USD 4.63 million a year earlier.

What a one-page AI usage policy has to answer

Six things: approved tools, forbidden data classes, the human review step, the disclosure rule, the named owner, and the incident deadline. A policy that answers those six can be read in ninety seconds and enforced by a manager with no security background. A policy that opens with principles and closes with a values statement is a document nobody consults at the moment of decision.

The moment of decision is always the same. Someone has a contract, a customer list, or a half-written proposal, and a chat window open. Your policy either reaches that moment or it does not.

The six clauses that do work

The best public example is not a template vendor’s PDF. It is an actual employer policy: U.S. General Services Administration Order CIO 2185.1C, signed 11 March 2026, which governs AI use for every GSA employee and contractor. It is worth reading because it commits to specifics that template policies avoid.

ClauseThe specific versionThe theatre version
Approved toolsName the tools. GSA requires staff to use one named internal chat tool, and anything else needs security and board approval.”Use approved AI tools.” No list, no approver named.
Forbidden dataName the classes. GSA bars internal, pre-decisional and controlled unclassified information as prompt input without committee approval.”Do not share sensitive information.”
Human reviewName the trigger. GSA requires board approval before any output from a public tool enters a production work product.”Always check AI output.”
DisclosureName the artefact. GSA requires work product materially modified by or solely produced by generative AI to be labelled, covering text, code, audio, imagery and video.”Be transparent about AI use.”
OwnerName a person and a review date.”IT is responsible.”
IncidentsName the clock. GSA requires a use case with a security or privacy incident to be resubmitted for re-evaluation within five days.”Report incidents promptly.”

The pattern is boring on purpose. Every workable clause names a thing, a person, or a number. Every theatrical clause names a virtue.

The clauses that are theatre

Blanket bans. A ban on AI at work does not stop AI at work, it moves it to personal accounts on personal devices where you have no logs. IBM’s 2026 figure for shadow AI incidents is what a blanket ban actually produces.

Accuracy pledges. “Employees must verify all AI output for accuracy” is not a control, it is a wish. The enforceable version names which categories of work require a second human signature before release.

AI detection promises. Detector tools do not produce reliable evidence, and a disciplinary clause resting on one will not survive contact with a dispute. Ask for disclosure instead, and make disclosure cheap to give.

One-off training. Training that happened once at rollout is not a control either, and it is measurably rare. In IBM’s 2026 data, only 30% of breached organisations ran employee training on AI risks, down from 36% the year before.

Policy coverage is going backwards, not forwards

The most useful finding in the 2026 IBM report is not the shadow AI number. It is that 68% of breached organisations lacked governance to manage AI or detect shadow AI, up from 63%, and that almost every governance control they measured declined year on year. Strict approval processes for AI deployments fell to 38% from 45%. Regular audits for unsanctioned AI fell to 29% from 34%. Only 19% reported any coordination between their governance and security teams.

That decline happened while adoption climbed. The U.S. Census Bureau put AI use at roughly 19.8% of U.S. businesses as of 3 May 2026, and 37% among firms with 250 or more employees. Eurostat reported on 11 December 2025 that 20.0% of EU enterprises with ten or more staff used AI in 2025, up from 13.5%.

There is also a gap between what the policy says and what people do. A global study of more than 48,000 people by the University of Melbourne with KPMG, published April 2025, found only 40% of employees said their workplace had a policy on generative AI use, nearly half admitted using AI in ways that contravened company policy, and 57% said they hid their AI use and presented the output as their own.

”Can we put company data into it” is a tier question

Most policies answer this with a yes or a no. The correct answer depends on which account tier the person is logged into, and that belongs in the policy as a line, not a paragraph.

Anthropic states that by default it does not use inputs or outputs from its commercial products, including Team, Enterprise and the API, to train models. On consumer plans the position is different: since its 28 August 2025 terms update, Free, Pro and Max users choose whether their chats train the models, and choosing yes extends retention to five years.

OpenAI’s developer documentation states that data sent to the OpenAI API is not used to train its models unless you opt in, with abuse monitoring logs kept up to 30 days. Google’s Workspace privacy hub, last updated 14 August 2026, states that Workspace does not use customer data to train models without the customer’s prior permission.

So the enforceable clause is not “do not put company data into AI.” It is “company data goes only into the accounts on this list, and never into a personal account.” One line, and it maps to something an admin can check.

Where AI literacy law fits

If you operate in or sell into the EU, staff AI competence is already a legal duty rather than a nice idea. Article 4 of the EU AI Act has applied since 2 February 2025, and the European Commission’s own AI literacy FAQ, last updated 27 July 2026, confirms supervision and enforcement began on 2 August 2026. The Commission also says national market surveillance authorities could impose penalties for infringements, without attaching one of the headline fine bands to it.

The duty was then softened. The Commission’s page on the AI omnibus entering into force on 27 July 2026 states that the previous AI literacy requirement for companies is simplified, with the Commission and member states taking a stronger role. Read that as pressure reduced, not removed, and note that our post on which AI regulations apply to your business covers the Texas, Colorado and UK positions for readers outside the EU.

One more line worth adding while you are in the document: the U.S. Copyright Office’s January 2025 report on copyrightability holds that prompts alone do not make a human author, which is a good reason for your policy to say who owns AI-assisted deliverables before a client asks.

What we run ourselves

Our own fleet operates under exactly these clauses. As of July 2026 it is 41 agents in production, each one a tomte, our word for one production agent with one defined job, and every one has a named owner, a permission scope, and a human merge gate before anything reaches a live system. In one thirteen-day stretch those agents ran 5,450 times with zero failures.

The governance is the reason, not a footnote to it. You can read how the fleet is run on our agent fleet page, and the pre-deployment checks sit in the AI security review to run before deployment.

A fractional AI officer engagement includes this document: one page, six clauses, named owner, quarterly review, written and maintained alongside the builds it governs. Fixed monthly price, cancel monthly, and you own the document.

If your AI policy is currently three pages of principles and no tool list, write to us at /start and describe what your team is already doing with AI. You get a written reply within one business day, and no meeting.

Tell us what you want automated

Describe the work in writing. You get a written reply within one business day: a fixed-price proposal, a scoping question, or an honest referral out.

Start at /start

▸ written reply within one business day · no call scheduled, ever

Doesn't fit a package? Tell us what you need anyway.

Questions? Ask in writing

no chatbot · a human replies

Ask us anything, in writing

A founder replies within one business day. That is the same promise clients get.