EP 136: How to Write a One-Page AI Policy From Scratch | AI in HR Series

Series: AI in HR (Ep 3 of the series) · Host: Kerri Roberts · Run time: ~33 minutes

🎧 Listen on Apple Podcasts · Spotify · Buzzsprout

📺 Watch on YouTube: [add per-episode YouTube URL]

📖 Read the full transcript below

Episode Summary

A policy is not permission. It’s protection. If your company doesn’t have an AI policy, that doesn’t mean your company isn’t using AI - it means AI is running inside your business with no rules. Right now, someone on your team is probably pasting a salary, a Social Security number, or client information into a chatbot. Not because they’re reckless, but because nobody ever set the parameters.

In this episode, Kerri Roberts shows you how to write a real one-page AI policy from scratch. Not a 40-page binder, not legalese - five plain-English sections your whole team can read in two minutes. She walks through why a policy gap is a finance risk (HR metrics are finance metrics), what the current data actually says about who’s using AI, and the exact prompt she uses to get AI to draft a compliant first draft for her. Your team is already using AI. The only question is whether you’ve told them the rules.

In This Episode

  • Why “no AI policy” doesn’t mean “no AI” - it means AI with no guardrails

  • The real numbers: 40% of employees use AI at work, and only ~30% of companies have any guidelines

  • Why HR metrics are finance metrics, and how a policy gap becomes legal and financial exposure

  • The five sections of a one-page AI policy: approved tools, a never list, human ownership, disclosure, and an owner + review date

  • The “never list” - what should never be pasted into a public AI tool

  • Why 54% of existing AI policies fail by being too restrictive, and how to avoid it

  • What has to stay human - and why AI slop quietly destroys trust

  • The exact prompt Kerri uses to have AI draft a compliant policy (and why you should talk, not type)

Chapter Timestamps

0:00 The AI already running inside your company

1:39 Welcome (and why the new iPhone made me use ChatGPT)

3:56 You’re not going to ignore AI - so let’s set rules

5:00 Who’s actually using AI at work (the Gallup numbers)

7:00 HR metrics are finance metrics: what a policy gap costs you

10:57 The one-page policy: 5 plain-English sections

12:00 Section 1 - Approved tools

13:30 Section 2 - The never list

14:34 Section 3 - A human owns every decision

6:00 Section 4 - Disclosure

16:55 Section 5 - Owner and a review date

17:30 Don’t over-restrict (why 54% of AI policies fail)

21:18 What has to stay human (AI slop and the trust problem)

26:00 How to actually prompt AI to draft your policy

29:00 Resources: the book, the coursework, the HR audit

30:39 Speaking, contact, and working together

33:04 Don’t waste the chaos - embrace it

Resources Mentioned

The HR Easy Button (book): saltandlightadvisors.com/thehreasybutton - paperback, hardback, and Kindle on Amazon

HR coursework, tools, and free resources: saltandlightadvisors.com/resources

Free Mini HR Audit: saltandlightadvisors.com/hraudit

Companion blog post: How to Write a One-Page AI Policy for Your Small Business - saltandlightadvisors.com/blog

Your Action Item

Block 30 minutes this week and draft your one-page AI policy using the five sections: approved tools, a never list, human ownership, disclosure, and an owner with a quarterly review date. Open your AI, give it your state, industry, size, and mission and values, and tell it to ask you 5-10 questions before it drafts anything - compliant to your state and federal law. Then you edit. Something beats nothing, and most companies still have nothing.

GET THE MONDAY EMAIL

If this episode resonated, you’ll like the Monday morning email. Every Monday at 5:28am, Kerri sends one practical idea for leaders who want to do this work better - including the conversations behind episodes like this one. 1,000+ leaders. 50%+ open rate. https://saltandlight.myflodesk.com/saltandlightadvisors

Full Transcript

The AI already running inside your company

If your company does not have an AI policy, that does not mean that your company is not using AI. You have AI running inside of your company - I have no doubt. It’s just running without any rules.

Do you recognize that? People are obviously using AI in your company. I’ve read some stats about policies and utilization, and we’re going to get into it today. But right now, somebody on your team is probably putting a salary, a Social Security number, maybe even a client’s credit card information into AI right now. And they’re not trying to be reckless - they just don’t have a place where parameters have been set.

So that’s exactly what we’re getting into today. We’re going to talk about how to write an AI policy from scratch. I know - so exciting. But this is important. You have to have an AI policy. I’m going to give you an outline for a one-pager. I’m not talking about a 40-page binder, and I’m not talking about this like I’m an attorney, because I am not. I’m an HR pro. I’m just trying to get you started so you have something, because your employees are using it inside of your business and we need to get into it.

Welcome (and why the new iPhone made me use ChatGPT)

Welcome back to another episode of Don’t Waste the Chaos. I’m your host, Kerri Roberts. And I’ll tell you what - I got a new iPhone over the weekend, and I am so grateful, thanks to AI, that I was able to figure out how to plug it in. I’ve got an iPhone 17 Pro now, so I need a C-to-C, and that’s not the cord that I had before. I figured it out, but gosh dang, it feels like it takes a full-on master’s degree to figure out how to hook cords up anymore. And I’m a pretty tech-savvy girly. This was hard. I literally used ChatGPT right before I sat down to record.

I’m excited for this conversation. We’ve talked about whether your HR is ready for AI, and then we did an assessment the second week we talked about AI. Now we’re going to talk about a policy - because we have to have a policy. It’s not because I’m so lame that we have to write everything down. We just need some protection. Your team is already using AI. The question is not whether to let them, because they’re going to. It’s whether you’ve told them the rules. That’s where your protection comes in. We’re not talking about permission - we’re talking about process. If you don’t provide the tools, the parameters, and the rules, they’re just going to use their personal AI for work, and your company information ends up stored on their personal AI. We’ve got to pay for it, have a policy, and be rocking and rolling with it.

You’re not going to ignore AI - so let’s set rules

I’m recording this at the beginning of August 2026. And friend, if you think you’re going to ignore AI in your business, you’re just not. It’s not possible. It has reformed my business - the admin and the marketing side has been absolutely reformed, and your business can too. I know we have opinions on data centers, on some of the repercussions, on AI slop on social media - I’ve got opinions on all of that too. But there are also so many ways it’s helpful.

Here’s what’s happening. You’ve got AI with no guardrails. Someone’s passing the compensation spreadsheet into a chatbot. A manager is running a termination through their AI but hasn’t told it what state they’re operating in. Social Security numbers are just up in the browser tab - that’s happening right now, without parameters. This episode is going to help you write a real one-page policy from scratch. Policy is not permission. It is protection for your organization.

Who’s actually using AI at work (the Gallup numbers)

Most people think an AI policy just means “can you use it, yes or no?” And most people have already decided for you - they’re going to use it. I saw a stat from Gallup that said 40% of employees are using AI at work right now, whether the company has a policy or not. That’s over double what it was in 2023. And 8% of employees are using it every single day.

Here’s the part that should make you feel better, not worse: only about three in ten companies have a policy or any guidelines at all around it. So you’re not behind. But let’s make sure you’re not one of the companies that stays behind. The 40% figure came from Gallup, and the roughly 30% of organizations with any guidelines came from Gallup as well. Fresh data.

HR metrics are finance metrics: what a policy gap costs you

So many times with human resources, we think about it from a cost-center perspective - which tells me you don’t have a very strong HR person who can show how it benefits the organization. But I digress. Here’s where a policy can cost you. HR metrics are finance metrics. I’ve said that over and over. HR owns the largest line item - typically compensation and benefits. So this is a finance issue, and every gap in your policies has an associated dollar sign.

If there’s no rule on what data goes in, and the compensation spreadsheet or an employee’s personal information or client information ends up in a public tool, that’s a breach - something you can get sued for. If there’s no human-in-the-loop rule and a manager is leaning on AI for employment law, there could be a wrongful termination claim. If there’s no disclosure rule and you can’t prove how a hiring decision was made, that could be a discrimination case. More than half - 57% of HR pros - are unaware of their state’s workplace AI laws. That was in a SHRM report that came out earlier in 2026.

A policy gap is a finance risk sitting on your balance sheet, whether you’ve put a price tag on it or not. I’ve been dragged into far too many claims - over 20 years in HR and serving other clients’ HR teams, I’ve sat in lawsuits, been deposed. Some of these last six months; I had one last over a year and a half. They are so time-consuming and financially draining, and even if you settle, it’s still a mess. So draft the freaking policy. There are so many times a company owner says, “I just don’t want to put it in writing, because then we’re trapped.” I see where that comes from, but to me that just comes across as weak leadership. Sorry if that’s the truth.

The one-page policy: five plain-English sections

Even among companies already using or piloting AI, fewer than half have a policy governing it. So if you write one, you’re ahead of the curve. You don’t need a lot of legalese. I’m not an attorney - this is my advice based on what I’ve seen - but I think you need five plain-English sections your whole team can read in about two minutes. If it sounds out of alignment with your culture, that’s odd to me - it’s one of your cultural documents, so it should sound like your culture.

Section 1 - Approved tools

The first thing you list out is your approved tools. If it’s not on the list, an employee needs to ask before they use it. Name the tools people are allowed to use, and make sure you’ve got the paid or business version where data is not used for training. I have the business version of ChatGPT, the business version of Claude, and I pay for Outlook, so I’ve got all the AI tools in the Microsoft suite. The paid business versions let you set security in a much richer way than the free versions. Even for the paid versions, I keep my data scrubbed when I give it to AI, and I match it back up on the back end, because it’s safer. If a tool is not on the list and you want to use it, ask your manager or IT for approval first and show a use case for why the company should pay for the business version.

Section 2 - The never list

The second thing is what I’d call a never list - what you never put into AI. Social Security numbers, dates of birth. Anything medical - be careful. Disciplinary action records. Compensation data. Customer confidential data. Anything you wouldn’t email to a stranger, we’re probably not putting into AI. And if we are, we’re making sure the security is on lock.

Section 3 - A human owns every decision

The third thing: a human owns every decision. We’re not outsourcing decision-making to our AI. I know that seems obvious, but I want to see you put it in your policy - and do it in practice. AI can draft, summarize, and suggest - those are brilliant reasons to use it. But a human is the only one who makes and owns a decision that can affect someone’s job, status, pay, or client retention. No AI-only calls on people.

Section 4 - Disclosure

The fourth thing is disclosure. We want to disclose when we use AI - in hiring, recruiting, screening, evaluations, discipline - and keep a record. That helps you understand how decisions were made later if something comes up. Say there’s a wrongful termination case: we need to show whether we used AI to look for trends in performance reviews or disciplinary actions. Or if someone claims discriminatory hiring, we have to show how we used AI in the process. I’d keep that in a work instruction or standard operating procedure.

Section 5 - Owner and a review date

The fifth and final piece: an owner and a review date. I want somebody who owns this policy - not a department. Who owns it? What’s their job title? And how often will you review it? At a bare minimum, review this quarterly. For your whole handbook, I recommend at least annually. But AI is changing so frequently that we review this policy at least quarterly. So: approved tools, the never list, a human makes the decision, how you’ll disclose, and an owner plus a review cadence. Is it something an attorney would give you? No - they’d give you an 11-page situation, because this is the wild, wild west. But something is better than nothing.

Don’t over-restrict (why 54% of AI policies fail)

When you’re writing your policy, don’t over-restrict. That’s going to be a real problem - it’s very hard to hold people accountable to a policy that’s too tight. When I pick up a client’s handbook for the first time, they’ve either used a template that gives no indication of how they actually operate, or an attorney drafted it and you need a PhD to read it. Employees aren’t reading that, but they’re signing off on it. And when they break those policies, as long as they can prove it was too complex, a lot of judges rule in their favor.

Here’s the proof it’s worth doing right. Of the companies that do have a policy, only about a quarter - around 25% - call their existing AI policy clear and future-proofed. And 54% are too restrictive. That’s from the SHRM State of AI in HR report that came out in 2026. So don’t ban AI. I’ve seen companies say, “don’t use AI - we’ll use it eventually, we just don’t know how yet.” But how long is that going to take? Somebody needs to be working on it right now - your COO, your director of HR working with IT and operations and likely sales.

What has to stay human (AI slop and the trust problem)

Be very clear about what stays human. Hand AI the first draft: the job description, the first pass at a resume sort, the start of a policy draft. But keep in human hands the hiring call, the disciplinary decision, and the actual coaching conversation. I was looking this morning at one of my clients - the CEO puts out a motivational message every morning, but it’s so clearly AI-written that I’d bet more than 90% of employees aren’t reading it. Even with personal anecdotes, people are getting numb to it. I had another client whose employees were taking her weekly messages and putting them into their own AI to respond, because she required a response and had low trust. So it was her AI talking to their AI, back and forth. Is there a genuine sentiment in the whole thing? I don’t think so. AI can write a draft, but you need to own the decision and stand behind it. It’s a tool. Your curling iron can’t save the whole day, and AI can’t either.

How to actually prompt AI to draft your policy

Next week I’m getting into hiring - how to use AI in hiring and where maybe you shouldn’t. AI should not be another job for you, friend. It should be taking things off your plate. Here’s an example of how I’ve used AI to draft a policy. I’ll say: this client operates in Missouri, they’re in the construction industry, about $12 million in revenue, around 38 employees - the vast majority W-2, but they have some contractors. They’re fast-growing. They primarily work on interiors and exteriors. I feed it as much as I can, including their mission, vision, and values, and the issues they’ve had - roadblocks with hiring and retention, competitive pay.

Then: I’m trying to draft a policy for this client around AI utilization. Give me a first-round draft - but before you do, ask me 5 to 10 questions I should answer that go deeper, to help you make the best draft possible. And remember to be compliant to the state of Missouri and any overarching federal laws around AI. That is the way we set up our prompts.

And if you’re thinking “that’s going to take forever to type” - hit the mic button. I hit that mic button all the time, because your prompts are so much better when you talk to it versus type. When you type, you’re thinking about the clearest way to say it; if you just ramble, it will figure it out with you. It’ll also understand your voice better - your inflection, your emphasis, and the actual language you use. The more you talk to your AI, the better it captures your voice. I’d also say: give AI this podcast. Link the episode or copy the transcript and say, “I follow this HR consultant and this is what she recommended for a one-page policy. Start there and expand on it based on my industry and my business.”

Resources: the book, the coursework, the HR audit

I’d love it if you’d subscribe to the show. If you listened and you’re thinking “I need it in writing” - I’ve put it in writing. I’ve got the HR Easy Button book on Amazon: paperback, hardback, and Kindle. If you want to hop into my coursework, I record about a one-hour teaching video on every foundational HR topic - about 13 or 14 topics - then give you downloadable tools, templates, and scripts so you can apply it that same day. Find it at saltandlightadvisors.com/resources. There are also a few freebies there - my free mini HR audit and a hiring guide.

Speaking, contact, and working together

I’m always looking for new clients. My goal is to graduate clients every six months, sometimes a year - I’m not looking to keep you on my list for years. I build the foundation with you and then hand it off. If you want that mini HR audit, go to saltandlightadvisors.com/hraudit. If there’s anything I can do, saltandlightadvisors.com/contact will get you in touch. I recently revamped my contact page, so if you’ve sent me a message since January 2026, shoot me another one. And if you want me to come in as a keynote speaker for your business, leadership team, or a board meeting, I’d be happy to. I keynote a couple of times a month, and I’ve got retreats available too.

Listen, I know writing policies is not the sexiest thing anyone ever did. But I try to make it a little easier for you, because this work is worth it. So don’t waste the chaos - embrace it. I’ll see you next week.

Resources To Keep Building

Not sure whether your people systems could survive an AI mistake right now? Take the free HR Audit to see exactly where your gaps are in 5 minutes. saltandlightadvisors.com/hraudit

📚 Explore the HR coursework - Self-paced courses, tools, and resources to build your HR systems step by step. saltandlightadvisors.com/resources

✉️ Get the Monday Email - One practical idea for leaders, every Monday at 5:28am. 1,000+ leaders, 50%+ open rate. saltandlight.myflodesk.com/saltandlightadvisors

Need fractional HR support or want to talk through a specific challenge? saltandlightadvisors.com/contact

Next
Next

EP 135: Where to Start With AI in HR - 5 Tasks to Automate First