What is an AI policy?
Lightbridge Labs defines an AI policy as the single governing document that states how an organization may use AI acceptably and responsibly. It sets scope, guiding principles, roles, permitted and prohibited uses, data handling, model approval, human oversight, and review cadence. It is one artifact inside a broader AI management system, not the whole program.
An AI policy is the governing document, not the whole governance program.
An AI policy is a single artifact: the written statement of how an organization may use AI acceptably and responsibly. It says what AI is allowed to do, what it is not, who is accountable, how data is handled, how tools are approved, and where a person must review or stop an action. It is the document every other AI control points back to, and it is usually the first thing an organization writes when it decides to govern AI on purpose rather than by accident.
Keep the policy distinct from two things it is often confused with. The policy is one artifact inside a wider program: the AI governance framework is the full structure of policies, roles, processes, and controls the policy lives within. And the policy is not the standard: ISO 42001 is the certifiable AI management system standard that, among other things, requires an organization to have a documented AI policy. This page stays on the policy artifact itself: what it contains, how it fits, and how to write one. Building and running the surrounding program is the work Lightbridge Labs delivers through its AI governance practice.
An AI policy contains eight working sections.
A policy is only as useful as the parts that make it operable. These eight sections recur across every credible AI policy, because together they cover what AI may do, who owns it, how data and tools are controlled, and how a person intervenes when something goes wrong.
Scope and definitions
The systems, teams, and use cases the policy covers, and the terms it depends on. A policy that does not say whether it governs vendor AI, embedded features, and employee use of public tools leaves the largest gaps where risk actually lives.
Guiding principles
The stated commitments the organization holds itself to: fairness, transparency, safety, privacy, and human oversight. Principles are the anchor every specific rule points back to, and they keep the policy coherent as tools and use cases change.
Roles and accountability
A named owner for the policy and defined responsibilities across legal, security, data, and the business. A policy without an accountable owner is a document; a policy with one is a rule someone enforces and updates.
Permitted and prohibited uses
An explicit list of what AI may and may not be used for, sized to risk. Clear prohibitions, such as no unreviewed AI in decisions that affect a person's rights, do more to shape behavior than broad aspirations.
Data handling and privacy
Rules for what data may enter an AI system, how confidential and personal information is protected, and where outputs may flow. This is where an AI policy meets existing privacy and information-security obligations rather than duplicating them.
Model and tool approval
How a new AI model or tool gets reviewed and approved before use, and who signs off at each risk tier. Approval gates keep shadow AI from entering production through the side door.
Human oversight and incident handling
The points where a person must review or can stop an AI action, plus a defined path for reporting and responding when a system produces harm. Oversight and incident response turn the policy from a statement into an operating control.
Review cadence
How often the policy is revisited and what triggers an off-cycle update, such as a new regulation or a serious incident. AI changes quickly, and a policy that is never reviewed drifts out of alignment with the tools it governs.
Human oversight and prohibited-use rules matter most where AI takes real action with limited supervision. For why that property raises the stakes, see the Lightbridge Labs guide on agentic AI.
An AI policy sits inside an AI management system as one required artifact.
An AI policy does not stand alone. It sits near the top of an AI management system, or AIMS, the full set of policies, processes, roles, and controls an organization runs to govern AI. The policy states the commitments and rules; the rest of the management system carries them out through risk assessments, approval gates, monitoring, audit trails, and human-oversight points. Every one of those controls traces back to what the policy allows.
The standards make this explicit. Under ISO 42001, the AI management system standard, senior management must establish an AI policy that fits the organization's purpose and is communicated across it, and a documented management system is a requirement in its own right. The NIST AI Risk Management Framework points the same way: its Govern function calls for AI policies and procedures to be in place and implemented effectively across the organization. Neither standard is a universal legal mandate on its own, and no organization is legally required to certify to ISO 42001; both instead make a documented policy a core expectation of responsible AI. For the standard in depth, see the ISO 42001 compliance guide, and for the voluntary risk framework, the NIST AI Risk Management Framework explainer.
Write an AI policy as a staged sequence, not a single draft.
A policy that works is built in order: inventory the AI, ground the rules in principles and existing obligations, write enforceable clauses, name owners, then approve and communicate it. The pattern is consistent across the programs Lightbridge Labs runs.
Inventory your AI and set risk tiers
Start with where AI is used or planned, then classify each use by the consequence of getting it wrong. A tiered model concentrates the strictest rules on high-stakes uses and keeps low-risk experimentation light, which is what makes a policy adopted rather than ignored.
Ground the policy in principles and obligations
Anchor the document in a small set of principles and connect it to the rules you already answer to: privacy law, security policy, and any AI regulation that applies. A policy that contradicts existing obligations creates confusion instead of control.
Write specific, enforceable clauses
Convert principles into concrete permitted uses, prohibited uses, data rules, approval gates, and oversight requirements. Prefer clear, testable statements over aspiration. A reviewer should be able to read a clause and know whether a given use complies.
Name owners and approval paths
Assign a policy owner, a review group, and sign-off authority at each risk tier. Accountability is the difference between a policy that operates and one that sits in a shared drive unread.
Approve, communicate, and set the review cadence
Senior leadership approves the policy, it is communicated to everyone it governs, and a review schedule is set. Under ISO 42001, senior-management approval and clear communication of the AI policy are explicit requirements, not optional polish.
A policy written this way is one artifact in a larger program. For how the surrounding structure comes together, see the Lightbridge Labs AI governance framework guide, and for the certifiable standard the policy helps satisfy, the ISO 42001 advisory practice.
An AI policy template is a starting structure, not a finished policy.
Many organizations begin with a template, and a good one saves time. The risk is treating the template as the deliverable. A policy adopted word for word governs nobody. Judge a template against four tests before you build on it.
It maps to a recognized structure
A useful template aligns to an established reference such as ISO 42001 or the NIST AI Risk Management Framework, so the policy slots into a governance program rather than standing alone. A template with no lineage is hard to defend to an auditor or a customer.
It is tailored, not adopted verbatim
A template is a starting structure, not a finished policy. The scope, risk tiers, permitted uses, and data rules must reflect the organization's actual AI, sector, and obligations. A generic policy that no team recognizes is a policy no team follows.
It names owners and oversight, not just principles
Many templates stop at aspirations. A strong one forces you to name accountable owners, define approval gates, and set human-oversight points. Those operating parts are what turn a statement of values into a control.
It leaves room for review and change
AI and its regulation move quickly. A durable template builds in a review cadence and an update trigger, so the policy stays aligned with the tools and rules it governs instead of freezing at the date it was signed.
A policy is durable only when it is tailored, owned, and reviewed. Lightbridge Labs is pursuing ISO 42001 certification and operates to ISO 42001 controls in its own work, so the policy it helps a client draft is one shaped by running the same discipline internally. The AI governance practice stands up the policy and the program around it, and AI strategy sets the priorities the policy governs. Where AI policy work touches a specific platform, the ownership of AI features inside NetSuite AI sits with Lightbridge ERP, and AI inside Salesforce AI with Lightbridge Cloud; broader technology and digital-transformation strategy sits with the Lightbridge umbrella.
AI policy: frequently asked questions
- What is an AI policy?
- An AI policy is the governing document that states how an organization may use AI acceptably and responsibly. It sets the scope of what it covers, the guiding principles it holds to, the roles and accountability for AI decisions, the permitted and prohibited uses, the rules for data handling and privacy, the process for approving models and tools, the points of human oversight, how incidents are handled, and how often the policy is reviewed. The policy is a single artifact, not an entire governance program. It is the document every other AI control points back to, and it is one of the things a standard such as ISO 42001 expects an organization to have in place.
- What should an AI policy include?
- A complete AI policy covers eight things. Scope and definitions state what the policy governs and the terms it uses. Guiding principles set the commitments, such as fairness, transparency, safety, privacy, and human oversight. Roles and accountability name an owner and assign responsibilities. Permitted and prohibited uses spell out what AI may and may not be used for, sized to risk. Data handling and privacy rules govern what data may enter a system and how outputs may flow. Model and tool approval defines how a new AI tool is reviewed before use. Human oversight and incident handling set the points where a person must review or can stop an action and the path for responding to harm. Review cadence states how often the policy is revisited. Together these turn a statement of values into an operating control.
- What is the difference between an AI policy and an AI governance framework?
- An AI policy is one document; an AI governance framework is the whole program that document lives inside. The framework is the structured set of policies, roles, processes, and controls an organization uses to direct and oversee its AI across the lifecycle. The policy is a single artifact within it, the written statement of what the organization will and will not do with AI. Put simply, the policy states the rules, and the framework is the machinery that enforces them, measures compliance, and improves over time. An organization writes the policy as part of building the framework, not instead of it. The two are related but distinct, and confusing them leads teams to think a signed policy means they have a governance program when the operating parts are still missing.
- Is an AI policy required by ISO 42001?
- Yes. ISO 42001, the international standard for an AI management system, requires an AI policy as an explicit clause. Under the standard, senior management must establish an AI policy that fits the organization's purpose, gives direction to its AI objectives, and is communicated across the organization. A documented AI management system is likewise a requirement of the standard. So an AI policy is not merely good practice under ISO 42001; it is one of the artifacts an organization must have to conform. The NIST AI Risk Management Framework points the same way through its Govern function, which calls for AI policies and procedures to be in place across the organization. Neither standard is a universal legal mandate on its own, but both make a documented policy a core expectation of responsible AI.
- How does an AI policy fit inside an AI management system?
- An AI policy is a foundational artifact inside an AI management system, or AIMS. The AIMS is the full set of policies, processes, roles, and controls an organization runs to govern AI, the concept ISO 42001 specifies and certifies. The policy sits near the top of that system as the document that states the organization's commitments and rules, and the rest of the management system operationalizes it: risk assessments, approval gates, monitoring, audit trails, and human-oversight points all trace back to what the policy allows. Under ISO 42001, the AI policy is a requirement of the leadership clause, and the documented management system is a requirement in its own right. The policy is the statement; the management system is how the statement is carried out and kept current.
- How do you write an AI policy?
- Write it as a sequence, not a single draft. First, inventory where AI is used or planned and classify each use by the consequence of getting it wrong, so the strictest rules land on high-stakes uses. Second, ground the policy in a small set of principles and connect it to obligations you already answer to, such as privacy law and security policy. Third, convert those principles into specific, enforceable clauses: permitted uses, prohibited uses, data rules, approval gates, and oversight requirements a reviewer can test against. Fourth, name a policy owner, a review group, and sign-off authority at each risk tier. Fifth, have senior leadership approve the policy, communicate it to everyone it governs, and set a review cadence. This staged path is how Lightbridge Labs helps a client stand up a policy that operates rather than one that sits unread.
- What should we look for in an AI policy template?
- Treat a template as a starting structure, not a finished policy. Look for four things. It should map to a recognized reference such as ISO 42001 or the NIST AI Risk Management Framework, so the policy fits a governance program rather than standing alone. It should be tailored to your actual AI, sector, and obligations rather than adopted word for word, because a generic policy no team recognizes is one no team follows. It should force you to name accountable owners, approval gates, and human-oversight points, not just list principles, since those operating parts are what make a policy a control. And it should build in a review cadence and an update trigger, because AI and its regulation change quickly. A template that meets those tests saves structure; one that does not can give a false sense of coverage.
Important notices
General advisory: this page is general guidance from Lightbridge Labs as an independent AI-governance advisor. It is not a warranty and not a substitute for an assessment of your own organization, systems, and circumstances.
Not legal, audit, or accounting advice: this is a simplified summary of how an AI policy relates to standards such as ISO 42001 and the NIST AI Risk Management Framework, both detailed and evolving. It does not capture every requirement or control objective, and it does not establish whether your organization meets any standard. Consult your own counsel and verify every specific against the official standard text before relying on it.
Lightbridge certification status: Lightbridge Labs is pursuing ISO 42001 and operates to those controls while the audits proceed. ISO 27001 and SOC 2 are likewise in progress. Nothing on this page should be read as a claim that Lightbridge Labs holds, maintains, or is certified or compliant with any of these.
Freshness: standards text, guidance, and regulatory timelines change. This page reflects a general understanding as of mid-2026 and should be re-checked against current sources before action.
From a policy on paper to a governed AI program.
When the question shifts from what an AI policy is to writing one that fits your organization and holds up inside a governance program, Lightbridge Labs drafts the policy, names the owners, and stands up the controls around it.