What it is
The AI policy a small team is still following a year later: two to four pages of policy, one page of incident protocol, a register of the AI systems in use, and an annual rhythm with a half-hour monthly check.
In brief
Training & policy
A fixed price, known up front. All prices are on one page, with what is and isn't included.
What it does
Setting down what should already apply in practice: which data may never go into an AI service, who signs off before anything goes out, where to report a mistake, and who is responsible for what. Short enough to be read, concrete enough to be followed.
How it helps
There's a misconception that policy has to be thick. For an organization of five to a hundred people, a thick framework isn't just unworkable but counterproductive: it doesn't get read, so it doesn't get followed, so effectively it doesn't exist. The best policy isn't the most complete one, it's the one that's followed. One simple count measures progress: the number of tasks that run from start to finish with AI, with agreements and checks in place. If that count reads four or five after a year, it's working.
The steps
01
Intake: what is (and isn't) arranged today, and what the sorting session or scan has already surfaced.
02
Drafting: policy, protocol, and register, in the organization's own language.
03
The working session: sharpening it together with the team, so the rules become theirs instead of just paper.
04
Sign-off and setup of the annual rhythm, recorded in the file.
What isn't included
Sector-specific compliance frameworks and legal review of the lawful basis for processing. The policy does make visible when that review is needed.