GaganAI

August 5, 2026 · 7 min read

The AI policy every small practice needs (and the one rule that matters most)

Here's a small experiment for your next team meeting: ask, with genuine curiosity and a promise of no consequences, “who's used ChatGPT or something like it for work this month?”

In almost every practice I've had this conversation with, more hands go up than the principal expected — including, often, the principal's. Your team is already using AI. The only question is whether they're using it inside rules you've written, or rules each of them invented privately.

A policy is not about permission

The instinct is to think of an AI policy as a gate: who may use what. That framing produces long documents nobody reads. The useful framing is different — a policy exists to draw the line before someone finds it by crossing it.

Your office manager pasting a client's details into a free chatbot wasn't careless. She was being efficient with the tools she had, and nobody had ever told her there was a line, let alone where. The failure wasn't hers.

The one rule that matters most

If your policy is a single sentence, make it this: never put client-identifying information into an AI tool that hasn't been approved.

Everything else in a good policy is scaffolding around that sentence — which tools are approved, what “identifying” covers, and what to do when it goes wrong. A team that remembers one rule beats a team that skimmed twelve.

What a usable policy contains

  • The one rule, first. Not scope, not definitions. Policies that open with the rule get remembered.
  • A short never-list. SINs/SSNs, account numbers, birthdates, banking details, client documents. Absolute, no judgment calls.
  • The approved-tools table. Named tools, on named plans, allowed for named kinds of work — with the training-data setting verified and dated.
  • The strip-identifiers habit, with a worked example. Show the unsafe prompt and its safe rewrite side by side. The example teaches more than any paragraph of rules.
  • The human-review rule. AI output is a draft. Nothing reaches a client unread. In a regulated practice this is also what keeps AI a productivity question rather than a supervision one.
  • A no-blame incident step. Stop, write down what happened, tell the principal today. If people fear blame, they hide mistakes — and a hidden mistake is the expensive kind.
  • A review date. AI tools change their terms often enough that an unreviewed policy is stale within a year.

What to leave out

Anything that reads like it was written to impress a lawyer. Definitions of artificial intelligence. Enumerations of every model on the market. Threats. The moment a policy stops sounding like the practice's own voice, staff stop treating it as real.

One page is the right length for a small practice. Genuinely — one page, signed by each member of staff, beats a twelve-page document in a shared drive every time.

Where to start

I keep a free one-page starter policy you can adapt this week — the one rule, the never-list, the five behaviours, and a signature line. It's deliberately a starting point: the finished version needs your actual tools configured, your team trained, and the vendor details documented, which is a week of proper work rather than an afternoon of find-and-replace.

And if you'd like to know how urgently you need it, the AI Risk Scorecard takes two minutes and doesn't flatter.

About the author. Gagandeep Singh spent 20+ years delivering technology programs inside Canadian financial services — including NIST-aligned security work and enterprise data governance — and now helps advisory, accounting, and brokerage practices across Canada and the US adopt AI safely. Nothing here is legal, compliance, or financial advice; rules change, so verify specifics for your jurisdiction.

Wondering where your practice stands?

Eight questions, two minutes, an honest score — and a free one-page policy to start from.

Take the AI Risk Scorecard