Seed-stage B2B SaaS startup
Sample for a fictional organisation · 2,173 words[Company] Responsible AI Policy
- Version: 1.0
- Owner: Chief Technology Officer (CTO)
- Approved by: Chief Executive Officer (CEO)
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose
[Company] uses artificial intelligence ("AI") tools to support its internal work. This policy sets out the principles [Company] follows when it evaluates, approves and uses AI, and the commitments that put those principles into practice so that AI is used responsibly, safely and in a way that respects the rights of the people it affects.
This policy applies to everyone at [Company] who uses AI tools as part of their work, and it explains how new uses of AI are approved, how data is protected, and how [Company] oversees the output that AI tools produce.
2. Scope
This policy applies to all AI tools used by [Company] staff in connection with company work, regardless of the device or account used to access them. [Company] does not currently build AI-powered features into a product; this policy governs the internal use of third-party AI tools.
This policy covers:
- Generative AI tools, such as large language models, used to draft, summarize, translate, or analyze text or other content.
- AI-powered features built into software [Company] already uses, such as office, communication, or business software.
- Any other AI tool that a staff member proposes to use for company work, including tools that assist with decisions about people, such as hiring or performance.
Read the full example
[Company] Responsible AI Policy
- Version: 1.0
- Owner: Chief Technology Officer (CTO)
- Approved by: Chief Executive Officer (CEO)
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose
[Company] uses artificial intelligence ("AI") tools to support its internal work. This policy sets out the principles [Company] follows when it evaluates, approves and uses AI, and the commitments that put those principles into practice so that AI is used responsibly, safely and in a way that respects the rights of the people it affects.
This policy applies to everyone at [Company] who uses AI tools as part of their work, and it explains how new uses of AI are approved, how data is protected, and how [Company] oversees the output that AI tools produce.
2. Scope
This policy applies to all AI tools used by [Company] staff in connection with company work, regardless of the device or account used to access them. [Company] does not currently build AI-powered features into a product; this policy governs the internal use of third-party AI tools.
This policy covers:
- Generative AI tools, such as large language models, used to draft, summarize, translate, or analyze text or other content.
- AI-powered features built into software [Company] already uses, such as office, communication, or business software.
- Any other AI tool that a staff member proposes to use for company work, including tools that assist with decisions about people, such as hiring or performance.
3. Principles
[Company] applies the following principles to every use of AI, whatever the size of the task.
- Fairness: AI tools must not produce outcomes that unfairly disadvantage people based on characteristics such as race, sex, age, or disability, and [Company] checks for this before using AI in decisions about people.
- Transparency: People are told when AI has materially contributed to a decision about them, and AI-generated content is not passed off as unaided human work where that would mislead.
- Human oversight: A person with the authority and knowledge to change the outcome reviews any AI output used in a decision with legal or similarly significant effects on a person.
- Accountability: A named role is responsible for this policy, and every use of AI is approved and recorded before it starts.
- Privacy: Personal data is only used with AI tools that meet [Company]'s data protection requirements, and only for purposes consistent with why the data was collected.
- Safety and security: AI tools are chosen and used in a way that protects [Company]'s systems, data, and the confidentiality of the information staff work with.
4. Roles and Responsibilities
- Chief Technology Officer (CTO): Owns this policy, is accountable for its implementation, approves or delegates approval of new AI tools and uses, maintains the AI system inventory described in Section 13, and looks after security matters relating to AI.
- Chief Executive Officer (CEO): Approves this policy and approves any use of AI that is higher-risk, such as a use that affects customers, staff, or personal data, as described in Section 5.
- Staff: Use only approved AI tools, follow this policy and any related guidance, check AI output before relying on it, and raise concerns about AI use as described in Section 16.
5. Approving New Uses of AI
Every new use of AI at [Company] must be approved before it starts, and the amount of review scales with the risk involved. Low-risk uses, such as drafting internal text with an already-approved tool, need only confirmation that the tool itself has been approved for use. A use that affects customers, staff, or the public, or that involves personal or customer data, needs a short assessment of who could be affected and how before it can go ahead.
- The staff member proposing the use identifies the AI tool, its intended purpose, and the data it would touch.
- The CTO reviews the proposal and determines whether it is low-risk or requires further assessment.
- Where the use affects customers, staff, or the public, or involves personal or customer data, the CTO carries out a short impact assessment describing who could be affected and how, and the CEO approves the use before it starts.
- The approved tool, its purpose, and the outcome of any assessment are recorded in [Company]'s AI system inventory.
6. Data Governance
[Company] does not train or fine-tune AI models. Any proposal to train or fine-tune a model must be approved by the CTO and CEO before any work begins, following the same process as any other new use of AI.
- Personal data and customer data are entered into an AI tool only where that tool has been approved for that type of data.
- Before approving an AI tool, [Company] checks the AI model provider's terms to confirm whether it may use [Company]'s inputs and outputs to train its own models, how long it retains that data, and where it processes it.
- Personal data and customer data are sent only to AI services whose terms confirm that the provider will not use that data to train its models.
- [Company]'s data retention and access controls apply equally to any data stored, cached, or logged by an AI tool.
- The AI system inventory records which AI tools are approved, what data each may be used with, and the basis for that approval.
7. Fairness and Bias
Before an AI tool is used in a decision about a person, such as hiring, performance, or promotion, [Company] takes steps to understand and reduce the risk of unfair or biased outcomes. This applies whether the tool is used directly by [Company] or embedded in software [Company] already uses.
- Before using an AI tool in a decision about people, [Company] obtains the supplier's bias-testing results where available, or tests the tool itself using realistic examples.
- The result of that check is recorded in the AI system inventory alongside the tool's approval.
- Any AI tool found to produce biased or unreliable results in this context is not used for that purpose until the issue is resolved.
8. Human Oversight
AI does not make a decision with legal or similarly significant effects on a person, such as hiring, dismissal, or performance decisions, without a person reviewing the case who has the authority and knowledge to change the outcome. That person must genuinely review the case, not simply approve the AI's output as a formality.
- Staff using AI to support a decision about a person must record that a human reviewed the AI's output and made the final decision.
- Reviewers must have enough context and expertise about the situation to identify when the AI's output looks wrong, incomplete, or unfair.
- AI output used to inform a decision about a person is treated as one input among others, not as the decision itself.
9. Transparency
[Company] is clear with staff and with the people its work affects about where AI has played a role. This applies both to AI tools staff use directly and to AI features embedded in other software [Company] uses.
- People are told when AI has been used in a decision that affects them.
- AI-generated content sent outside [Company], such as in customer communications, is not presented as unaided human work where doing so would mislead the recipient.
- Staff disclose the use of AI tools when asked by a customer, partner, or colleague about how a piece of work was produced.
10. Safety, Security and Reliability
AI tools are subject to the same security expectations as any other software [Company] uses, and staff must satisfy themselves that an AI tool is reliable enough for the task before relying on its output.
- AI tools must be accessed only through accounts and configurations approved by the CTO.
- Staff must check AI-generated output for accuracy, relevance, and appropriateness before relying on it or sharing it, particularly for anything sent to a customer or used in a business decision.
- Any AI tool that behaves unexpectedly, produces harmful or clearly wrong output, or appears to expose data it should not have access to, must be reported as described in Section 13.
- Access to AI tools is removed promptly when a staff member leaves [Company] or no longer needs it.
11. Third-Party AI Services
[Company] accesses AI models through AI model providers' own services or APIs rather than running models on its own infrastructure. Before approving any such service for use, [Company] reviews the provider's terms to understand how it will treat [Company]'s data.
- Before approval, the CTO checks whether the provider may use [Company]'s inputs or outputs to train its own models, how long the provider retains that data, and where the data is processed.
- Personal data and customer data are only sent to AI services whose terms confirm the provider will not use that data to train its models.
- Providers are re-checked when their terms change materially, or at least once a year for any service handling personal data.
- Any AI service that cannot meet these requirements is not used for work involving personal data or customer data, even if it is otherwise useful.
12. Staff Use of AI Tools
Staff must use only AI tools that the CTO has approved for work, and must check AI output for accuracy before relying on it or sending it outside [Company]. Staff remain personally responsible for any work product they create with the help of AI, in the same way they are responsible for work they create without it.
- Personal data and customer data must only be entered into AI tools that have been approved for that type of data.
- Staff must not use unapproved AI tools for company work, even where a free or convenient option is available.
- Any use of AI in a decision about a person, such as hiring or performance, must follow the review process in Sections 5, 7, and 8.
- These rules apply to contractors performing work for [Company] in the same way they apply to employees.
13. Monitoring, Incidents and Records
[Company] keeps an AI system inventory recording, for each AI tool it uses: its purpose, the staff member or role responsible for it, the AI model provider, the data it uses, its risk rating, its approval record, and, where applicable, any fairness or reliability checks carried out.
- Any AI-related incident, such as harmful or biased output, a data leak through an AI tool, or a tool behaving outside its intended use, is handled through [Company]'s general incident response process.
- Staff must report suspected AI incidents to the CTO as soon as they notice them.
- The AI system inventory is reviewed at least once a year, and updated whenever a new tool is approved, an existing tool changes significantly, or a tool is retired.
14. Training and Awareness
[Company] makes sure staff understand this policy and know how to use AI tools responsibly, including how to check AI output, when human review is required, and how to raise a concern. This awareness is refreshed at least once a year and whenever this policy changes materially.
15. Legal and Regulatory Requirements
[Company]'s use of AI is subject to existing US laws on consumer protection, discrimination, and privacy, which apply to AI in the same way they apply to any other technology. Where AI is used in a decision about staff, such as hiring or performance, the CTO checks which state or local rules on AI in employment decisions apply before that use is approved.
- Personal data used with AI tools is handled in line with the requirements of CCPA and other applicable US state privacy laws, including the rights those laws give individuals over their personal data.
- AI systems and AI suppliers fall within the controls [Company] already runs as part of its SOC 2 program.
16. Raising Concerns
Any staff member, contractor, customer, or other person affected by [Company]'s use of AI may raise a concern about that use, including concerns about unfair, inaccurate, or unsafe AI output. Concerns should be sent to [AI concerns contact email] and will be acknowledged within 3 business days. Anyone who raises a concern in good faith will not be penalized for doing so.
17. Policy Review and Exceptions
This policy is reviewed at least once a year and updated as [Company]'s use of AI changes. Any exception to this policy must be approved in writing by the CTO or CEO before it takes effect.
Disclaimer
This document is provided for informational purposes only and does not constitute legal advice. It is provided "as is", without warranty of any kind, express or implied, and no liability is accepted for any loss or damage arising from its use. It is used at your own discretion. Review it with a qualified adviser before adopting it.