New noteWhat changes on January 1, 2027
Solidare AI — Technology built on solidarity

Policy · July 14, 2026

The one-page AI use policy: what's in it and why it's one page

The policies that get followed are the ones people can remember. Here is the structure we give every client, section by section.

By Solidare AI · 3 min read

Most AI policies we are shown are eleven pages long and were written by a lawyer for another lawyer. They are accurate and unread. The policy that changes behavior is one page on the wall, with a longer document behind it that a regulator, an auditor or a trustee can inspect. Both matter. Only one of them has to be memorable.

The eight sections

Purpose. One sentence on what AI is for here: taking repetitive work off people's plates while protecting the people whose records we hold. Approved tools. Named, with where to sign in. If it is not on the list, it is not approved. What never goes in. Anything that names a person; anything marked confidential; anything you would not email to a stranger. Human review. A person approves anything that touches a member, an employee, a patient or a dollar, and anything that goes out under our name. Disclosure. We tell people when AI helped, in plain language, before it affects them. New tools. Ask before you add one; here is the form and who answers it. If something goes wrong. Who to tell, today, no blame. Review. We revisit this every twelve months and whenever the law changes.

The card

The card is the policy at its shortest: the approved tools, the never-list, the human-review rule and the name of the person to call. It sits on desks, in the break room and inside the LMS. Instructors and office staff read cards. Nobody reads page seven.

What sits behind it

The longer document maps each section to the structure of NIST AI RMF 1.0 and the generative-AI profile, and to the management-system pattern in ISO/IEC 42001, so you can show the lineage if asked and pursue certification later without starting over. It carries the roles (who owns the policy, who approves tools, who handles incidents), the intake form, the review calendar, and the record of every decision. Anything touching workers follows the Future of Privacy Forum's best practices for AI in hiring and employment and is consistent with the AFL-CIO's Workers First principles.

How it gets adopted

A policy is adopted in the briefing, not in the signing. Twenty minutes with staff: here is what we are worried about, here is the card, here is the approved tool signed in on your screen, here are the three things people ask. Then the same twenty minutes with the board or the trustees, with the record behind it. Three weeks, start to finish, is normal.

Share this note

Forward the link, or email it to the person who should read it: send by email.

Next step

Want this applied to your organization?

Thirty minutes with the people who do the work. We’ll say what fits first, including "not yet."

NO SALES DECK · NO OBLIGATION · ASK@SOLIDARE.AI