Plenty of companies have an AI policy now, and the instinct is right: a policy that works is what lets a team use AI freely instead of guessing. A document exists, it was circulated, someone signed off. On paper, the box is checked. Yet ask around a few months later and you find the same thing almost everywhere: the policy is real, and nobody is following it.
The striking part is how identical the failure looks from one company to the next. AI policies don't fail in a hundred creative ways. They fail in about four, and they fail together.
The four ways it goes quiet
No one owns it. The policy was written, but ownership was never assigned. So when a genuinely new question comes up, and they always do, there's no one whose job it is to answer. The document can't update itself, and nobody else is going to.
It's too abstract to use. "Use AI responsibly and protect sensitive data" is fine as a sentiment and useless as an instruction. The person on a deadline, holding a specific document, can't tell from that whether this counts as sensitive. The policy speaks in principles; the work happens in specifics.
There's no classification under it. Almost every AI policy depends on a quiet assumption that people know which data is which. Most companies have never given them a way to know. Without a simple, shared traffic-light call anyone can make in the moment (green is fine, yellow needs care, red stays out), "don't put sensitive data into AI tools" is a rule pointing at a category no one has defined.
Nobody checks. A policy with no monitoring is a policy on the honour system, and the honour system erodes the first time following it is slower than ignoring it. If no one ever looks, the rule effectively doesn't exist.
The 2025 numbers track this exactly. Three-quarters of organizations have an AI usage policy. But far fewer have an owner, a response plan, or any monitoring behind it. The policy is the easy part to produce and the part most likely to stand alone.
Why a dead policy is worse than none
A company with no policy at least knows it has a gap. A company with a policy nobody follows has something more dangerous: the belief that the gap is closed. That belief shapes behaviour. People move faster and share more because they assume the document on the shared drive is doing its job, when the document is doing nothing at all.
You can see the result in how employees experience it. WalkMe's 2025 survey found 51% get conflicting guidance on how to use AI. Many of those companies have a policy. It's just that the policy and the daily reality have drifted apart, and nobody noticed because nobody was watching the gap.
What separates a policy from a paragraph
A policy that works isn't longer or more lawyerly. It has the parts the failed ones skip: a named owner, language concrete enough to act on, a traffic-light classification underneath it, and someone actually checking. Those are the load-bearing pieces, exactly the ones a quick copy-paste template leaves out, and exactly what we build when we build a governance system: a document set your team owns and runs without us.
Before you write or rewrite anything, find out which of those pieces you currently have. The AI Readiness Assessment shows you where your policy stands against the things that make one hold, in about two minutes.
A policy isn't the moment you write it down. It's the moment people start making decisions because of it.
Keep reading
Part of a series on AI governance, the structure underneath the tools.
- The 4 Stages of AI Governance Maturity. Where a policy that works sits on the larger ladder.
- Who Owns AI at Your Company?. The missing owner behind most dead policies.