[The AI Security Center ](/solutions/ai-security)[01 AI Insights ](/solutions/ai-security/insights)[02 AI Policy Toolkit ](/tools/ai-policy-generator)03 AI Risk Check

AI Governance

# Generate your free AI policy toolkit

Stop making employees guess what’s allowed. Generate an AI policy, checklist, and adoption guide your team can actually follow.

Generate your AI policy

### AI Policy Toolkit

Step of

3 mins to go

## What industry or sector is your organization in?

\[ ]

Finance

\[ ]

Health

\[ ]

Legal

\[ ]

Tech/SaaS

\[ ]

Retail

\[ ]

Gov/Public

\[ ]

Other

Your industry helps shape the policy considerations, data guidance, and rollout recommendations in your toolkit.

Your industry helps shape the policy considerations, data guidance, and rollout recommendations in your toolkit.

Continue

## Where does your organization primarily operate?

\[ ]

United States only

\[ ]

European Union or United Kingdom

\[ ]

Australia or New Zealand

\[ ]

Canada

\[ ]

Multiple regions, including Europe

\[ ]

Multiple regions, excluding Europe

Different privacy frameworks apply based on where your organization operates and the jurisdiction of your employees or customers.

Different privacy frameworks apply based on where your organization operates and the jurisdiction of your employees or customers.

Continue

## How many employees does your organization have?

\[ ]

Under 200

\[ ]

200–1,000

\[ ]

More than 1,000

Your organization's size affects how formal the governance structure needs to be — and how the policy is written.

Your organization's size affects how formal the governance structure needs to be — and how the policy is written.

Continue

## What types of data does your organization regularly handle?

Select all that apply.

\[ ]

Customer personal information names, emails, contact details

\[ ]

Employee personal information HR records

\[ ]

Financial records or transaction data

\[ ]

Health or medical information

\[ ]

Legal documents or privileged communications

\[ ]

Intellectual property or trade secrets

\[ ]

Government or classified information

\[ ]

Mostly public or non-sensitive information

Your current AI usage determines the optimal structure for your policy. This determines what data can and cannot go into AI tools.

Your current AI usage determines the optimal structure for your policy. This determines what data can and cannot go into AI tools.

Continue

## How do you currently approach AI in your organization?

\[ ]

Starting fresh We have no AI tools in active use, we’re creating our policy from scratch.

\[ ]

Controlled rollout A few approved tools are in use with some oversight.

\[ ]

Informal adoption Employees are using AI tools without formal approval — no policy exists yet.

\[ ]

Mixed environment We have some approved tools and informal Shadow AI use happening simultaneously.

\[ ]

Policy refresh We have an existing AI policy but it needs updating.

How your policy is framed depends heavily on where you're starting from. An organization with widespread informal AI use needs a different approach — including a transition period — than one starting from scratch.

How your policy is framed depends heavily on where you're starting from. An organization with widespread informal AI use needs a different approach — including a transition period — than one starting from scratch.

Continue

## What are your employees primarily using AI for?

Select all that apply.

\[ ]

Writing and content creation emails, reports, proposals, meeting notes, wikis

\[ ]

HR processes hiring, performance, onboarding

\[ ]

Coding and software development

\[ ]

Customer communications and support

\[ ]

Data analysis and summarisation

\[ ]

Legal or compliance document review

\[ ]

Financial modeling or reporting

The best AI policies are written for how your team actually works — not for a generic company. Your answers determine which use cases are specifically addressed in your policy.

The best AI policies are written for how your team actually works — not for a generic company. Your answers determine which use cases are specifically addressed in your policy.

Continue

## How do you currently manage new software and tool approvals?

\[ ]

No process Employees use what they want.

\[ ]

Informal Employees generally use what they need, IT is notified occasionally.

\[ ]

Semi-formal Managers can approve low-cost tools, IT reviews anything with data access.

\[ ]

Formal All new tools go through IT security review before use.

Your existing procurement process determines how your AI tool approval workflow should be structured — we'll build a process that fits your current operating model.

Your existing procurement process determines how your AI tool approval workflow should be structured — we'll build a process that fits your current operating model.

Continue

## We recommend a balanced AI risk posture for your organisation

You can adjust below if you feel another posture is better suited.

\[ ]

Open

* Approved list as recommendation, not mandate.
* Self-disclosure within 5 days.
* Education-first response to violations.

\[ ]

Balanced

* Approved list with 3-day fast-track process.
* Human review for high-stakes AI output.
* Anomaly-based monitoring, not surveillance.

\[ ]

Strict

* Default deny — only listed tools permitted.
* All customer-facing AI requires sign-off.
* Active logging of all AI tool usage.

Generate my policy

How it works

## From blank page to policy starting point.

* ### Answer 8 Questions

  Tell us about your organization, AI usage, data types, and approval process.

* ### Preview Your AI Toolkit

  See a tailored sample policy draft based on your answers.

* ### Get your AI toolkit

  Enter your work email to receive your full AI Policy Toolkit.

What’s inside the toolkit

## A sample policy, checklist, and rollout guide your team can review, adapt and use.

## AI Policy (Sample)

A structured policy starting point tailored to your organization, data profile, and AI usage.

## Workforce Adoption Guide

Plain-English guidance to help employees understand what’s allowed, what needs review, and what should be avoided.

## Implementation Checklist

A review guide to help your team pressure-test the policy before rollout.

Put your policy into practice

[Turn policy into action](https://www.upguard.com/tour)
