Enterprises adopt AI tools faster than they write rules for them. Marketing spins up consumer chat accounts. Engineers paste code into public models. HR tests CV screeners. Meanwhile legal and risk are asked for “an AI policy by next board” with no inventory of systems, data flows, or decision rights.
Copied templates fail. A policy borrowed from another industry ignores your regulators, data residency, labour rules, and vendor landscape. Overly vague policies create false comfort. Overly rigid policies drive shadow IT. Neither helps auditors or employees know what is allowed tomorrow morning.
Maintenance is the second failure. Policies are published as PDFs and forgotten. Model vendors change terms. New use cases appear in procurement and customer service. Without owners, review cadence, and linkage to exceptions, the document becomes shelfware while real decisions happen in Slack.
Risk and legal co-own normative language; IT owns the tool inventory; business owners own use-case risk tiers; HR owns employee acknowledgement. Anti-patterns include a one-page “be careful” memo, policies that ban tools without naming sanctioned alternatives, and drafting prose before anyone knows which systems already touch customer data.
AI-assisted policy drafting accelerates first versions and revisions — but only inside a consulting-led process: inventory, risk tiers, RACI, exception paths, and acknowledgement workflows. The artefact must be operable, not merely eloquent.