← Back to Field Notes

July 13, 2026

Why your organization needs an AI use policy before it needs more AI tools

In my last post, I said AI readiness starts with your organization’s core values and your people, not with picking a tool. The first of those, mission-driven policy, deserves a much closer look, because it’s the piece organizations sometimes skip entirely or treat as an afterthought once the tools are already in place.

I chaired the committee that wrote my former school’s Ethical Use Policy for AI and technology. If there’s one thing that experience taught me, it’s that policy isn’t the paperwork you get to after the real work is done. Policy is the real work, and done right, it’s your organization’s mission translated into a set of decisions people can actually act on.

Many organizations have this in the wrong order. A staff member starts using an AI tool because it helps them get through the day faster. Word spreads. More people start using it, or using something else entirely, each making their own judgment calls about what’s appropriate to put into a chatbot and what isn’t. Nobody planned this rollout, and nobody checked any of it against what the organization actually stands for. It just happened, tool by tool, person by person, with no connection to mission at all.

Shadow use is happening whether you’ve noticed or not

If your organization hasn’t published anything about AI use, that doesn’t mean AI isn’t in use. It means it’s being used without guidance and without any ties to your values, which is a precarious situation. Staff are already deciding case by case what data is safe to share, which tools to trust, and how much to rely on the output. Every one of those decisions carries risk, and right now, nobody is checking them against a standard, because there isn’t one.

A policy doesn’t slow this down. It’s the only thing that brings it into the open, and the only way to make sure the decisions being made every day actually reflect what your organization cares about.

Governance is what makes adoption safe to speed up

This is the part that surprises people: a clear policy speeds adoption instead of gating it. Once my school’s policy was in place, staff stopped hesitating and second-guessing themselves. They knew what was in bounds, and just as importantly, they knew it reflected who we actually were as a school, not an arbitrary rule handed down from above. Uncertainty about whether something is allowed is a bigger barrier to adoption than any technical learning curve. Remove the uncertainty and connect it to something people already believe in, and they move faster, not slower.

The same logic applies outside education. A staff member who isn’t sure whether client data is safe to paste into a tool will either avoid the tool entirely, which slows the organization down, or use it anyway and hope for the best, which is a liability problem waiting to surface. Policy closes that gap, and a policy grounded in mission closes it in a way people actually buy into.

A mission-driven policy is built, not handed down

The version that actually works isn’t written in a back office and distributed as a memo. It’s built with input from the people who will actually live inside it: the staff using the tools day to day, the leadership accountable for outcomes, and anyone with compliance or data privacy responsibility. That process is where the mission-driven part actually happens. It’s not enough to reference your mission statement in the first paragraph and move on. The stakeholder sessions are where you find out what your values actually mean in practice: tool by tool and decision by decision.

Policy also needs to say something specific. A policy that says “use AI responsibly” tells staff nothing. A useful one names what data can and can’t go into which tools, who signs off on new tools before they’re adopted, and what happens when someone gets it wrong, all of it traceable back to why your organization exists in the first place.

The foundation for everything else

This is the first of the three things I wrote about in my last post: mission-driven policy, the right champion, and starting from real pain points. The other two only work if this one is solid. A champion can’t credibly vouch for a tool if there’s no policy backing them up, and pain-point discovery can turn into a free-for-all if there’s no framework deciding what’s actually allowed. Skip this step, and the other two are operating without a foundation.

If your organization is using AI tools without a policy governing them, or if the one you have doesn’t actually connect to what you stand for, that’s worth fixing before you add anything else. Let’s talk about what that process looks like.