A one-page policy your team can actually follow: what may go into a general model, what never does, and who decides the grey cases. Drafted inside a regulated practice, so it holds anywhere confidentiality matters — in language the sign-off owner will approve and a busy team will actually read.
It's the first thing I hand a group, before any technique. Not because compliance is interesting, but because ambiguity is what stops people using the tool in the open. Quiet use is worse than no use.
Read the AI usage policy template →