Lakshmikumaran and Sridharan logo
Salient Features Your AI Usage Policy Should Have

Salient Features Your AI Usage Policy Should Have

Subhomoy Bakshi, Head of Digital Transformation

20 Sept 2025Updated 12 Jul 20266 min read

In brief

Governance principles are written for the board. An AI usage policy is written for the employee who, under deadline, is deciding whether to paste a client contract into a public chatbot.

Governance principles are written for the board. An AI usage policy is written for the employee who, at four in the afternoon and under deadline, is deciding whether to paste a client contract into a public chatbot. That gap is where most AI risk actually lives. A company can hold the right convictions about fairness, transparency, and accountability and still be undone by a single unguided act at a desk. The policy is the document that carries those convictions the last few feet, from the framework to the keyboard. A good one is specific enough to answer the question the employee is actually asking, and short enough that they read it before they act rather than after.

Purpose and scope. Begin by saying plainly why the policy exists and whom it binds. The purpose is to ensure that AI is used responsibly and lawfully; the reach should extend to every employee, contractor, and third party who touches the company's AI systems, and to every tool, whether built in-house or bought from a vendor. Employees improvise most where the boundary is vague, so name it. A policy that applies to "our AI" and stays silent on the free browser tool someone found last week has already left its largest opening unaddressed.

Ethical principles and compliance. The policy should restate the ethical commitments the organisation has adopted, translated from aspiration into instruction. Fairness means that AI outputs affecting people, in hiring, lending, or similar decisions, are reviewed for bias before they are relied upon. Transparency means that a person subject to a significant automated decision is told, and that employees can document and explain how an AI-driven output was reached. Accountability means that no one may hide behind the machine: the person who deploys or uses a tool answers for how it is used and for what its output does. Many organisations formalise this by naming an owner, or steward, for each AI system, responsible for its performance and its compliance. Compliance itself belongs here as a floor, not a footnote: AI must be used within all applicable laws, from data protection to intellectual property to any sector-specific guidance.

Data usage and security. Because almost every AI use involves data, the policy has to govern data directly. On privacy, the rule should track the company's obligations under the applicable regime, whether the DPDP Act in India or the GDPR abroad: personal data used with AI systems follows the privacy policy, and is anonymised or aggregated wherever feasible before it enters a model. That single line prevents a great deal of thoughtless copying of raw customer records into whatever tool is at hand. On security, sensitive data used for AI should be stored under controlled access, and any cloud-based AI service should meet the company's security standards before it is trusted with real data. The clause that earns its place most often is the simplest: no confidential or proprietary data goes into an external AI tool without approval, because an online service can absorb what it is shown. On governance, require that training data be vetted for quality and bias before a model is deployed, and that projects engage the data governance function where one exists.

Approved and prohibited uses. Employees calibrate to examples faster than to abstractions, so give them both. List uses the company encourages, such as customer-service assistants, analytics for forecasting, or internal document review, so the default reads as permission rather than suspicion. Then draw the hard lines. Prohibit any use that breaks the law or the company's values: AI for unlawful surveillance, for deepfakes or misinformation, for discrimination in decisions about people. Prohibit private exploitation of company data, such as an employee mining internal records with an AI tool and selling what it yields. Where the company is not yet ready for a high-risk application, fully autonomous decisions in a critical function without human review, for instance, say so rather than leaving it to be discovered.

Human oversight. Define where a human must stand in the loop, and when. Outputs that reach external stakeholders, customers, partners, regulators, should be reviewed and approved by a person before release. Recommendations above a set risk threshold should be vetted before anyone acts on them. Some policies fix an explicit trigger: any AI decision with legal or financial implications above, say, Rs 50 lakh must be escalated for human approval. The figure matters less than the discipline of naming one, because a stated threshold is what stops an unattended system from sending an erroneous communication or executing a transaction no one chose to authorise.

Monitoring, audit, and maintenance. An AI deployment is not fire-and-forget, and the policy should refuse to treat it that way. Every production model needs a named owner who watches its performance and checks it for bias and error at a stated cadence, with a periodic audit of each system for compliance and effectiveness. Models drift as the world they were trained on moves, so build in procedures to retrain or update when accuracy degrades, and route any material change, a new data source, a significant algorithm revision, through a re-approval step. This is close to a small development lifecycle for AI, with checkpoints for risk, and in regulated sectors such as banking it is what lets the company show a regulator the documented history the regulator will ask for.

Incident reporting. Tell employees exactly what to do when something goes wrong. If a model produces a harmful or suspect result, or someone suspects misuse, there should be an unmistakable path to report it, to a risk committee or an internal channel, and a summary of what the response involves: suspending the system if needed, informing anyone affected by an error that reached them, and investigating the root cause. The aim is a culture in which people surface problems rather than bury them, which happens only when reporting is safe and the route is known in advance.

Training and awareness. A policy no one has read governs nothing. Mandate that relevant staff be trained on it and on responsible AI use, as part of onboarding for technical roles and through periodic refreshers for everyone else. Because the field moves quickly, set a review cycle, annually is a reasonable default, so both the policy and the people held to it keep pace with new external requirements.

Governance and exceptions. Name the owner of the policy, whether an AI governance committee or the Chief Risk Officer, and state how it is enforced, with violations referred to the ordinary disciplinary process. Then, deliberately, provide a way to say yes. A team with a defensible reason to depart from the letter of the policy, an experimental pilot, perhaps, should have a route to seek approval, so the document guides rather than freezes. Those exceptions should be rare and well justified, but a policy with no exceptions process invites the quiet workarounds that are far harder to see.

An AI usage policy is an act of foresight: an attempt to anticipate how people will use and misuse a fast-moving tool, and to set guardrails before the misuse happens rather than after. It works best when leadership models the behaviour it asks for and does not press teams to cut the corners the policy forbids. And it is never finished. As the law develops and the company's own experience deepens, the policy should be revisited and revised: a living document that evolves alongside the technology it governs.

Internal policy sets the standard the company holds itself to. External law sets the standard it will be held to regardless. The next piece turns to the statutes and regulations that enterprises in India and abroad should keep in view: the acts and laws to keep in mind before implementing AI.