How to Write a Short AI Charter That Teams Actually Follow
A short AI charter provides teams with a simple framework to use artificial intelligence tools without stifling initiative, exposing sensitive data, or producing unverifiable deliverables.

A short AI charter provides teams with a simple framework to use artificial intelligence tools without stifling initiative, exposing sensitive data, or producing unverifiable deliverables.
A short AI charter isn’t meant to cover everything. It provides teams with a simple framework to use artificial intelligence tools without stifling initiative, exposing sensitive data, or producing unverifiable deliverables.
In an SME or scale-up, the right document isn't the one that impresses the executive committee. It is the one a sales representative, recruiter, product manager, or developer can apply on a Tuesday morning between two tasks. The goal is therefore to write less, but decide clearly.
Teams are already using AI, sometimes without saying so. They summarize meeting notes, rephrase emails, brainstorm content ideas, analyze data exports, or ask for help with code. If a company waits six months to publish a 30-page policy, habits will have already set in.
An overly long charter creates three problems. It is rarely read, it conflates practical rules with complex legal issues, and it gives the impression that AI is a risk to avoid rather than a tool to manage. A short charter works better because it reduces ambiguity at the moment of action.
The ideal format often fits on one or two pages. It answers four practical questions: what can be done, what must never be done, when is approval required, and who decides in case of doubt. The rest can live in companion documents, such as a GDPR procedure, a security policy, or a registry of approved tools.
A short AI charter should be written like a user guide, not an internal rulebook. Each rule must help someone decide quickly: Can I paste this file into an AI tool? Can I send this text to the client? Can I automate this step without human review?
If a sentence doesn't change an operational decision, it probably has no place in the first version.
Before drafting, bring together three profiles: an operational team member who knows actual use cases, someone responsible for data or security, and a decision-maker from management. The group doesn't need to produce an exhaustive policy. It needs to make a few non-negotiable decisions.
Question to settle | Expected decision | Short example wording |
|---|---|---|
Which use cases are permitted? | List tasks accepted without prior approval | We can use AI to prepare, rephrase, summarize, and explore ideas. |
Which data is prohibited? | Define data that must never be entered | No personal customer data, sensitive HR data, or confidential information may be copied into an unapproved tool. |
Who validates deliverables? | Mandate human review | Any output intended for a client, candidate, partner, or public use must be reviewed by a responsible human. |
Which tools should be used? | Restrict tools to approved solutions | Teams only use company-approved tools for professional purposes. |
What to do in case of doubt? | Establish an escalation reflex | In case of uncertainty about data, a use case, or a tool, the team requests approval before use. |
This table can serve as the backbone for the final document. It forces useful choices and avoids turning the charter into a general manifesto on artificial intelligence.
An internal charter is no substitute for legal analysis. In Europe, the Artificial Intelligence Act sets obligations based on risk levels and the nature of the systems used. The CNIL also points out that the GDPR applies whenever personal data is processed, including through AI tools.
For a small business or scale-up, the charter must bridge the gap between compliance and everyday work. It doesn't need to explain the entire AI Act, but it must prevent obvious mistakes: copying personal data into an unapproved tool, publishing generated content without verification, or automating an important decision without human oversight.
A short AI charter is easier to write if you build on stable components. Each block should contain a rule, a rationale, and an example. That is enough to be understood without legal training.
Start by explaining why the company authorizes AI. A good formulation avoids two extremes: magical thinking where AI transforms everything, and a defensive tone where every use case seems dangerous.
Example: We use AI to save time, improve the quality of specific deliverables, explore options faster, and automate repetitive tasks. AI assists teams; it does not replace their professional responsibility.
This sentence establishes a sound framework: the tool assists, but the user remains accountable.
List simple, frequent, and low-risk use cases. In most organizations, this includes rephrasing, summarizing, research assistance, drafting outlines, analyzing non-sensitive documents, and generating first drafts.
The trap is trying to anticipate everything. Favor clear categories instead. For example: drafting assistance, analysis assistance, organization assistance, automation assistance. These categories will outlive specific tool names or features.
A useful charter must say no. Teams primarily want to know where the boundary lies. Prohibit use cases that expose the company to disproportionate risk: automated HR decisions, scoring clients or candidates without human oversight, generating unreviewed legal or financial advice, or processing sensitive data in an unapproved tool.
For gray areas, use the formula "subject to approval." This prevents blocking experimentation while maintaining a control point.
This is the core of the charter. Many mistakes stem from confusion between public data, internal data, and confidential data. A simple rule is often enough: the more sensitive the data, the less it should leave the company's controlled environment.
You can classify data into three levels. Public: already published content, sales collateral, information accessible to everyone. Internal: procedures, meeting notes, working documents without sensitive data. Confidential: customer data, HR data, contracts, proprietary code, non-public financial figures, and trade secrets.
Human review must be stated in black and white. Any AI output can contain errors, approximations, or overly confident formulations. The charter must therefore specify that the user verifies facts, adapts the tone, checks sources, and takes responsibility for the final deliverable.
This rule is especially critical for external communications, decision-making analyses, code, legal content, sales collateral, and HR messaging. If the output commits the company, it must be reviewed.
Even a short charter needs an owner. Designate an individual or small group responsible for maintaining the list of approved tools, answering questions, and updating the charter. Without an identified owner, the document quickly becomes outdated.
As your organization grows, you can formalize roles in greater detail. A dedicated article on how to clarify AI roles, governance, and responsibilities can help when use cases become cross-functional.

The following template can be adapted in a workshop. It is deliberately direct, because a charter should not sound like a legal memo. Replace the examples with your own tools, data, and approval channels.
Section | Target length | What it must contain |
|---|---|---|
Purpose | 3 to 5 lines | Why the company uses AI and what role humans retain |
Permitted uses | 5 to 8 lines | Categories of accepted tasks and concrete examples |
Prohibited data | 5 to 8 lines | Types of data never to enter into unapproved tools |
Uses subject to approval | 5 to 8 lines | Cases requiring approval from a manager, an AI lead, or a security officer |
Human review | 3 to 5 lines | Responsibility to verify prior to release or decision-making |
Tools and support | 3 to 5 lines | List of approved tools, inquiry channel, and update frequency |
Purpose: We use AI to speed up specific tasks, improve the quality of our deliverables, and automate what can be automated without lowering our standards.
Responsibility: AI assists teams, but each team member remains responsible for what they produce, share, or decide based on an AI output.
Permitted uses: Teams may use AI to rephrase, summarize, outline plans, explore ideas, analyze non-sensitive information, and create initial document drafts.
Prohibited data: Personal data, confidential customer information, sensitive HR data, contracts, technical access credentials, trade secrets, and non-public numbers must not be entered into unapproved tools.
Validation: Any production intended for a client, candidate, partner, or external publication must be reviewed and approved by a qualified person.
Tools: Professional work must be done using company-approved tools. Any new tool must be approved before being used with internal data.
Doubt: In case of uncertainty regarding a use case, data, or generated output, the team requests approval before proceeding.
This foundation fits on one page. It can be supplemented with a more detailed appendix for teams handling sensitive data, developing automations, or integrating AI into a product.
Drafting represents only half the work. A short AI charter only has an impact if it becomes an instinct across teams. To achieve this, avoid a formal rollout followed by collective neglect. Instead, favor short, recurring routines.
Before publishing the charter, ask teams how they are already using AI. You will often uncover useful yet unmanaged use cases: drafting sales proposals, analyzing support tickets, screening applicants, summarizing meetings, or generating scripts.
This discussion is also the ideal moment to identify risk areas. If you are unsure how to approach the topic, you can draw on a methodology for team AI discussions around tools and rules. The charter will be far better accepted if it addresses real cases rather than abstract assumptions.
A rule alone is rarely sufficient. Add examples by team. For sales: do not paste an entire CRM into an unapproved tool. For HR: do not ask an AI to rank candidates without controlled criteria. For product: do not merge suggested code without a review. For marketing: verify facts, sources, and claims before publishing.
These examples do not necessarily need to lengthen the main charter. They can live in a Notion page, an internal knowledge base, or training materials.
A 60- to 90-minute session is often enough to introduce the charter, present permitted use cases, and practice the right reflexes. Training should stem from actual tasks, not trending features. Employees should leave with prompt examples, clear data guidelines, and a verification habit.
If you structure this upskilling, an operational AI training plan for teams helps bridge the gap between curiosity and reliable usage. The charter then becomes an adoption driver, not a forgotten compliance document.
Some charters fail not because they are inaccurate, but because they do not match the company's operating tempo. Teams need fast decisions, not a document requiring interpretation for every single sentence.
Common mistake | Impact on teams | Simple fix |
|---|---|---|
Using overly legalistic language | Employees do not read it or ask for an exception for every task | Rewrite into concrete action rules |
Prohibiting without providing alternatives | Shadow AI continues informally | Offer approved tools and permitted use cases |
Listing too many tools | The charter becomes obsolete within months | Maintain the tool list in a separate appendix |
Overlooking data rules | The primary risks remain unaddressed | Classify data into public, internal, and confidential |
Failing to designate an owner | Nobody updates the rules | Appoint an AI point person or a small committee |
The best test is to hand the charter to someone who was not involved in drafting it. If they can explain in two minutes what they are allowed to do, what they must not do, and who to contact in case of doubt, the document is ready.
The charter is sufficient to guide individual usage and early experiments. It is no longer enough once AI is embedded into a critical process, a core business automation, or a customer-facing product.
In such cases, it must be supplemented with a more robust framework: business objectives, data mapping, risk analysis, performance benchmarks, human oversight, logging, and a maintenance plan. This is especially true for tools that influence significant HR, commercial, financial, medical, legal, or operational decisions.
The rule is simple: the more directly AI acts on a process, the more formal the governance must be. The charter remains the cultural foundation, but it must be tied to project procedures, audits, and technical validations.
Does an AI charter need to be approved by a lawyer? Not necessarily for an initial operational version, but a legal review is recommended if you handle sensitive data, use AI in high-stakes decisions, or operate in a regulated industry.
What length should you target for a short AI charter? One to two pages are sufficient for shared rules. Role-specific details, tool lists, and security procedures can be placed in an appendix.
Should free AI tools be banned? Not automatically. The key questions are what data is entered into them, what contractual guarantees exist, and whether the tool is approved for professional use.
Who should own the charter in an SME? Ownership can come from leadership, operations, IT management, or an AI lead. What matters most is having an identified person who is accessible and empowered to update the rules.
How often should the charter be updated? A quarterly review is a good cadence at the beginning. Afterward, an update can be triggered by the introduction of a new tool, an incident, a regulatory change, or a new use case.
A good charter does not block AI usage. It gives teams the confidence needed to move forward without improvising on data, tools, and human oversight.
Impulse Lab supports SMEs and scale-ups with AI audits, training programs, and custom web and AI development tailored to their workflows. If you want to identify the right use cases, establish clear rules, and turn AI into tangible productivity gains, connect with our team via Impulse Lab.
Our team of experts will respond promptly to understand your needs and recommend the best solution.
Got questions? We've got answers.

Leonard
Co-founder