Almost every organisation with any AI ambition now has an AI policy. Far fewer have an AI policy that anyone follows. The gap between those two is where governance quietly fails, because a policy nobody reads or follows is not neutral. It is worse than having none, since it hands you false assurance: a document you can point to that changes nothing about what people actually do.
The good news is that policies do not get ignored out of defiance. They get ignored for mundane, fixable reasons. This post is about those reasons, and about how to build an AI policy that actually changes behaviour. It is the companion to how to write an AI policy, which covers what goes in the document; this one is about getting it followed.
Why AI policies get ignored
If your policy is being ignored, it is almost certainly one or more of these:
- It is unreadable. Ten pages of legalistic prose that nobody finishes, let alone remembers.
- Nobody can find it. It lives in a wiki or a shared drive that people visit once, at onboarding, and never again.
- It has no owner. So it goes stale, and a policy that is visibly out of date teaches people that the policy does not matter.
- It bans without offering an alternative. “Do not use ChatGPT” with no sanctioned way to get the same benefit just pushes the behaviour onto personal accounts, out of sight. That is shadow AI, and it is a policy failure, not just a user one.
- It has no teeth, in either direction. No consequence for ignoring it, and no support for following it. So following it is pure friction with no payoff.
Notice that none of these are solved by writing a better document. They are solved by treating the policy as a product that has to be adopted, not a text that has to be approved.
Write it for the reader, not the auditor
The first fix is the writing itself, but not in the way people assume. The goal is not completeness; it is usability. A policy that a busy person can read in five minutes and act on beats a comprehensive one they never open.
- Keep it short and plain. A page or two of plain language. If it reads like a contract, it will be treated like one: signed and ignored.
- Make it concrete. People do not need principles; they need to know what they can and cannot do. Give examples: this tool is approved for this, this data must never go into a public model, this kind of decision needs a human sign-off.
- Write for the doer. The audience is the person using AI in their job on a Tuesday, not the auditor reviewing you in six months. Serve the first and the second is satisfied anyway.
Make the compliant path the easy path
This is the single biggest lever, and the one most policies miss. People follow the path of least resistance. If the compliant path is harder than the workaround, they take the workaround, every time. So your job is to make the right thing the easy thing.
- Sanction, do not just ban. For each thing you want to restrict, provide an approved way to get the underlying value: an enterprise AI account with proper data controls, a vetted internal tool, a clear “yes, here is how.” Blanket prohibition without an alternative is how you manufacture shadow AI.
- Give clear green, amber and red. Most day-to-day questions are “can I use this AI for this?” Answer it up front with simple categories, so people are not left guessing (and guessing generously in their own favour).
- Reduce the friction of doing it right. If getting a tool approved takes three weeks and an email chain, people will not bother. Make the sanctioned route fast.
Put it where the work happens
A policy in a document repository is a policy at rest. To change behaviour it has to be where the behaviour happens.
- Bake it into onboarding and into the moment someone requests or adopts an AI tool.
- Surface it in the tools and workflows people use, not just once a year in a training slide.
- Tie it to AI literacy. People can only follow a policy they understand; the literacy work and the policy work are two halves of the same job. A rule someone does not understand is a rule they will misapply.
Give it an owner and a pulse
A policy is a living thing or a dead one; there is no in-between. Keeping it alive takes two things:
- A named owner with the authority to maintain it, handle exceptions, and act on it. Under ISO 42001, leadership owns the AI policy, and in practice a specific person keeps it current. A policy owned by “everyone” is owned by no one.
- A review pulse. A scheduled review every six to twelve months, plus an update whenever a significant new tool arrives, the law moves, or an incident happens. Feed what you learn back in, so the policy tracks what people are actually doing rather than what they were doing a year ago.
Enforce lightly, but really
Enforcement is where policies either become real or reveal themselves as theatre. The aim is not a compliance crackdown; it is credibility. A policy that is never enforced, even gently, is understood by everyone to be optional.
- Make consequences proportionate and consistent. Not draconian, but not absent. The point is that the policy is taken seriously, which mostly means it is applied the same way to everyone.
- Treat shadow AI as a signal, not just a sin. When you find people using unsanctioned tools, the first question is why the sanctioned path failed them. Often the policy, not the person, is what needs fixing.
Measure whether it is actually followed
You cannot manage adoption you do not measure, and attestation sheets do not measure adoption. Behaviour does. The real signals:
- Are people using the approved tools, or personal workarounds?
- Is shadow AI shrinking over time?
- Do teams actually consult the policy when they hit a grey area, and raise questions and incidents through the channels it defines?
High sanctioned-tool usage and falling shadow AI mean the policy is landing. A wall of signatures on a document nobody opens means it is not.
It is one part of a system
A policy that is followed is powerful, but it is not the whole of governance. It is one component of an AI Management System: the statement of intent that the inventory, risk process, controls, oversight and evidence make real. A policy without that machinery behind it is a promise with nothing enforcing it; the machinery without a clear, followed policy is activity with no direction. You need both, and the policy only earns its place if people actually live by it.
The short version
AI policies fail in the following, not the writing. They get ignored because they are unreadable, unfindable, unowned, and because they ban useful things without offering an alternative, so people route around them. Build one people follow by writing it short and concrete for the person doing the work, making the compliant path the easy path (sanction, do not just ban), putting it where the work happens, giving it a named owner and a review pulse, enforcing it lightly but genuinely, and measuring adoption by behaviour rather than signatures. Do that and the policy stops being a document you can point to and becomes a thing that actually shapes how your organisation uses AI, which was the entire point.
Want a policy that gets followed, inside a governance system that makes it stick? The AI governance guide covers the full picture, and our AI governance consulting builds the policy and the machinery behind it with you. For a quick read on where you stand, the free AI governance check takes about ten minutes, no email.
Frequently asked questions
Why do AI policies get ignored?
Usually for practical reasons, not defiance. The policy is too long and legalistic to read, it lives in a wiki nobody visits, it has no named owner so it goes stale, it bans useful tools without offering an alternative (so people route around it), and it carries no real consequences either way. People do not follow a document they have not read, cannot find, do not understand, or that makes their job harder with no upside. Fix those and adoption follows.
What makes an AI policy people actually follow?
Three things above all: it is short and readable (plain language, a page or two, written for the person doing the work rather than the auditor); it makes the compliant path the easy path (approved tools, clear green/amber/red guidance, and sanctioned alternatives instead of blanket bans); and it lives where the work happens (onboarding, the tools themselves, day-to-day workflows), with a named owner who keeps it current. A policy people follow is a usable tool, not a legal artefact filed and forgotten.
Should an AI policy ban tools like ChatGPT?
Rarely a blanket ban, because blanket bans mostly create shadow AI: people keep using the tool on personal accounts where you have no visibility or control. A better approach is to sanction an approved, safer way to get the same benefit (an enterprise account with data controls, a vetted internal tool), set clear rules for what data can and cannot go into it, and reserve outright prohibition for genuinely high-risk uses. Give people a compliant path to the value they want, and far fewer will go around you.
Who should own the AI policy?
A named person with the authority to keep it current and act on it, not a committee and not "everyone". Under ISO 42001, top management is accountable for the AI policy, and in practice a specific owner (an AI governance lead, or that duty assigned to an existing role) maintains it, reviews it, handles exceptions, and feeds incidents back into it. A policy with no owner is a policy nobody updates, and an out-of-date AI policy is worse than useless because people learn to ignore it.
How often should you review an AI policy?
On a set cadence and whenever something material changes. A common rhythm is a scheduled review every six to twelve months, plus an event-driven update when you adopt a significant new AI tool, when the law moves (as the EU AI Act and its timelines have), or after an incident. AI moves fast enough that an annual-only policy drifts out of date; the point is that the policy keeps pace with what your people are actually doing, so it stays credible enough to follow.
How do you know if your AI policy is working?
Look at behaviour, not sign-off sheets. The real signals are whether people are using the approved tools rather than personal workarounds, whether shadow AI is shrinking, whether teams actually consult the policy when they hit a grey area, and whether questions and incidents are being raised through the channels the policy defines. If usage of sanctioned tools is high and shadow AI is falling, the policy is landing. If everyone has attested to a document nobody uses, it is not.
Building something you need to govern?
Start with a fixed-scope AI Opportunity & Risk Audit.
Meet an Expert