Free tool · No sign-up

AI Policy Builder.

A policy is only useful if it says what your organisation actually does. Answer the sections below and the builder assembles them into a structured AI use policy — the same shape our studio hands over with a done-for-you build — that you can copy, download, and take to review.

Approved AI use cases

Anything not listed here is out of scope until it is reviewed.

Data classes in scope

Declare what the models may and may not see.

Approval and accountability gates

Who has to say yes, and when.

Prohibited uses

Silence is read as permission — state the bans.

Frameworks you must evidence

The ones customers will ask you to prove.

What to do with it

A drafted policy is the start, not the control.

Take the document to your security and legal reviewers, correct what does not match reality, and publish the version you are willing to be held to. A policy nobody can evidence is worse than none, because it becomes the thing you are measured against.

Most of the gates this builder asks about need something engineered behind them: an allow-listed tool surface, a redaction layer, append-only audit, scoped credentials. If your policy promises controls you do not have yet, send the studio your technical specs or run the security scan to see how far the current build is from the document.

Score the policy you already have