ai-usage-policy
Installation
SKILL.md
AI Usage Policy Skill
Most corporate AI policies fail in one of two ways: a fearful ban everyone quietly ignores (shadow AI, zero visibility), or legal fog nobody can apply to the question they actually have — "can I paste this customer email into Claude?" This skill writes the policy as a decision aid: one page, answerable in the moment of use, with the reasoning logged separately for counsel.
What This Skill Produces
- A one-page policy: approved tools, the data traffic-light, disclosure duties, review obligations, and how to get a tool approved
- A decision log: the reasoning behind each rule, for legal/leadership review
- A rollout note: how the policy lands without becoming shelfware
Required Inputs
Ask for (if not already provided):
- The org: size, industry, regulatory exposure (health, finance, gov contracts change the answers)
- Current reality: which AI tools are already in use — officially and (honestly) unofficially
- Data landscape: what sensitive classes exist (customer PII, PHI, source code, financials, client-confidential)
- Enterprise agreements in place: which tools have zero-retention/no-training terms signed vs consumer accounts
- Risk appetite: enable-with-guardrails or restrict-hard? (Get the sponsor's one-word answer.)