Your AI Policy Needs a Human’s Name On It
Writing the policy is the easy part. Nobody owning it is why it doesn’t work. This is not an AI problem. It’s an HR foundations problem that AI just made obvious.
The handbook test
You have a handbook. It says something about bereavement leave. Then an employee comes to you and says their step uncle passed away, except he was an uncle by marriage, and the grandparents divorced years ago. Does that qualify? Nobody reads that policy and sorts it out alone. They go find a person. And if there is no person, they guess. Or their manager guesses. And now two employees have gotten two different answers to the same question, which is how a documented policy quietly turns into an inconsistency problem. Every piece of foundational HR works this way. The PTO policy that lived in someone’s head. The offer letter that promised something you can’t legally deliver. The no-call-no-show with nothing written down. A document without an owner is just a file.
What that looks like with AI
Right now an account manager at your company has a client contract open and wants to summarize it. Somewhere in a Drive folder there’s a paragraph about responsible AI use. She cannot tell whether it covers this, and there is nobody she can ask. So she does one of two things. She doesn’t use the tool, and you lose the hour she would have saved. Or she uses it, doesn’t mention it, and client data is now sitting in a free consumer account you do not control and cannot audit.
The research says this is the normal outcome, not the edge case. SHRM’s State of AI in HR 2026 found that 49% of organizations have a policy regulating employee AI use, and only about a quarter of those believe their policy will hold up over time. Pacific AI’s governance survey found that at small companies, only about a third have anyone who owns AI governance, and just 9% monitor their AI for accuracy, drift, or misuse. And a KPMG and University of Melbourne global study found that 57% of employees who use AI at work have hidden that use or passed AI-generated work off as their own. That last number gets read as a trust problem. It usually isn’t. People hide it because nobody told them what the rules are and there is nobody safe to ask.
The fix is a name and a list
Step one: put one human’s name on it. One person. It can be you, your office manager, or the person in operations who’s already the unofficial AI nerd. Their job is not to know everything about AI. Their job is to be the answer to “hey, can I put this in there?” Then say the name out loud. In a meeting, in writing, somewhere people will actually see it. An owner nobody knows about is the same as no owner. They also need enough authority to say yes and no, and a standing check-in with you. You can’t hand someone accountability with no ability to decide anything.
Step two: hand that person a do-not-feed-it list. This is what keeps the owner from answering the same question forty times. Name the data that never goes into a public or free AI model. Social security numbers and personal identifiers. Health information. Compensation data. Performance and discipline notes. Anything client-confidential. Five lines, plain English. Your list may look different from mine, and that’s the point. Decide it once so nobody has to guess.
Then check it more often than you think
AI tools change faster than your handbook does. A 30-minute review once a quarter is the floor, and right now every 30 days is reasonable. Governance is not a document. It’s a policy, an owner, and a rhythm for checking it. That’s the whole definition. Worth knowing while you build it: employment-related AI law is moving. Illinois amended its Human Rights Act to cover AI in employment decisions effective January 2026. New York City has required bias audits for automated hiring tools since 2023. California has no AI statute, but its FEHA automated-decision-system regulations took effect in October 2025 and cover recruitment, hiring, and promotion. Colorado’s replacement AI act lands January 2027. Missouri, where I practice, has no AI-specific employment law. Over a dozen bills died in the 2026 session and the legislature doesn’t take it back up until January 2027. Your existing anti-discrimination obligations apply either way. If an AI screening tool produces a discriminatory outcome, you own it, law or no law.
This is the foundation, not the roof
Culture matters. But you can’t tell your team to use AI responsibly and call that a policy when there is nobody they can ask what responsible means. That’s the same thing as handing someone a company t-shirt while their paycheck is wrong. A named human and a short list. You can do both before lunch.
Not sure whether your people systems can hold up the AI rules you’re about to write? The free HR Audit will show you exactly where your gaps are in 5 minutes. saltandlightadvisors.com/hraudit
Resources to keep building:
Take the free HR Audit - Score your HR systems in 5 minutes and see exactly where your gaps are.
saltandlightadvisors.com/hraudit
Listen to Don’t Waste the Chaos - The podcast for small business owners building strong people operations. https://youtu.be/U4o-OQY0ExE?si=V-ecEQrHpdlnysDe
Get The HR Easy Button - Kerri’s book on building HR systems that actually work for small businesses.
Subscribe to the newsletter - Weekly HR insights for founders, in your inbox every Monday.
saltandlight.myflodesk.com/saltandlightadvisors
Need fractional HR support or want to talk through a specific challenge?
saltandlightadvisors.com/contact
Ready to build foundational HR systems on your own?