A Multiverse Ventures Inc. project Call us: 250-709-5968

When a client asks who approved your AI, what will you say?

Your team is already using AI tools, approved or not. Build a plain-English AI use policy for your business in about five minutes. Print it, sign it, and have the answer on file.

Free. Two pages. Written for owners, not IT departments.

You already have an AI rollout. Nobody held a meeting about it.

Staff use AI to write emails, summarize calls and clean up spreadsheets. That's mostly good. The trouble starts when someone outside the business asks how it's controlled.

Personal accounts, company data

Free AI accounts can keep what's typed into them and may use it for training. If client details went in, you can't easily get them back.

Tools that act, not just write

A draft is harmless until someone sends it. Tools that can email customers, post online, issue refunds or change records need a named person and a human approval step.

Hidden instructions in plain sight

An AI that reads incoming email or web forms can be steered by text hidden inside them. There's no perfect filter, so the fix is limiting what the AI can reach and do.

What's in your policy

Every section is filled in from your answers: your tools, your data, your people. No blanks to puzzle over.

  1. Purpose and who it coverseveryone, every device
  2. Approved AI tool registertool, access, named owner
  3. Account rulesbusiness accounts only
  4. What data can and can't go inbased on what you handle
  5. Permission levels and human approvalfor send, post, pay, change
  6. Vendor settings checktraining, retention, sharing
  7. Prompt injection in plain Englishfive-minute staff briefing
  8. Mistakes, incidents and accountabilitywho to tell, how fast
  9. Review schedule and sign-offowner and employee signatures

Build your AI policy

Four short steps. Answer what you know; "not sure" is a fine answer and the policy will tell you what to check.

  1. 1Your business
  2. 2Your AI tools
  3. 3Data and actions
  4. 4Who's in charge

Your business

This goes on the policy header so it's ready to sign.

Your AI tools

Check everything anyone on the team uses for work, even occasionally, even on their phone.

Which AI tools get used for work? *
What kind of accounts are people using? *
Data and actions

This decides the data rules and which actions need a human sign-off.

What sensitive information does your business handle? Even if it hasn't gone near an AI tool yet.
What can any of your AI tools do, or what would you like them to do? Leave all unchecked if AI only writes drafts that a person copies and uses.
Has anyone checked the privacy settings inside your AI accounts? * Things like "use my data for training," how long chats are kept, and sharing defaults.
Who's in charge

A policy with no named person is a wish list. Pick real people.

Keeps the tool list current and approves new tools.
Sending to customers, publishing, payments.
Review it, adjust anything that doesn't fit, then sign.

A policy on paper is step one. Does your setup match it?

A short AI audit checks your real account settings, connections and permissions against this policy, and gives you a fix list in plain English.

Book a free AI risk review

Questions

Is it really free?

Yes. You get the full policy on screen to print, save or copy. If you'd like help putting it into practice, you can ask for a free review call, and that's entirely optional.

We're a small team. Do we actually need this?

If anyone uses AI for work, yes. The question you'll eventually get from a client, insurer or regulator is simple: who approved this tool, and what can it reach? Two signed pages answer that.

Is this legal advice?

No. It's a practical starting template based on your answers and common good practice. Privacy and employment rules vary by province, state and industry, so have it reviewed by your advisor before relying on it.

Do you use AI to write my policy? Where do my answers go?

The policy is assembled in your browser from a template based on your answers. Nothing you type is sent to an AI model. Your contact details and answers are saved so we can follow up; see the privacy notice for details.

What's a "human approval step"?

Before an AI tool sends, posts, pays or changes anything that can't easily be undone, a named person reviews the exact message or transaction and says yes. Not a summary of it, the real thing.

What happens on a free AI risk review?

A 20-minute call. We walk through your tool list and account settings, flag anything that doesn't match your policy, and tell you what to fix first. If you want help fixing it, we can talk about that. If not, you keep the list.

Contact us

Questions about your policy, or want a hand putting it into practice? Reach us directly.

Company
Multiverse Ventures Inc.
Phone
250-709-5968
Email
hello@policyfirstai.com
Book a call
Free 20-minute AI risk review