Build the One-Pager: Drafting an AI Usage Policy Before an Incident Forces It
Objective: Given a messy list of the AI tools a marketing team already uses and the gaps in how they're governed, draft a one-page AI usage policy covering all six sections the lesson requires.
You're the marketing coordinator at Yatharth Hospital & Trauma Care Services, the NCR-and-UP hospital chain. Your team has adopted five AI tools this year for patient-facing campaign copy, none of them documented, and a regulator audit is scheduled in six weeks.
Turn the raw list of tools and gaps below into a working one-page policy using the lesson's six required sections.
Before you start
What you'll need
Free path (everything below is enough to finish)
Free, versioned, easy to route to a legal or privacy reviewer
The process
1 step
Step 01 of 01
The lesson defines six sections for a working policy: approved tools list, data classification, disclosure rules, vendor checklist, review cadence, and a named owner, and insists it must fit on one page or nobody reads it.
Given that two of the five tools in use have no signed DPA and nobody currently reviews AI-generated patient-facing copy before it publishes, which two sections of the policy need the strongest, most specific language, and which one hard gate stops both problems at once?
Procedure
- List the 5 current AI tools by name under 'Approved tools list', mark the 2 without a signed DPA as 'pending review, not yet approved for patient data'
- Write the data-classification rule naming patient PII and unreleased campaign pricing as never-paste categories
- Write the disclosure rule: any AI-assisted patient testimonial or before/after content gets a visible label before publish, no exceptions
- Add the vendor checklist hard gate: no new AI vendor connects to patient data without a signed DPA on file first
- Set review cadence to quarterly and name one accountable owner by role, not by name
Yatharth Hospital, AI Usage Policy (v1, one page) 1. Approved tools: [Tool A], [Tool B] (DPA on file). [Tool C], [Tool D] (pending review, DPA required before patient data use). 2. Data classification: never paste patient PII, unreleased pricing, or NDA content into any AI tool. 3. Disclosure: any AI-assisted patient testimonial or before/after image carries a visible label before publish. 4. Vendor checklist: no new AI vendor touches patient data without a signed DPA on file first. Hard gate, no exceptions. 5. Review cadence: quarterly, next review scheduled ahead of the regulator audit. 6. Owner: Marketing Compliance Lead.
Healthy
Every current tool is explicitly categorized as approved-with-DPA or pending, and the vendor hard gate is written as non-negotiable.
Unhealthy
A policy that lists tool names but leaves 'pending review' tools connected to real patient data while the review is pending.
What this means
The policy's value is the hard gate, not the document; a beautifully written policy that doesn't disconnect ungoverned data access hasn't fixed anything yet.
So what do I do about it?
| Symptom | Action | Effort |
|---|---|---|
| Two tools with patient-data access have no DPA on file, six weeks before an audit | Suspend patient-data access for both tools today; restore only once a signed DPA is on file | 30 min |
Final deliverable
A one-page AI usage policy with all six required sections, one explicit hard gate, and a named owner role.
See a reference example
Concord Biotech, AI Usage Policy (excerpt) 4. Vendor checklist: no new AI vendor connects to regulatory-filing or customer data without a signed DPA on file first. Current gap: ad-optimization vendor added in Q1 has no DPA, access suspended pending signature.
Success criteria
You're done when you can:
- All six required sections are present and specific to the given tool list
- The vendor DPA gap is written as a hard, non-negotiable gate rather than a soft suggestion