There Is No AI Work Product
The first thing every leader asks is what their AI policy should be. The whole answer fits in one sentence, and it moves accountability to exactly one place.
The first thing almost everyone asks me is a version of the same question. What should our AI policy be? They are bracing for a long document, a committee, a quarter of legal review before anyone is allowed to touch a tool.
Here is the whole thing in one sentence.
There is no such thing as an AI work product. There is only AI-assisted human work product.
It does not matter who drafted it
Read that again, because it decides everything else. The person whose name is on the work owns all of it. Every fact, every number, every claim. It does not matter whether they wrote it, a colleague wrote it, or a chatbot wrote it. The author of record is accountable, completely, for what they hand over.
The fear that melts
This is the part that moves mountains. The moment accountability sits with the human, the fears that freeze companies lose their grip. Hallucinations. Uneven quality. A confident, fluent, wrong answer. None of these are new. They are the ordinary hazards of any first draft from any source, and you already know how to handle them, because you read the work before it leaves your hands.
A chatbot is a fast, tireless, sometimes-wrong colleague. You would not send a junior analyst’s memo to the board unread. Treat the machine’s output the same way, and suddenly you can use it for far more, far faster, because you are the backstop, and you always were.
Two tiers of data
Everything else is logistics. Most of what people call an AI policy is really a data policy, so keep it simple enough to hold in your head. The sensitivity of the information decides the environment it is allowed to enter.
Tier 1 is confidential: unpublished results, program data, patient information, anything not yet public. It goes only into contracted, enterprise-secure environments you have approved for that class of data. Tier 2 is open: anything public, or that safely could be. There the default is yes, so explore. That is the whole model, and if someone cannot say which tier a thing belongs to, that is a classification question to answer first, not a reason to freeze.
The question you have to answer
The hardest part hides inside Tier 1, and it is not technical. It is whether you trust your own contracts. If you hold an enterprise agreement that a vendor will not train on or keep your data, then you have already made the decision. Trust it, and let people work.
Reopening that debate on every single use is not caution. It is paralysis dressed as diligence. Responsible innovation means you do not relitigate settled questions out of principle. And if you genuinely do not trust the agreement, then be honest with yourself: you do not have a tooling problem, you have a Permission problem, and the work is on the front end, choosing terms you can stand behind. Do that once. Then get out of the way.
Write it on one page
So write your policy, and write it short. The few duties that come with total accountability are simple: verify before it leaves you, name the human on consequential work, disclose where it is material, and ask early when unsure. You do not have to start from a blank page.
Here is Monday morning. Do not commission a policy. Write the sentence at the top of a blank page, there is no AI work product, only AI-assisted human work product, and then add only what you need underneath it: which data goes where, and who to ask when in doubt. If your draft runs past a page, you are writing to cover yourself, not to help your people. The shortest honest policy is the one that gets read, and the only one that lets the work move.
Cheers,
-Titus
Get it in your inbox.
New Issues, FAQs, and Case Studies as they go out. Each one names something, explains something, or hands you something you can use on Monday. Subscribe, and I will send each as it goes out.
Prefer the tool you already think in? Here is how to read it in your chatbot.