Service · Policy
G2AI Policy & Acceptable Use Framework.
Most AI policies get written and forgotten. This is the one that gets used. A published policy, practical staff guidance that matches how people actually work, and a rollout designed to be adopted rather than ignored.
Outcomes
What changes when the engagement lands.
Policy the business follows
The policy fits how people actually work. It gets used, not filed.
Guidance staff can use in a hurry
The staff guide is written so someone can consult it in the middle of a task, not just at induction.
Rollout designed for adoption
Not a memo. A programme with champions, training, and follow-up.
Regulator-defensible position
The framework holds up under regulatory scrutiny — GCC PDPL, EU AI Act deployer obligations where applicable.
Deliverables
What's in the engagement.
A two- to three-week engagement that produces a published AI policy, practical staff guidance, and a rollout the team actually follows — not a shelf document.
Published policy
The formal AI acceptable use policy. Ready for the intranet and the handbook.
Practical staff guidance
Task-level guidance written for the operators who use AI in the flow of work.
Rollout plan
Champions identified. Training designed. Follow-up cadence set.
Review and update cycle
A rhythm for updating the policy as models and risks change.
How we deliver
Fixed scope. Named phases. Duration on the cover.
The engagement is priced against the outcome, not open-ended hours. Every phase has a duration, a named deliverable, and a check-out.
Total duration2 to 3 weeks
Sales cycle3 to 5 weeks
- 01Week 1
Current state
Existing policy review. Staff interview. Gap analysis.
- 02Week 2
Framework draft
Policy and guidance drafted. Reviewed with legal, risk, and operator representatives.
- 03Week 3
Rollout
Final published. Rollout plan and materials handed over.
Built for
Buyers this engagement fits.
Typical buyer
CEO, COO, Head of Legal, Head of Risk
Businesses whose staff use AI without a policy
Usage is already happening. This is what makes it safe and sustainable.
Regulated organisations with an AI Act or PDPL horizon
The regulator will want a policy. Have one that stands up.
Executive teams whose previous policy failed to land
The last one got written and forgotten. This one is built to land.
Related services
Where this leads next.
Regulatory Readiness (EU AI Act / GCC PDPL)
Gap assessment against deployer obligations and GCC regimes. Closing roadmap.
Sovereign AI Readiness & Governance Baseline
Governance review. Model and data inventory. Control set mapped to ISO 42001. Certification roadmap.
AI Opportunity Audit
Structured pass over the operation. Prioritised opportunity map. Costed business case for the top two or three.
Talk to us.
45 minutes on your operation and the engagement you have in mind. No pitch, no deck.
Lead intake
Request a briefing
A 45-minute call. No pitch, no deck. We ask the questions we'd ask a Discovery client and tell you honestly whether this is the right next move.