Service · AI ways of working
We roll out AI usage rules inside companies
Not another policy nobody opens. We talk to the team, agree the limits with management and leave one page people actually read — with a named person to ask and a date to review it.

We start from what is already happening
The first sentence we hear in the management meeting is usually: "people here don’t really use it". An hour later, after talking to the teams, it turns out three departments do — on personal accounts, with nothing agreed about what may be pasted in. The scale shows up in a study by Experience Institute and Praca.pl (July 2026, N = 1,636): only 27% of employees confirm their company has clearly defined rules for using AI, and just 16% ever wonder whether the way they use these tools is legal. So we don’t start by writing a document. We start by establishing what is genuinely in use — because a document that ignores that describes a company which does not exist.
What the rollout looks like
Five steps, two to three weeks
- Discovery — short conversations across a few teams and a list of the tools actually open on company machines.
- Decisions with management — what is allowed, what is never allowed and what requires asking first. Three lists, not twenty clauses.
- One page — rules written in the team’s own language, with a named person to ask, a contact channel and an effective date.
- The announcement — a meeting, not an email. People need to ask out loud and hear that asking is fine.
- A 30-day review — which questions came back, what the team works around, what to add or delete.

The five mistakes we see most often
- A document written without a single conversation with the team. It bans things nobody does and says nothing about what happens daily.
- A list of prohibitions with no list of what is allowed. If you never say what is fine, people assume nothing is — and carry on quietly.
- No name. "In case of doubt, contact the relevant department" means, in practice: contact nobody.
- Banning tools the team already uses without naming an alternative. The effect is the opposite of the intent — usage moves to private phones.
- Nothing about mistakes. If nobody says what happens when someone pastes the wrong thing, you will hear about it as late as possible.
What comes up in conversations with the team
We run these conversations without managers in the room and without names in the notes — otherwise you only hear the answer people consider safe. The questions repeat in every company, whatever the industry:
- "Can I paste part of a contract to get it summarised?"
- "If I admit I use AI, will I look like someone who cannot do the work alone?"
- "Can anyone in the company see what I ask the model?"
- "I have my own paid account — am I allowed to use it for work?"
- "Who is responsible if the model gets a number wrong and I miss it?"
Why one page instead of a policy document
A formal policy and a set of rules are two different documents, and they can happily coexist. The policy is for the institution: liability, procedures, consequences — drafted with a lawyer, long because it has to be. The rules are for the people inside: they must answer "can I paste this file here?" faster than it takes to find someone who knows. We measure a rollout with one test: stop a random person in the company and ask them to name three things that must never be pasted in, plus the person to ask. If they cannot, the document is not working — regardless of its length or who approved it.
Prefer to do it yourself? We built a free generator
Not every company needs an agency for this. In a small team sitting in one room the whole conversation fits into a single meeting — all that is missing is the document. That is why we published a free generator as part of our FlashAI product: answer eight questions and get a one-page set of rules for your team, no sign-up. The AI usage rules generator is public and asks for nobody’s contact details. We do the same thing, but with the discovery, the team conversations, the announcement and the review — the part no form can do for you.
What we do not do
This is organisational help, not legal advice. We do not issue legal opinions, we do not audit contracts with model vendors and we do not declare that after our work a company complies with any particular act — compliance depends on what actually happens to the data, and a lawyer determines it, not an agency. We handle the part where most companies get stuck: making sure the team knows what is allowed, who to ask and what to do after a mistake. If a law firm has already written your policy, all the better — then our job is to translate it into one page and communicate it.
Rules nobody has read protect nobody. A rollout does not end the day the document is published — it ends the day the team knows who to ask.
We speak from deployment experience, not from slides

SymfoniX
A deployment where the AI runs locally and the data never leaves the company — which is how we know what really goes out and what does not.

FlashAI
Our own AI agent. We apply the rule we write about: contact data is masked before anything reaches the model.
Frequently asked questions
How long does a rollout take?
Usually two to three weeks from the first meeting to the announcement. The writing is not what takes time — the conversations do, plus agreeing three lists with management: what is allowed, what is never allowed and what requires asking first. Then a 30-day review, because the first version always misses something.
Do you do this for small companies?
Yes — though for a team under roughly ten people one meeting with everyone plus the document the same day is usually enough. If even that feels excessive, we will honestly point you to our free generator on flashai.pl: eight questions, one finished page, no agency involved and no cost.
How is this different from a policy written by a law firm?
Scope and audience. A law firm describes liability and procedure for the institution; we answer the team’s question "can I paste this file here?" in one paragraph. The two do not compete — most often we work from an existing policy and translate it into a page you can read over coffee.
Is this legal advice or a compliance statement?
No. It is organisational help: agreeing the rules, writing them in plain language and communicating them to the team. We make no claim of compliance with the AI Act, GDPR or any other act — that is a legal assessment and belongs to a lawyer who knows how the company actually processes data.
We wrote rules a year ago. Is it worth revisiting them?
Usually yes — because what changes is not the law but the list of tools and what people do with them. In a review we check two things: whether the team can recall the rules from memory, and whether tools have appeared that the document knows nothing about. The second is almost always true.
Want this agreed and announced across your company?
Tell us how many teams you have and what you guard most closely — we will propose a scope and a date. The first conversation is free.