Adoption LessonsGovernance
Three policy versions in five months is a good sign
Jason Lawrence
My firm’s AI policy went through three versions in five months. Version 1.0 on 1 April. A reissue on 20 May. Version 2.3 on 12 August.
That can look like a policy nobody got right. I read it the other way. Every version answered something people had actually done with the tool. A policy that hasn’t changed in a year of AI is a policy nobody is using.
The number: three versions in five months
Here is what changed between them.
Approvals moved into the open. Version 1.0 sent requests for new tools to an email inbox. Only the people reading the inbox saw what had been asked. Now requests go to an open Slack channel, so everyone sees what has been asked and what the answer was. The next person with the same question can find the answer before they ask it.
Exceptions got a route. Some work genuinely can’t follow the standard rule. The first version had no way to say so. We added an exception route with two named approvers and a one-business-day target. A route with a name and a deadline on it is one people can actually use.
Incidents got named triggers. “Report any incident” means little to someone who isn’t sure what counts. So the policy now lists the triggers, and one of them is “I put work into a personal account”. It is on the list because it is the one that actually happens. Naming it makes it something people report, not something they hide.
Thirteen pages became one. The full policy ran to thirteen pages, and nobody read it. So we shipped a one-page Five Rules guide beside it. The full policy is still there for the questions the page can’t answer. The page is the one people read.
What went right
Every change came from use. People used Claude, found a gap, and the gap went into the next version. The open channel helped, because a question asked there is a gap everyone can see.
What went wrong
The policy people signed moved three times. The copy Claude itself read did not move at all. It stayed on the April text until August, and so did the wiki summary built from it. That is its own lesson, and it is the failure we would warn anyone about first. Updating the version people sign is not the same as updating every copy that gets read.
What we would do now
Plan for the reissue from the start. Put a version date and an owner’s name on the policy, and expect the date to change. Treat a policy that hasn’t moved in six months as a question, not a success. Either nobody is using the tool, or nobody is telling you what they find.
Make updating every copy a step in the reissue: the one people sign, the one on the wiki and the one Claude reads.
And start with the one page, not the thirteen. The long version can follow. The page is what people use.
One thing to try this week
Find your AI policy and check its version date. If it hasn’t changed since you rolled Claude out, ask your team one question in the channel where they already talk: what have you done with it that the policy doesn’t cover?
Then write your rules on one page. Here is a template to start from.
Get new lessons by email
Short lessons from a real Claude rollout, each backed by a number.
