Guide
Nobody reads the policy. So they assume the answer is no.
Most investment firms we meet have one of two AI policies. Either nothing is written down, or counsel has produced fourteen careful pages that nobody on a deal team has opened. Both produce the same behaviour: people assume that putting real work into the tool is forbidden, and the licences sit unused while the early adopters quietly do it anyway.
This guide is about the page that fixes that. It is one page, it is written in the words of the desk rather than the vendor’s, and it answers three questions: what may go in, what may not, and who decides the edge cases. It sits beside the document counsel writes rather than replacing it, and the two are different things with different readers.
Two documents
ai policy for fund managers what should it include
Counsel's document, and the desk's page.
The fund-counsel commentary agrees on what a manager’s AI policy has to cover, and it is right: an inventory of the tools in use and who approved them, what may be entered into each, vendor terms on confidentiality and data ownership, which outputs count as records and how long they are kept, and one named owner for the firm’s AI disclosures. That document is for the regulator, the LP who asks, and the auditor. It should be written by counsel and it will be long.
The desk’s page is a different document with a different reader. An associate with a CIM open at eleven at night does not consult a fourteen-page policy; they either put the document in or they do not. The page is written for that moment. It is short enough to be pinned above a monitor, it names the tools by the names people use for them, and it is consistent with counsel’s document in every particular, because it is derived from it.
The one page
what to put in an ai acceptable use policy for employees
What may go in, what may not, and who decides.
Five parts, in this order, and the whole thing fits on one side.
- The tools, by name
- Which tools are approved, under the firm's own enterprise terms, and how to reach each one. If a tool is approved only for certain desks, say which. A tool people have to ask about is a tool they use twice.
- What may go in
- Stated positively and specifically: a CIM from the data room, a credit agreement, a portfolio company's monthly reporting, an LP letter. People do not act on 'confidential information may be used in approved tools'. They act on 'the CIM goes in'.
- What may not
- Equally specific: material non-public information about a listed name, personal data of a named individual, anything an LP has asked in writing to keep out of AI systems, anything in a tool that is not on the approved list. Short, because it is a list of exceptions rather than a definition.
- Who decides the edge cases
- One name and one address. Not a committee and not a form. The associate at eleven at night needs a person who will answer by morning, and a question that takes a week to answer is a question that gets answered 'no' by default.
- What to do with the output
- A model's output is a first pass that a person reads before it goes anywhere, with the source cited beside every claim. Say that, say who signs, and say that the person who sends it owns it. That one sentence is most of the firm's accuracy policy.
The reason the page has to be this short is set out on AI Enablement, as the second of the five things that have to be true before adoption moves.
What LPs ask
lp due diligence questions about ai use at gp
The question is no longer whether, it is where the data goes.
Investor due diligence questionnaires now carry AI questions, and the ones that matter are about data: whether the manager uses public AI tools, whether LP information can be entered into them, who the vendors are and on what terms, and whether the LP will be told if something goes wrong. Some LPs are writing those terms into the fund documents.
A firm with the two documents above answers all of that in a paragraph. Enterprise terms with named vendors, no public tools, a written line on what goes in, a named owner, and a desk that actually follows it because the page was written for them. The firm that cannot answer is usually the one with the fourteen pages.
Keeping it true
how often to update ai policy
The tools change monthly. So does the page.
A policy that describes last year’s tools is a policy nobody trusts. New capabilities arrive in the approved tools every month, and a desk that discovers one the page does not mention concludes the page is out of date and stops reading it. On the retainer, the page is reviewed monthly with the people who use it, in the same session as the prompting practice, and the monthly account of what changed includes what changed on the page. Counsel’s document is updated on its own schedule, and the page is checked against it each time it is.
Questions
The questions that follow.
What a COO, a general counsel or a chief compliance officer asks once they accept that the long document and the short page are different things.
Do we need an AI policy if we only use enterprise tools?
Yes. Enterprise terms settle where the data goes; they say nothing about what your people may put in, what they may not, or who signs an output before it leaves the firm. Those are the firm's decisions, and the desk needs them written on one page.
Can you write our AI policy?
We write the desk's page, with the people who will use it, and we keep it current on the retainer. Counsel writes the document for the regulator, the LPs and the auditor, and we work from it. We are not lawyers and nothing on this page is legal advice.
What goes wrong with a long AI policy?
Nobody reads it, so people assume the answer is no, so the licences go unused while the early adopters use the tools anyway, outside any line at all. A fourteen-page policy nobody opens is the same as having no line, and in one respect worse: the firm believes it has one.
Should the policy ban public AI tools?
It should name the approved tools and say that nothing else is used for firm work, which has the same effect and is a sentence rather than a paragraph. The approved list should be the tools people actually want to use, on enterprise terms, or the ban will be ignored.
Who should own the AI policy inside the firm?
Two owners. Counsel or compliance owns the long document and the disclosures. Somebody who performs the work owns the desk's page and is the name on it: the person an associate can write to at eleven at night and hear back from by morning.
What do LPs ask about AI in due diligence?
Whether the manager uses public AI tools, whether LP information can be entered into any AI system, which vendors on what terms, who owns the outputs, and whether the LP is told of an incident. Some are now writing these terms into the fund documents. A firm with a named vendor list, enterprise terms, a written line and a named owner answers all of it in a paragraph.
Send us the fourteen pages.
Or the nothing. Either way, tell us which tools your people have and which desks use them, and we will show you what the one page looks like for your firm.
Subject line: AI policy
