The AI-Safe Desk · Module 4: Your rulebook
Writing the page
The rulebook has five short sections, and you have already done the work for all of them in the activities. Tools: which ones you use, marked consumer, business or internal, with the settings you have set. Bands: your own examples of green, amber, red and black from your role. Routine: your redaction replacements and your two-second question. Settings: what you have switched off and where. Escalation: who you ask when unsure, and what you do while you wait.
Write it in plain English, first person, no policy language. "I do not paste health information into any AI tool." "I replace client names with roles before pasting." It should read as a description of how you actually work, because that is what it is.
Keep it to one page. If it is longer, you are writing a policy, and you already have one of those that nobody reads.
In practice. A team leader wrote her rulebook and pinned it above her desk. Her manager saw it, asked for a copy, and a version of it became the team's starting point. The organisation's formal policy, when it arrived nine months later, was longer, and said the same things.
Help me write a one-page personal AI rulebook from my notes. My tools and their versions: [ list ]. My settings: [ list ]. Examples of green, amber, red and black from my role: [ list ]. My redaction replacements: [ list ]. Who I escalate to: [ name or role ]. Write it in first person, plain English, five short sections, under 350 words. It should read as a description of how I work, not a policy. No legal language.
At your desk. Write the page. Read it aloud. Cut anything you would not actually do. Then read it as your data protection lead would, and mark anything they would question. Fix those before anyone else sees it.
Write it down.
- My first rule, in my words:
- The line my DPO would question:
- What I changed: