How to Draft a Department-Level AI Policy
The structure of a workable department-level AI policy: scope, permitted use, data rules, approval, human review, procurement and incident handling.
What Should a Department-Level AI Policy Contain?
A department AI policy should be short enough for officers to read and specific enough to follow. Cover scope, permitted and prohibited uses, data classification rules, approval pathways, mandatory human review, procurement requirements, training obligations and incident reporting — with named owners for each.
Key Takeaways
Short, specific policies get followed; long ones get filed.
Prohibited uses must be stated explicitly.
Approval pathways prevent both shadow use and paralysis.
Every clause needs a named owner.
Practical Framework
Eight Policy Sections
Scope and Definitions
What the policy covers and the terms used.
Permitted Use
Approved tools, approved tasks and explicit prohibitions.
Data Rules
Classification, handling, retention and disclosure limits.
Approval and Review
Use-case approval, human review points and escalation.
Procurement and Incidents
Buying requirements, reporting duties and response steps.
What Government Leaders Should Do Next
- Draft with operations, legal, security and training together.
- Circulate to officers for readability feedback.
- Publish alongside practical examples.
- Review the policy every six months.
Risks and Common Mistakes
- A policy written only by the legal function.
- Blanket prohibitions that drive shadow use.
- No approval path, so nothing can be done legitimately.
- Publication without training or examples.
What Delay Costs: Government AI Policy Framework
- Officers make individual judgement calls with no guidance.
- Disclosure incidents occur before rules exist.
- Procurement proceeds without consistent requirements.
In the absence of a policy, every officer is quietly writing their own — and the department will be judged on the weakest one.
86%
of employers expect AI and information processing to transform their business by 2030
Source: World Economic Forum, Future of Jobs Report 20251%
of executives describe their organisation's AI rollout as mature
Source: McKinsey, Superagency in the Workplace, 202563%
of employers identify skills gaps as a major barrier to business transformation
Source: World Economic Forum, Future of Jobs Report 2025Questions Government Decision-Makers Ask Next
Who Should Own How to Draft a Department-Level AI Policy?
A senior accountable sponsor should own the outcome, while a cross-functional team covers policy, operations, data, technology, legal, security and capability building.
How Should a Department Start With How to Draft a Department-Level AI Policy?
Start with a documented baseline, a narrow set of high-value use cases, a representative pilot cohort and clear measures of adoption, quality, time saved and risk.
What Should Be Measured?
Measure competency gain, active adoption, task turnaround, output quality, control compliance and the number of validated use cases moved into normal operations.
Authoritative Sources
IndiaAI — AI Competency Framework for Public Sector Officials
Official national AI capability and competency context.
Capacity Building Commission
Official competency-led public-sector capacity-building guidance.
Ministry of Electronics and Information Technology
Official digital policy, governance and responsible AI context.
Last Reviewed: 15 September 2026
Turn This Guidance Into a Department-Specific Action Plan
Share the intended outcome, current constraints and decision stage. We will help identify the capability, governance and pilot sequence needed before wider implementation.
Translate the framework into your departmental context.
Identify immediate readiness and control gaps.
Outline a proportionate diagnostic or pilot with no obligation.
Secretaries, Legal Teams, CIOs