If your team is adopting AI tools faster than your policies can keep up — or doing it without policies at all — this session is for you. Our September 1 AI Academy Live session showed that addressing an AI policy doesn’t mean simply creating a document full of restrictions. It's a governance system that makes it easier for people to use AI safely and confidently.
During Inside the SmarterX AI Policy, Tracy Lewis, SmarterX COO, and Samantha Jorden, Senior Associate Attorney at Toerek Law, walked attendees through how SmarterX built the operational and legal foundations behind its AI use.
A Need for Comprehensive, Clear AI Guidance as AI Accelerates
Lewis described a familiar challenge for organizations navigating rapid AI adoption: employees independently experimenting with new tools and technologies, often faster than centralized processes and governance could evolve. At SmarterX, the experimentation was driven by real business needs, she explained. People were looking for better ways to solve problems and work more effectively. As AI adoption accelerated, the need for clearer guidance and more consistent processes became apparent. Lewis and Jorden shared how they evolved their approach, along with lessons any organization can apply to its own AI policies.
One of the biggest themes of the session was that an AI policy is rarely just one document. When SmarterX set out to answer the simple question of whether an employee could use an AI tool, the team discovered that the answer was spread across its employee handbook, IT security policy, contractor agreements, and more. Lewis pointed out that many AI questions are really familiar workplace questions in a new form, so the goal wasn't to invent new rules from scratch. It was to make sure every document told the same story.
From there, SmarterX built its guidelines around a simple idea: the more sensitive the information and the more an AI tool can do on its own, the more human oversight and care are required. To make this easy to apply, SmarterX decided to sort the information it uses with AI into three levels:
- Public: Anything already published, like blog posts and marketing materials. This can be used in any AI tool.
- Confidential: Everyday internal information, like drafts, pricing, and plans. The test is simple: if you wouldn't publish it on the blog today, it's at least confidential. It can only go into company-approved AI accounts.
- Highly sensitive: Personal data, payment details, trade secrets, and anything under an NDA. This needs extra approval before it goes into any AI tool.
When in doubt, employees are told to choose the higher level or ask.
Guidance Is Important for Legal Issues, too
Jorden brought an essential legal perspective to the conversation. She explained why governance matters for protecting confidential data and preserving intellectual property rights.
She also reminded attendees that vendor marketing is not a security review. Someone has to actually read the terms, with attention to data training and retention, indemnification, and warranty disclaimers. And approving a tool doesn't mean approving everything that can be connected to it.
Jorden’s perspective on disclosure was especially valuable: It isn't just a communications decision, but a legal compliance, trust, and IP protection issue. That's why SmarterX requires employees to add a short, simple disclosure to their own work internally when AI has played a significant role in creating it. Transparency in use is built in from the start.
Lewis shared how SmarterX designed an approval process that doesn't strangle experimentation. It uses a single intake form, an acknowledgment within three-days, pilot approvals, and a shared approval register that records both yeses and nos.
Lewis also made clear that publishing a policy isn't the same as implementing one. The team rolled out the policy in layers: a key-points email, a full team walkthrough, and DocuSign acknowledgment. Supporting resources included an AI decision tree, a "five rules to remember" reference, and a Gemini Notebook containing the policies, so employees can ask questions and get back simple answers.
Lewis noted the team used Claude to help build the policy, starting by asking what it needed to know rather than asking for a draft. AI accelerated the process, but humans owned every decision, and the final policy includes its own AI disclosure note.
What You'll Learn
- Why AI governance needs to span your handbook, security policy, AI policy, and contractor agreements.
- How to build a simple data classification system employees can apply on their own.
- How to scale oversight across chat, persistent artifacts, integrations, and agents.
- What a real vendor security review should cover from a legal perspective.
- When AI disclosure is required, and what good documentation looks like.
- How to design an approval process and rollout that encourages responsible experimentation.
If you couldn't join us live, or you'd like to revisit Lewis and Jorden's frameworks, the complete session is now available on demand. The recording includes the full presentation, real examples from SmarterX's policy and appendices, legal insights, and a brief audience Q&A.
Whether you're writing your first AI policy, updating existing AI guidelines, or trying to get visibility into how your team is really using AI, this session is an excellent place to start.
AI Academy Live sessions are included with AI Mastery Memberships and are also available for individual purchase. Watch or purchase now: Inside the SmarterX AI Policy
This article was written with support from Claude.
Susan Valerian
Content Specialist, SmarterX
