Case Study: Turning a 40-Page AI Policy Into an Operating Habit
A manufacturer had an exemplary AI policy nobody followed. Rewriting it to one page — and teaching it with the team's own work — did what three compliance emails could not.

The best-written AI policy we have ever reviewed belonged to an organisation with one of the worst Judgment & risk scores we have ever measured1. That is not a paradox. It is the pattern.1A composite case, anonymised from several Fellow engagements. Numbers are representative of the pattern, not one client's audited results.
The situation
A manufacturing group of about 1,200 people had commissioned a thorough AI usage policy: forty pages, legally reviewed, covering data classes, approved tools, escalation paths. It had been distributed by email, twice, with a mandatory acknowledgement click.
The readiness assessment then asked their people a simpler question: does a data policy exist, and could you describe it? The gap was stark — the overwhelming majority had acknowledged a policy they could not state a single rule from◦.By the numbers92% vs 9%had formally acknowledged the policy, versus could describe any rule in it when asked
Meanwhile, output verification — the behaviour the policy mandated most carefully — depended entirely on which individual happened to be doing the work.
Why paper does not change behaviour
A policy is a description of intended behaviour, not a mechanism for producing it◦. Reading is not rehearsal: people do not consult documents mid-task, they follow habits and copy colleagues. A rule that is not present at the moment of work does not exist at the moment of work.DefinitionPolicy theatre Controls that exist to be shown — to auditors, boards, clients — rather than to be used, creating the impression of safety without the behaviour
The forty pages also carried a quieter cost: because the official rules were unusable, teams had each improvised their own informal ones — twelve different local versions of "be careful", none of them the written one.
What we did
- Cut the policy to one page. Three categories — never leaves approved tools; allowed with care; freely allowed — with the five most common data types of each named explicitly. The legal team kept the forty pages as an annex; the page became the interface.
- Taught it in ninety-minute working sessions, using each team's real deliverables. Every session ended with the team classifying ten of their own recent AI uses against the page — disagreement was the point, and settling it was the training◦.Figure
The moment that changes behaviour is applying the rule to your own work, not reading it - Moved verification into the workflow. For the three deliverable types where an error would reach a customer, a named checker and a five-line checklist — in the template itself, not in a separate document.
- Made the rule the reflex. Team leads opened week meetings for a month with one classification question. Sixty seconds each time; that repetition, not the email, is what installed the rule.
What changed
At re-assessment one quarter later, the described-the-policy number moved from single digits to a strong majority, and verification on customer-facing deliverables was structural rather than personal◦. The incident that eventually tested it — a supplier document pasted toward an unapproved tool — was caught by a colleague quoting the rule from memory, which is the only place a rule ever works.By the numbers9% → 78%respondents able to state the core data rule unprompted, one quarter after the rewrite
What to steal
- This week: ask ten people to state your AI data policy from memory. Their answers are your real policy.
- This month: compress the written policy to one page someone could apply mid-task; keep the long version as an annex.
- This month: teach the page against your teams' own recent work — classification arguments included.
- This quarter: move verification into templates and workflows for the deliverables where errors travel furthest.
A policy that lives only on paper scores as risk, not protection, in a readiness assessment — and in reality◦. If this is your flagged pattern, the one-page rewrite is the highest-leverage week you can spend.RelatedThe wider pattern: when usage outruns control
นโยบาย AI ที่เขียนดีที่สุดที่เราเคยเห็น เป็นขององค์กรที่ได้คะแนน Judgment & risk ต่ำที่สุดเท่าที่เราเคยวัดมา1 นี่ไม่ใช่เรื่องย้อนแย้ง แต่คือรูปแบบที่เกิดซ้ำ1กรณีศึกษานี้เป็นการประกอบขึ้นจากหลายงานจริงของ Fellow ปรับข้อมูลให้ไม่ระบุตัวตน ตัวเลขสะท้อนรูปแบบที่พบซ้ำ ไม่ใช่ผลตรวจสอบของลูกค้ารายเดียว
สถานการณ์
กลุ่มผู้ผลิตขนาดประมาณ 1,200 คนว่าจ้างจัดทำนโยบายการใช้ AI อย่างละเอียด: สี่สิบหน้า ผ่านการตรวจทางกฎหมาย ครอบคลุมชั้นข้อมูล เครื่องมือที่อนุมัติ และขั้นตอนการส่งต่อ ส่งทางอีเมลสองรอบ พร้อมบังคับให้คลิกรับทราบ
จากนั้นแบบประเมินความพร้อมถามคำถามที่ง่ายกว่านั้น: มีนโยบายข้อมูลหรือไม่ และคุณอธิบายมันได้ไหม ช่องว่างชัดเจนมาก — คนส่วนใหญ่กดรับทราบนโยบายที่ตัวเองบอกกฎสักข้อเดียวไม่ได้◦ ขณะเดียวกัน การตรวจทานผลลัพธ์ — พฤติกรรมที่นโยบายเน้นหนักที่สุด — ขึ้นอยู่กับว่าใครเป็นคนทำงานชิ้นนั้นตัวเลข92% กับ 9%กดรับทราบนโยบายอย่างเป็นทางการ เทียบกับอธิบายกฎใดกฎหนึ่งได้เมื่อถูกถาม
ทำไมกระดาษจึงไม่เปลี่ยนพฤติกรรม
นโยบายคือคำอธิบายพฤติกรรมที่ตั้งใจ ไม่ใช่กลไกที่สร้างพฤติกรรมนั้น◦ การอ่านไม่ใช่การฝึกซ้อม: คนไม่เปิดเอกสารกลางงาน แต่ทำตามความเคยชินและเลียนแบบเพื่อนร่วมงาน กฎที่ไม่อยู่ตรงหน้างาน เท่ากับไม่มีอยู่ในขณะทำงานนิยามPolicy theatre การควบคุมที่มีไว้เพื่อ“โชว์” — ต่อผู้ตรวจสอบ บอร์ด หรือลูกค้า — มากกว่าเพื่อใช้จริง สร้างภาพลวงตาของความปลอดภัยโดยไม่มีพฤติกรรมรองรับ
สี่สิบหน้านั้นยังมีต้นทุนเงียบ ๆ อีกข้อ: เมื่อกฎทางการใช้ไม่ได้ แต่ละทีมจึงสร้างกฎเถื่อนของตัวเอง — “ระวังหน่อยนะ” สิบสองเวอร์ชัน ไม่มีอันไหนตรงกับฉบับจริง
สิ่งที่เราทำ
- ตัดนโยบายเหลือหนึ่งหน้า สามหมวด — ห้ามออกจากเครื่องมือที่อนุมัติ, ใช้ได้อย่างระมัดระวัง, ใช้ได้อิสระ — พร้อมระบุชนิดข้อมูลที่พบบ่อยห้าอันดับแรกของแต่ละหมวด ทีมกฎหมายเก็บสี่สิบหน้าไว้เป็นภาคผนวก หน้าเดียวนั้นคือ interface
- สอนใน workshop 90 นาที ด้วยงานจริงของแต่ละทีม ทุก session จบด้วยการให้ทีมจัดประเภทการใช้ AI จริงสิบรายการล่าสุดของตัวเองเทียบกับหน้านั้น — ความเห็นต่างคือหัวใจ และการหาข้อสรุปร่วมกันคือการอบรมที่แท้จริง◦ภาพประกอบ
จังหวะที่เปลี่ยนพฤติกรรม คือตอนที่ได้ใช้กฎกับงานของตัวเอง ไม่ใช่ตอนอ่าน - ย้ายการตรวจทานเข้าไปอยู่ในเวิร์กโฟลว์ สำหรับงานสามประเภทที่ความผิดพลาดถึงมือลูกค้า ใส่ผู้ตรวจที่ระบุชื่อและเช็กลิสต์ห้าบรรทัดลงในเทมเพลตเลย ไม่ใช่เอกสารแยก
- ทำให้กฎเป็น reflex หัวหน้าทีมเปิดประชุมต้นสัปดาห์ด้วยคำถามจัดประเภทหนึ่งข้อ เป็นเวลาหนึ่งเดือน ใช้เวลาหกสิบวินาทีต่อครั้ง การทำซ้ำนี้ต่างหาก ไม่ใช่อีเมล คือสิ่งที่ติดตั้งกฎลงในองค์กร
สิ่งที่เปลี่ยนไป
ในการประเมินซ้ำหนึ่งไตรมาสถัดมา สัดส่วนคนที่อธิบายกฎหลักได้จากความจำกระโดดจากเลขหลักหน่วยเดียวเป็นเสียงข้างมาก◦ และเหตุการณ์ที่ทดสอบระบบจริง — เอกสารซัพพลายเออร์ที่กำลังจะถูกวางลงเครื่องมือที่ไม่อนุมัติ — ถูกเพื่อนร่วมงานทักท้วงโดยอ้างกฎจากความจำ ซึ่งเป็นที่เดียวที่กฎใช้การได้จริงตัวเลข9% → 78%ผู้ตอบที่สามารถบอกกฎข้อมูลหลักได้เอง หนึ่งไตรมาสหลังเขียนใหม่
สิ่งที่นำไปใช้ได้เลย
- สัปดาห์นี้: ถามสิบคนให้บอกนโยบายข้อมูล AI จากความจำ คำตอบของพวกเขาคือนโยบายจริงของคุณ
- เดือนนี้: บีบนโยบายให้เหลือหน้าเดียวที่ใช้ได้กลางงาน เก็บฉบับเต็มไว้เป็นภาคผนวก
- เดือนนี้: สอนหน้านั้นด้วยงานจริงล่าสุดของทีมคุณเอง รวมการถกเถียงเรื่องการจัดประเภท
- ไตรมาสนี้: ย้ายการตรวจทานเข้าเทมเพลตและเวิร์กโฟลว์ โดยเริ่มจากงานที่ความผิดพลาดเดินทางไกลที่สุด
นโยบายที่อยู่แค่บนกระดาษ นับเป็นความเสี่ยง ไม่ใช่เกราะป้องกัน — ทั้งในแบบประเมินความพร้อมและในโลกจริง◦ ถ้านี่คือรูปแบบที่ถูกติดธงในรายงานของคุณ การเขียนใหม่เหลือหน้าเดียวคือสัปดาห์ที่คุ้มค่าที่สุดที่คุณจะใช้ได้บทความที่เกี่ยวข้องรูปแบบใหญ่กว่า: เมื่อการใช้งานล้ำหน้าการควบคุม
Keep reading

Case Study: What Changed When AI Adoption Got a Named Owner
A retailer's AI momentum collapsed the month its champion resigned. The rebuild took one owner, three workflows, one measure each — and a monthly review leadership actually attends.

Case Study: The Audit That Turned “Not Sure” Into a Plan
A division head answered “not sure” to seven of twelve readiness indicators. Four weeks of asking — not surveying — turned the blind spots into the year's adoption roadmap.