Case Study: Turning a 40-Page AI Policy Into an Operating Habit
A manufacturer had an exemplary AI policy nobody followed. Rewriting it to one page — and teaching it with the team's own work — did what three compliance emails could not.

The best-written AI policy we have ever reviewed belonged to an organisation with one of the worst Judgment & risk scores we have ever measured1. That is not a paradox. It is the pattern.1A composite case, anonymised from several Fellow engagements. Numbers are representative of the pattern, not one client's audited results.
The situation
A manufacturing group of about 1,200 people had commissioned a thorough AI usage policy: forty pages, legally reviewed, covering data classes, approved tools, escalation paths. It had been distributed by email, twice, with a mandatory acknowledgement click.
The readiness assessment then asked their people a simpler question: does a data policy exist, and could you describe it? The gap was stark — the overwhelming majority had acknowledged a policy they could not state a single rule from◦.By the numbers92% vs 9%had formally acknowledged the policy, versus could describe any rule in it when asked
The acknowledgement rate was not a lie. It was an accurate measurement of a different thing: how many people had clicked a button. Compliance dashboards are full of numbers like this, and they are dangerous precisely because they are true. Nobody was deceiving the board; the organisation was reporting the metric it had, and that metric measured distribution rather than adoption◦.DefinitionAcknowledgement gap The distance between clicking "I have read this" and being able to apply it mid-task — usually invisible, because only the click is measured
Meanwhile, output verification — the behaviour the policy mandated most carefully — depended entirely on which individual happened to be doing the work. In practice that meant two engineers checked everything, a third checked nothing, and nobody could tell you which of the three had drafted the specification a customer was currently reading.
The interviews surfaced something the survey could not: people were not ignoring the policy out of indifference. Several had genuinely tried to use it. One quality lead described opening the document, searching for the word "supplier", finding nine matches across four sections that appeared to contradict one another, and giving up after about six minutes. He then did what everyone does — asked the colleague at the next desk, who had never read it either.
Why policies fail everywhere, not just here
This organisation was not unusually badly run. It was unusually well documented, which is what made the failure mode easy to see.
KPMG and the University of Melbourne's 2025 study of more than 48,000 people across 47 countries found that 66% of employees rely on AI output without checking its accuracy◦, that 56% say they have made mistakes in their work because of AI, and that roughly one in two report using AI in ways that go against their organisation's policies1. The behaviour those forty pages were written to prevent is, on that evidence, the median behaviour.By the numbers66%KPMG and the University of Melbourne's 2025 global study: employees who rely on AI output without checking accuracySourceKPMG & University of Melbourne, "Trust, attitudes and use of AI", 2025
Part of the reason is that almost nobody is taught. The National Cybersecurity Alliance's 2025 "Oh Behave!" study found that 58% of AI users had received no training at all on AI security and privacy risks◦, and that 43% had shared sensitive work information with AI without their employer's knowledge2. A document is not training. It is the thing training would have been about.By the numbers58%National Cybersecurity Alliance 2025: AI users who received no training on AI security and privacy risksSourceNational Cybersecurity Alliance & CybSafe, "Oh Behave!", 2025–2026
And where policies exist at all, they trail usage badly. ISACA's 2025 AI Pulse Poll found that 83% of respondents believe employees at their organisation are using AI, while only 31% said their organisation has a formal, comprehensive AI policy3. This manufacturer was, on paper, in the better 31% — which is the entire point of the case.SourceISACA, 2025 AI Pulse Poll
The cost of the gap is now a matter of public record. In Moffatt v. Air Canada (2024 BCCRT 149), a British Columbia tribunal held Air Canada liable for a bereavement-fare policy that its website chatbot had simply invented, and rejected the airline's argument that the chatbot was a separate legal entity responsible for its own statements4. The award was small — CA$812.02 — but the principle was not: an organisation owns what its AI tells a customer. The same failure has since reached professional work; in October 2025 Deloitte Australia refunded part of an A$440,000 contract with the Australian Department of Employment and Workplace Relations after a delivered report was found to contain AI-hallucinated citations, including a fabricated quote from a federal court judgment5. Closer to home, the enforcement is Thai and recent. Thailand has no AI law — the PDPA is what a Thai organisation is actually judged against, and its compliance checklist includes training the people who handle personal data. In November 2025 the PDPC ordered a company to suspend iris scanning and delete the biometric data it had already collected, and five cases that August carried roughly THB 21.5 million in fines between them6.SourceMoffatt v. Air Canada, 2024 BCCRT 149 (via McCarthy Tétrault)SourceDeloitte Australia's partial refund on an AI-error report, 2025 (via CFO Dive)SourceChambers, Data Protection & Privacy 2026 — Thailand
Why paper does not change behaviour
A policy is a description of intended behaviour, not a mechanism for producing it◦. Reading is not rehearsal: people do not consult documents mid-task, they follow habits and copy colleagues. A rule that is not present at the moment of work does not exist at the moment of work.DefinitionPolicy theatre Controls that exist to be shown — to auditors, boards, clients — rather than to be used, creating the impression of safety without the behaviour
The forty pages also carried a quieter cost: because the official rules were unusable, teams had each improvised their own informal ones — twelve different local versions of "be careful", none of them the written one. Two of those local versions were stricter than the policy, costing the business real speed for no reduction in risk. Three were considerably looser. The most common was a single heuristic passed on verbally: "don't put customer names in it" — which permitted almost every genuinely risky thing the policy prohibited, and prohibited a great deal that was harmless.
What we did
- Cut the policy to one page. Three categories — never leaves approved tools; allowed with care; freely allowed — with the five most common data types of each named explicitly. The legal team kept the forty pages as an annex; the page became the interface. Getting to one page took four drafts and two arguments, and the version that worked was written upward from the twelve informal rules, not downward from the forty pages.
- Taught it in ninety-minute working sessions, using each team's real deliverables. Every session ended with the team classifying ten of their own recent AI uses against the page — disagreement was the point, and settling it was the training◦. Eleven sessions covered everyone who touched AI; in nine of them at least one classification could not be settled in the room and had to be escalated, which is how we found the four cases the page genuinely did not cover.Figure
The moment that changes behaviour is applying the rule to your own work, not reading it - Moved verification into the workflow. For the three deliverable types where an error would reach a customer, a named checker and a five-line checklist — in the template itself, not in a separate document.
- Made the rule the reflex. Team leads opened week meetings for a month with one classification question. Sixty seconds each time; that repetition, not the email, is what installed the rule◦.Figure
The classification argument is the training. The one-page rule is only the prompt for it
The resistance was not where we expected it. Legal signed off on the one-pager in a single meeting once we agreed the forty pages remained binding as an annex — the page was framed as a reading aid rather than a replacement, which removed the objection entirely. The real resistance came from two plant managers who read ninety minutes per team as ninety minutes of lost production, and who were right to ask. We ran their sessions inside the existing shift-handover slot at sixty minutes instead of ninety, and accepted a slightly worse session in exchange for it happening at all.
Total effort: about five person-weeks of Fellow time, eleven sessions, and roughly two hundred person-hours across the client's population — nearly all of it the sessions themselves. The expensive part was never the writing.
The near-miss was in the checklist. Our first five-line check for customer-facing documents included a line about tone, which nobody could apply consistently and which turned the check into a matter of opinion. Two teams began skipping the whole checklist because of that one line. We cut it in week three and completion recovered within a fortnight. A checklist is only as strong as its weakest item, because the weakest item teaches people that the list is optional.
What changed
At re-assessment one quarter later, the described-the-policy number moved from single digits to a strong majority, and verification on customer-facing deliverables was structural rather than personal◦. The incident that eventually tested it — a supplier document pasted toward an unapproved tool — was caught by a colleague quoting the rule from memory, which is the only place a rule ever works.By the numbers9% → 78%respondents able to state the core data rule unprompted, one quarter after the rewrite
What did not move was equally instructive. The twelve informal rules did not disappear; they narrowed. At re-assessment three local variants were still in circulation, but all three were now stricter than the page rather than looser, and all three were recognisably derived from it. We count that as success rather than failure: the goal was never uniformity of wording, it was that every local version be a safe reading of the same rule◦.RelatedWhere unusable rules send the work
What we would do differently
We taught the page and then left. The month of sixty-second classification questions was the mechanism that actually installed the rule, and it was owned entirely by team leads whom we had briefed for about twenty minutes each. In two of the eleven teams it stopped after nine or ten days, and those two teams scored visibly lower at re-assessment. We had treated the reinforcement as the easy part because it was the cheap part. It was the load-bearing part.
If we ran it again, we would spend a full session with team leads alone before touching the wider population — not on the policy, on the ritual: what the question sounds like, what to do when someone gets it wrong in front of their team, how to keep it to sixty seconds. We would also hand them a stock of twenty pre-written classification questions, because the real reason it stopped in those two teams was not resistance. It was that the lead ran out of things to ask on a Monday morning and quietly dropped it.
The harder admission is that we still do not know how long the effect lasts. Our measurement window was one quarter. A rule people can quote three months after being taught is a genuine result; whether it survives a year, a reorganisation and a wave of new joiners who never sat in a session is a question our data cannot answer, and we would rather say so than imply otherwise.
What to steal
- This week: ask ten people to state your AI data policy from memory. Their answers are your real policy.
- This month: compress the written policy to one page someone could apply mid-task; keep the long version as an annex. Write it upward from the informal rules people already use, not downward from the long document.
- This month: teach the page against your teams' own recent work — classification arguments included.
- This month: brief whoever will run the reinforcement, separately and properly, and hand them the questions to ask.
- This quarter: move verification into templates and workflows for the deliverables where errors travel furthest — and cut any checklist line that two reasonable people could answer differently.
A policy that lives only on paper scores as risk, not protection, in a readiness assessment — and in reality◦. If this is your flagged pattern, the one-page rewrite is the highest-leverage week you can spend.RelatedThe wider pattern: when usage outruns control
Sources
- KPMG & University of Melbourne, "Trust, attitudes and use of AI", 2025
- National Cybersecurity Alliance & CybSafe, "Oh Behave!", 2025–2026
- ISACA, 2025 AI Pulse Poll
- Moffatt v. Air Canada, 2024 BCCRT 149 (via McCarthy Tétrault)
- Deloitte Australia's partial refund on an AI-error report, 2025 (via CFO Dive)
- Chambers, Data Protection & Privacy 2026 — Thailand
Keep reading

Case Study: What Changed When AI Adoption Got a Named Owner
A retailer's AI momentum collapsed the month its champion resigned. The rebuild took one owner, three workflows, one measure each — and a monthly review leadership actually attends.

Case Study: The Audit That Turned “Not Sure” Into a Plan
A division head answered “not sure” to seven of twelve readiness indicators. Four weeks of asking — not surveying — turned the blind spots into the year's adoption roadmap.