Who Signed This? The Case Against AI-Written Policies
Governance documents exist to locate a human who stands behind the rule. Generate the text and skip the signature, and you haven't automated governance. You've deleted it.
Strip the letterhead off a code of conduct and ask what's left. Not the text: the text is a commodity now, and AI-written policies have made it close to free. What's left is the part that was always the point: a named human who weighed the trade-offs, put their signature under the rule, and accepted that enforcing it is now their problem. A policy is a promise with a name on it. Generate the promise and skip the name, and you haven't automated governance. You've deleted it.
The incentives explain why this is spreading anyway. Policy drafting is slow, unglamorous work that sits in nobody's bonus structure, and a generative tool produces a plausible conflict-of-interest policy in under a minute. Fast and cheap wins the internal argument every time, so drafts get generated, skimmed and ratified by momentum. But the speed is only a saving if the words were the product. They never were.
What is a company policy actually for?
Follow the mechanism. A governance document is not information; it is an instrument. Its function is to locate accountability: to record that a specific person or body considered a question, made a call, and stands behind the consequences. The drafting is where that consideration happens. Every clause a committee argues over is a decision someone then owns. Hand the drafting wholesale to a model and the words still arrive on time, but the consideration never happened.
You get the receipt without the purchase.
Now run the enforcement scenario, because enforcement is the only moment a policy is real. An employee is disciplined under a clause. They ask the obvious question: who decided this, and why? Under a human-authored regime the answer is a person, a minute, a rationale. Under the generated regime the honest answer is "a text model, tuned on other organisations' boilerplate, unreviewed in the specifics". That is not an answer a rule can survive. A dispute is coming that turns on exactly this provenance question, and the unsigned rulebook will come off badly.
There's a quieter problem underneath. The drafting system is a third party: unnamed, unaccountable, and now co-author of your internal constitution. Its habits and priors, formed on everyone else's documents, flow into yours unexamined. No sane board would let an anonymous consultant write its bylaws sight unseen, yet the economics of generated text invite exactly that, because reading carefully now costs more than the drafting did. When scrutiny is the expensive step, scrutiny is the step that gets cut.
Should you use AI to write company policies?
As a drafting aid, with a human author of record interrogating every clause: defensible. As the author: no. The line between the two is not how much of the text the tool produced; it's whether a human did the deciding. The test is blunt. Could the person who signs the document defend every clause with the tool out of the room? If yes, the tool saved typing. If no, you have an unsigned instrument wearing a signature. This is the same discipline we argue for in keeping humans in control of practical AI, and the same readiness question that applies before any build: if you can't review it, you aren't ready to deploy it. Nobody serious ships generated code to production without review, ownership and a trail. Your rulebook deserves the scrutiny your codebase already gets.
Open source is the early warning here, and it generalises. "Community-governed" is a label businesses price as neutrality and continuity insurance, but the label often describes projects whose real control sits with whoever owns the trademark and appoints the leadership, not with the community that can neither elect nor remove it. Put AI drafting into that mix, in code, in documentation and eventually in governance text itself, and the question stops being cultural. "Who actually authors the rules of our upstream dependencies?" becomes a supply-chain question, and one worth asking with the same rigour you'd apply to a licence audit.
The fix: a sign-off rule for AI-written policies
The control is boring, and it's borrowed straight from software. Every governance document gets a named human author of record. Tool assistance is recorded internally, clause-level review is logged, and the person who signs must be able to explain every provision on demand. Version history is kept, the way a commit log is kept, so that "who decided this and why" always has an answer with a name in it. That is an afternoon of process per document, which is roughly what the drafting tool saved you. If your organisation is redesigning its operating rules around AI, that's the kind of work our technical strategy practice exists for.
None of this is an argument against the tools. It's an argument about what a rule is. A rule is a decision a human stands behind, and everything else is text that resembles one.
A rule nobody signed isn't a rule. It's formatting.
Questions people ask
Is it legal to use AI to draft HR policies?
The live question in a dispute is rarely who typed the document; it's whether the organisation can show a considered, fair rationale for the rule it enforced. AI drafting doesn't make a policy unlawful, but it makes that rationale hard to evidence if no human owned the decisions, and a policy its signer can't explain is fragile exactly when it's tested.
What is a policy provenance record?
It's the governance equivalent of a commit history: who drafted the document, what tools assisted, who reviewed each clause, and who ratified it and when. It turns "who decided this?" from an awkward silence into a lookup, which is most of what legitimacy requires.
Should companies disclose that a policy was drafted with AI?
Internally, yes, always: the author of record, the tooling used and the review trail should be on file before ratification. External disclosure is a judgment call, but internal traceability isn't, because it's the thing you'll need on the day the rule is challenged.
Related
- On Ubuntu 26.04 LTS, the coreutils Your Build Depends On Isn't GNU Anymore
- The Sovereignty Premium: Why Sovereign AI Solutions for Enterprise Are Winning on Access, Not Speed
- Trade-Secret Cases Are Won Years Before Anyone Resigns. Ask Faccenda Chicken.
- Security & Trust
Written by an AI editorial persona of Abyshire's proprietary editorial system and reviewed by our team.