Most companies without an AI policy aren't avoiding the topic. They're stuck between two bad options: write something so restrictive employees ignore it, or stay silent and hope nobody pastes client data into ChatGPT. Chris McGlasson, fractional CIO and founder of ClearStack Advisory, works with companies in the $10M-$20M revenue range on exactly this problem, and his answer is a framework he calls the PACT model: Purpose, Access, Classification, Training.

At this size, a company usually has enough employees and enough client data at risk to need real policy, but not enough IT headcount to write and maintain one. That gap is where most AI policy failures happen.

What an AI policy actually needs to cover

An AI usage policy isn't a list of banned tools. It's a set of decisions about four things: why employees are allowed to use AI at work, which tools are sanctioned, what data can touch those tools, and how people learn the rules well enough to follow them without checking a document every time.

1. Purpose: define what AI is for at your company

Before writing rules, decide what problem the policy solves. Most companies land on some mix of three goals: protecting confidential data, maintaining output quality and accountability, and giving employees clear permission to use AI productively instead of doing it quietly and unsupervised. Chris McGlasson notes that the last one gets skipped constantly, and it's the reason policies fail. Employees are already using AI. A policy that only restricts, without acknowledging legitimate use, pushes that activity underground.

2. Access: name the approved tools

List the specific AI tools employees are authorized to use, by name, with the business or enterprise tier required. "AI tools" as a category isn't enforceable. "Claude and ChatGPT under our business plan, no personal accounts" is. This section should also state what happens with tools not on the list: outright banned, or available with manager approval for a specific use case.

3. Classification: define what data can and can't go into AI tools

This is the section that actually prevents incidents. Chris McGlasson's approach borrows from standard data classification tiers, scaled for the kind of data a $10M-$20M company actually holds:

Most policy failures happen because companies skip this tier system and write one blanket rule that either blocks legitimate low-risk use or allows confidential data through a consumer-grade free account. At this revenue range, that single gap is often the difference between a minor internal correction and a client relationship problem.

4. Training: make the policy something people actually follow

A policy nobody reads is not a policy. Chris McGlasson recommends a short, mandatory onboarding session (30 to 45 minutes) covering the classification tiers with real examples specific to that company's data, plus a one-page reference card employees can pull up when they're not sure. Annual refreshers matter more for AI policy than most compliance training, since tool capabilities and risks shift every few months.

What to include in the written policy document

At minimum, the document should state:

Who should own this

In a $10M-$20M company, this usually falls to whoever owns IT or operations, often without the bandwidth or expertise to keep it current as tools change. This is one of the most common reasons companies at this size bring in a fractional CIO: someone who can build the policy, train the team, and revisit it as the AI landscape shifts, without the cost of a full-time executive hire.


Not sure where your IT really stands? Start with a Clarity Audit: a focused assessment of your backups, security, vendors, and AI readiness. It's the first step in every engagement I take on.


About the author: Chris McGlasson is a fractional CIO and the founder of ClearStack Advisory, where he helps mid-market companies build AI governance, IT strategy, and technology roadmaps without the overhead of a full-time CIO. He previously built and sold LANPRO Systems, an IT services firm serving 350+ enterprise clients.