Every Swiss practice that uses AI — a notary's office, a fiduciary, a doctor's surgery, a small firm — slowly builds a list of tools: a dictation assistant here, a summariser there, a chatbot for drafting letters. One day someone asks a simple question: "What exactly do we use AI for here, and where does the data go?" If you cannot answer that in thirty seconds, you need a one-page AI policy.
This is not bureaucracy for its own sake. It is the sensible way to know, at a glance, which tools are allowed, for which tasks, and with which data — and to show that to a client, an employee or an auditor without a scramble.
Why one page is enough
A policy that no one reads is worse than no policy. The goal is not a thick manual; it is a single page that anyone in the practice can understand in two minutes. It answers four questions:
- Which tools? The named services you actually use — the dictation app, the translation assistant, the email drafter.
- For what? The tasks where AI is welcome, and the ones where it is not.
- With which data? What may be pasted in, and what must stay out — client names, patient data, figures.
- Who decides? The human checks every AI draft before it goes out. No exception.
A simple routine to write it
You do not need a lawyer or a consultant to draft the first version. You need one quiet hour and a simple prompt. Give the AI your real situation and let it propose a structure, then you shorten it until it fits on one page.
Step 1 — List what you actually use
Sit down and write out every AI tool anyone in the practice touches in a normal week. Be honest and complete: the dictation software on the phone, the summariser in the meeting app, the chatbot someone uses for letters. This list is the backbone of the policy.
Step 2 — Let the AI draft the page
Hand the AI your list and a few sentences about your data, and ask it to draft the page in plain language:
We are a small Swiss practice (a notary / a fiduciary / a medical office). We use the following AI tools: [list them]. We work with personal and sometimes sensitive data (client files, health data, figures). Please draft a one-page internal AI policy in plain language that covers: (1) which tools are approved, (2) which tasks AI may be used for, (3) which data may never be entered, (4) that every AI draft must be reviewed by a human before it is sent, and (5) a short note on our obligations under the Swiss Data Protection Act. Keep it to one page, in clear sentences, without legal jargon.
Step 3 — Shorten, sign and pin it up
Read the draft once, cut anything vague, and check that the four questions are answered. Then date it, share it with the team, and pin a copy where people actually see it. Review it once a year, or whenever you add a new tool.
A second prompt: the client-ready sentence
Clients are starting to ask how their data is handled. You do not need a long answer — one honest sentence is enough. Ask the AI to turn your policy into it:
From our one-page AI policy, write one sentence for clients explaining that we use AI to help with drafting and organisation, that sensitive data is never entered into public tools, and that a person always reviews the final result.
What the page does for you
- Clarity for the team. Everyone knows what is allowed, so no one improvises with client data.
- Trust with clients. You answer the data question in one sentence instead of hesitating.
- in an audit. You can show, in writing, that AI use is deliberate and documented.
What it is not
A one-page policy is not a substitute for the law, and it is not a guarantee. It is a record of intent and a shared rule. For anything involving sensitive patient data, professional secrecy, or large contracts, the careful step remains: use local or zero-retention tools, and keep the human decision in front.
The outcome
One quiet hour, one page, and the question "what do we use AI for here?" finally has a written answer. You pin it up, forget about it for a year, and get back to the work you are actually good at.