AI-Assisted Policy Drafting and Updates
Overview
Your HR team needs to update the remote work policy. Someone asks AI: "Draft a remote work policy for our company." AI produces 2,000 words of plausible-sounding policy language. It looks professional. It feels like it covers all the cases. You send it to your legal team. They send it back with seven major changes: "This doesn't comply with state laws. This creates liability around ADA accommodations. This contradicts your benefits policy. This is unenforceable."
Three days of work, now wasted.
The problem: AI is brilliant at generating policy-sounding language. It's terrible at knowing what's actually legal, what actually applies to your situation, and what aligns with your company's other policies. AI hallucinates compliance.
This lesson teaches you the right way to use AI for policy work. The rule is simple: AI never creates policy substance. Ever. But AI can help you take existing policy, improve clarity, update format, and explain it to employees. That's where AI actually helps.
Why This Matters for HR Professionals
Policies are legal documents. If they're wrong, they create liability. If they're unclear, employees get confused and make bad decisions. If they're inconsistent with each other, you have conflicts. Policies are also your protection. They document what you're allowing, requiring, and protecting against.
The stakes in policy are high. You can't afford to have AI hallucinate compliance requirements. You need your policies accurate. So AI's role is limited: drafting help, clarity improvement, employee communication, but never substance creation.
Most HR leaders get this wrong. They ask AI to "write our remote work policy" when they should ask AI to "clarify this existing policy language" or "rewrite this policy to be shorter and clearer."
This distinction matters more than you think. A poorly drafted policy that sounds good but has legal holes can expose your company to litigation, discrimination claims, or regulatory fines. But a clearly written, compliant policy that employees understand? That reduces disputes and builds trust.
The Right Way: Use Existing Policy as Source Truth
Here's the rule: Never ask AI to create policy substance. Always provide the accurate policy to AI and ask it to help with clarity, formatting, or communication.
The wrong way:
"Draft a flexible work policy for our company."
The right way:
"Here's our existing flexible work policy. It's 2,000 words and employees say it's hard to understand. Rewrite it to be clearer and shorter (under 800 words) without changing the actual rules. Use simple language. Include examples."
In the second example, you're using AI as a clarity tool, not a policy creator. The substance comes from your actual policy. AI just makes it better to read.
Another example:
Wrong: "Create an expense policy covering travel, meals, and office supplies."
Right: "Here's our expense policy. Some employees are confused about what meal expenses count, and about approval authority. Rewrite the meal section with 3-4 examples of what does/doesn't qualify. For approval, clearly state who approves what amounts."
You're not asking AI to create rules. You're asking it to clarify and exemplify your existing rules.
Why This Distinction Matters
The difference between "create policy" and "clarify policy" is the difference between liability and protection. Here's a real scenario:
A 200-person tech company asked AI to "draft a remote work policy from scratch." The AI produced something sensible on the surface: "Employees may request remote work with manager approval." But the policy didn't specify what happens to ADA accommodations for people with disabilities who need remote work. It didn't say whether remote workers had to come in for all-hands meetings. It didn't address timezone conflicts.
When an employee requested remote work for an ADA accommodation (chronic pain, needed home setup), the manager denied it based on the vague policy. The company faced an ADA compliance claim.
Compare that to a company that said to AI: "Here's our existing remote work policy, written by our employment lawyer. It explicitly covers ADA accommodations, meeting expectations, and equipment. Make it clearer for employees with examples and an FAQ."
The AI improved clarity. The legal substance stayed intact. When the ADA accommodation request came, the policy already had the answer.
This is why source truth matters. Your lawyer-reviewed policy is the source. AI is the translator and clarifier, not the creator.
The Three-Step Mental Model
When you're thinking about using AI for any policy work, ask yourself:
- Do I need AI to create substance here? (No. Stop. Don't do this.)
- Do I need AI to clarify or explain existing substance? (Yes. This is AI's job.)
- Is this about improving how we communicate policy, not changing the policy itself? (Yes. Proceed with AI.)
If you're at step 1, step away from AI. Talk to your legal team or your policy owner. Get the substance right first.
The Process: Audit, Clarify, Verify
Here's the actual workflow for policy updates:
Step 1: Audit your existing policy
What do you currently say? Is it accurate? Does it cover what you need? Is it consistent with other policies?
Example: You have a remote work policy that says "employees can request remote work." You also have an attendance policy that says "no more than 2 absences per quarter." Are remote work days counted as absences? Your policies don't say. This is a gap.
Fix the gap first. Before you ask AI for help, know what your policy actually needs to say.
Start your audit by asking:
- Does this policy still reflect how we actually operate? (If your handbook says "annual performance reviews in December" but you do them in June, fix that first.)
- What situations is this policy unclear about? (Where do employees ask for clarification?)
- Where does this conflict with other policies? (Check your full handbook for contradictions.)
- Is there case law or regulatory changes that affect this policy? (Have employment laws changed since we wrote this?)
- Who in the organization actually knows and understands this policy? (If only your founder knows it, it's not clear enough.)
Real audit scenario: A 50-person company inherited a "work schedule" policy from their previous HR person. It said "working hours are 9 to 5." But the company had flex hours, work-from-home, and customer service people on night shifts. The policy was technically accurate but completely outdated. Before sending to AI, they updated it to reflect reality: "Core hours are 10-2pm for collaboration. Outside core hours, you set your schedule based on your role and manager agreement."
Step 2: Use AI to clarify the language
Once your policy substance is right, use AI to make it clear.
Paste your policy and ask: "This policy is the source of truth. I want to make it clearer for employees while keeping the substance exactly the same. Rewrite it: shorter (under 800 words), simpler language, add 2-3 examples of common situations."
AI returns a clearer version. You check: "Does this say the same thing as the original?" If yes, you're moving forward. If AI changed the meaning, you know to reject it.
Concrete AI prompt for clarity work:
"Here's our current [topic] policy: [paste]. Rewrite this for employees who might not read the whole thing. Target: 400-600 words. Structure: 1) What this policy is about (one sentence), 2) The main rules (simple language, bulleted), 3) Three real examples of situations and what the policy says about them, 4) How to ask questions/get exceptions. Keep the exact same rules; just make it more readable."
AI's output should feel like your policy sounds when explained by a friendly HR person over coffee, not like legal language.
Step 3: Verify against legal/compliance requirements
Before you finalize the policy, someone who understands your state laws and your company structure needs to verify it's compliant.
This is non-negotiable. For any policy that touches benefits, employment status, accommodations, or compliance (FMLA, ADA, wage/hour), have a lawyer review before you publish.
What needs legal review?
- Remote work / flexible work policies (ADA implications)
- Time off policies (FMLA, state family leave, vacation, sick time)
- Compensation policies (wage/hour law, pay equity)
- Discipline and termination (wrongful termination risk)
- Accommodation requests (ADA, state disability law)
- Anti-discrimination policies (federal and state)
- Confidentiality and IP policies (can be enforceable or not depending on state)
- Safety policies (OSHA requirements)
What doesn't need legal review every time?
- Office equipment policies
- Expense policies (unless they have tax implications)
- Social media policies (though nice to have legal eyes on this)
- Dress code (unless it impacts protected classes)
Budget for a lawyer review. A one-time policy review costs $1,000-3,000. A wrongful termination lawsuit costs $50,000+. Do the math.
Important: AI is a clarity tool for policy, never a compliance tool. Always verify compliance with actual legal expertise.
Common Policy Topics: How to Approach Each
Remote Work Policy
Wrong approach: Ask AI to draft a remote work policy.
Right approach:
1. Define what you actually want: "Can people work from home? Always? Sometimes? How do they request it? Who approves?"
2. Provide context: "We're a 200-person company. We have offices in [cities]. Most of our work is cloud-based except [specific team] needs in-office."
3. Ask AI to help with clarity: "Here's what I want to say about remote work: [your draft]. Rewrite this more clearly. Include examples: 'Example: A software engineer can work remote most of the time but should come in for sprint planning.' Add sections: How to request, what approval looks like, what happens if someone abuses it."
Common remote work policy gaps:
- What about ADA accommodations? (If someone needs remote work for a disability, that's not optional.)
- Time zone rules? (If you're hiring remote across zones, when do people need to overlap?)
- Equipment and setup? (Do you provide office equipment to remote workers? Setup allowance?)
- Coworking spaces? (Can remote workers use company-provided spaces or must they set up at home?)
- Tax implications? (If you hire someone to work remote from another state, you may have tax and unemployment insurance obligations there.)
- Communication expectations? (Slack on all day? Cameras on during meetings? Flexible work hours?)
Real scenario: A company had a remote work policy that said "remote work is allowed with manager approval." A manager denied a remote request from someone with anxiety disorder who had good performance. The employee complained to HR. HR realized the policy didn't account for ADA, and now they had a mess. The rewritten policy explicitly says "accommodation requests related to disability are not discretionary; follow the accommodation process."
Time Off / PTO Policy
Wrong approach: Ask AI to create a comprehensive PTO policy from scratch.
Right approach:
1. Know your policy: How many days do people get? How do they accrue? Can they carry over? What happens at termination?
2. Provide to AI: "Here's our PTO policy. Most people don't understand the accrual calculations and when they can take time. Explain the accrual system with examples: 'If you work full-time, you accrue X per month. Here's what that looks like over a year.'"
Common PTO policy gaps:
- FMLA compliance? (If you have 50+ employees, FMLA applies. Is your policy consistent with it?)
- State requirements? (Some states mandate sick leave, paid time off, family leave. Is your policy at least as generous?)
- Part-time and contractor rules? (Does your policy cover them or just full-time?)
- Payout at termination? (State law varies. What do you actually owe?)
- Carryover and use-it-or-lose-it? (Some states prohibit use-it-or-lose-it. Others allow it. Know your state.)
Real scenario: A company had a "use it or lose it" vacation policy. In California, this is illegal. An employee sued for unpaid vacation. Now they had to pay out all unused vacation plus penalties. The rewritten policy accounts for state law.
Work-from-Home During COVID (or any crisis)
Wrong approach: Ask AI to draft an emergency work policy.
Right approach:
1. You decide: What are you actually allowing? Remote work? Which roles? What about collaboration expectations?
2. Provide to AI: "We're moving to full-time remote work. Here's what we need to communicate to employees. Help me write this clearly: what's changing, when, what they need to do, how to reach IT support."
Crisis policy considerations:
- Is this temporary or permanent? (Affects how you communicate and what you build for.)
- Equipment provision? (Laptop, monitors, chairs? What's covered?)
- IT support? (24/7 helpline? Email only?)
- Mental health support? (Crisis increases stress and isolation.)
- Communication tools? (Video conference expectations, working hours, availability.)
- Team continuity? (If someone gets sick, who covers their work?)
Real scenario: During a pandemic, a company issued a "work from home immediately" email but didn't specify whether people needed manager approval, what hours they were expected to work, or what tools to use. Chaos followed. The revised policy was clear: "Effective immediately: all work is remote. We'll transition to permanent remote later and give 30 days notice. For now: manager approval not needed. Use [tools] for communication. We know things are uncertain; we'll update this weekly."
Updating Existing Policies: The Revision Workflow
Sometimes you need to update a policy because circumstances changed.
Scenario: Your remote work policy was written assuming offices would reopen. Now you're remote-first. The old policy says "remote work is approved on a case-by-case basis." New policy should say "everyone is remote by default."
How to use AI:
"Our old remote work policy (below) assumed offices would reopen. We're now fully remote. Here's what needs to change: [list the changes]. Rewrite the policy to reflect remote-first, removing references to office-based defaults."
AI takes the old policy and updates it. You check: "Does this say what I need it to?" If yes, send to legal. If no, ask AI to adjust.
This is much better than rewriting from scratch. You're keeping the good parts and changing the specific parts.
Policy Clarification: Where AI Really Shines
AI actually excels at one policy task: explaining policies to employees.
How to use it:
"Here's our expense policy. Create an FAQ for employees: What expenses count? What doesn't? When do I need approval? Give 3-4 concrete examples for each category."
AI produces:
Q: "Can I expense dinner when I'm traveling for work?"
A: "Yes, if it's a meal while traveling. Budget: $50/day for meals. If you go over, you need your manager's approval."
Q: "Can I expense coffee with a client?"
A: "No. Coffee with colleagues is not a reimbursable meal. Coffee with a client (business development) is, up to $15 per person."
This is incredibly useful. Employees understand the policy. They know what to do. You get fewer questions and fewer policy violations because people understand.
The Three Checks Before Publishing Policy
Before any policy goes to employees:
Check 1: Accuracy
Does this accurately reflect what we're allowing/requiring? Is anything missing or wrong?
Check 2: Compliance
Does this comply with applicable laws (state, federal, industry)? Does it respect ADA, FMLA, wage/hour law, anti-discrimination law? Have a lawyer review.
Check 3: Consistency
Does this align with our other policies? If this says "manager approval" and another policy says "no one needs approval for X," you have a conflict.
Tip: Before you publish any policy, create a checklist: Accurate? Compliant? Consistent? Check all three before it goes to employees.
Try This Now: Three Exercises
Exercise 1: Audit a Current Policy
Pick one of your company policies (remote work, PTO, expenses, whatever). Read it all the way through.
Write down:
- Is this clear to employees? (Be honest. Would you understand it if you were new?)
- Is there anything confusing or ambiguous?
- Are there situations the policy doesn't cover? (What questions do employees ask that aren't answered?)
- Is this consistent with related policies? (Check your handbook for contradictions.)
- When was this written? (If it's more than two years old, it might be outdated.)
- Has the law changed? (State employment law changes frequently.)
If you found problems, that's your policy audit. Now you know what needs fixing.
Audit prompt for AI (to find gaps):
"Here's our [topic] policy: [paste]. Based on this, what situations or edge cases might employees be unclear about? What questions would you predict employees asking? What compliance risks do you see?"
Use AI's response to identify what your policy is missing, then fix the substance yourself before asking AI to clarify.
Exercise 2: Clarify Existing Language (With Comparison)
Take a policy you identified as unclear. Ask AI: "Rewrite this policy to be clearer (shorter, simpler language, add 2-3 examples) without changing the substance at all. After your rewrite, list what you changed and why. [Paste policy]."
Compare original to AI version side by side. Does AI's version say the same thing? If yes, great, could you use this? If it changed meaning, ask AI to revise and be more literal to the original.
Clarity exercise prompt:
"Original policy: [paste]
Make this clearer for employees. Target word count: [shorter length]. Use this structure: 1) What this policy means in one sentence, 2) The actual rules (keep exact same rules), 3) Three examples of real situations and what the policy says, 4) How to get exceptions or ask questions. Don't change what the policy allows/requires; just make it more readable."
Count the words in both versions. Usually, clarity reduces word count because you're removing legal jargon.
Exercise 3: Create an Employee FAQ
Take a policy that gets questions (you know which ones, managers and employees ask about them). Ask AI: "Create a 5-7 question FAQ for employees about this policy. Include the most common misunderstandings people have about it. [Paste policy]."
Review the FAQ. Is it accurate? Would this help employees understand?
FAQ exercise prompt:
"Here's our [topic] policy: [paste]
Create an FAQ section that answers the questions employees actually ask about this. Include common situations that confuse people. Format: Q: [question] A: [clear answer with examples]. Make the language casual and helpful, like explaining to a colleague, not legal language."
Then do this critical step: **show the FAQ to 2-3 employees and ask: "Does this answer what you actually wonder about?" Their feedback is gold.
Exercise 4 (Optional but Powerful): Create an Exception Request Form
Some policies need exceptions sometimes. Instead of having employees guess if they can ask, make the exception process clear.
Ask AI: "Create a one-page form for employees to request an exception to this policy: [paste policy]. The form should explain: what the policy normally says, when exceptions might be considered, how to request one, how long review takes, who decides. Make it friendly and clear that exceptions are possible."
This is useful for remote work exceptions, PTO carryover exceptions, equipment exceptions, etc.
Why this matters: When the exception process is clear, you get fewer surprise requests and employees feel heard.
Practical Application - "What to Do Monday Morning"
Stop asking AI to create policy. Full stop.
For policy updates you need, use this workflow:
- Audit your current policy (what needs changing?)
- Provide current policy to AI as source truth
- Ask AI to clarify/update/improve readability (not substance)
- Have legal review before publishing
Create policy FAQs with AI. This is where AI helps most. Explaining policies to employees, not creating them.
For any policy touching compliance (FMLA, ADA, wages, benefits), get legal review. Not optional. Built into your process.
Maintain a policy changelog. What changed? When? Why? This protects you if questions arise later.
Key Takeaways
- AI creates policy substance: Bad idea. Don't do it.
- AI clarifies existing policies: Good idea. Use it.
- AI explains policies to employees: Great idea. FAQs, examples, all helpful.
- Always verify compliance: With legal, not with AI.
- Policies need three checks: Accurate, compliant, consistent.
- Use AI for clarity and communication, not creation.
FAQ
Q: Can I use AI to help me think through policy decisions?
A: Yes. "What should our flexible work policy cover?" is a brainstorm question. AI can help you think through options and considerations. But then you decide the actual policy (using your business needs, legal advice, and company values), and you provide that to AI for clarity help. The decision-making happens in your head and in conversation with legal; AI is a thought partner, not a decision-maker.
Q: What if I don't have a legal team to review policy?
A: Hire an employment lawyer for policy review. It costs money upfront but saves money in liability later. Budget for it. For smaller companies: hire a lawyer once a year to review major policies. Cost: $2,000-5,000. Saves you thousands in prevented disputes. You can also find employment law resources through professional organizations like SHRM, which offer template policies, or through online services like Rocket Lawyer (not legal advice, but helpful starting points that you then customize). The key: some lawyer eyes on anything touching employment law.
Q: Can I use AI to compare our policy to what other companies do?
A: Definitely. "How do other companies structure remote work policies?" is a good research question. AI can help you brainstorm what's common. But then you decide what's right for you, not copy someone else. Every company has different needs: you might be fully distributed, your competitor might be office-first. Copy their policy, and it won't fit. Better approach: understand what options exist, then design for your situation.
Q: What about policy for new situations (like AI use in the workplace)?
A: You decide what your policy should be first (research best practices, think through what you want, maybe consult legal about liability). Then provide that to AI for clarity help. For emerging topics, AI won't have the answer. You need to think it through. Example: "Should employees use AI tools to draft customer emails?" You and your team decide. Then ask AI to help you write that decision clearly.
Q: How do I know if my policy is compliant?
A: Have a lawyer review it. That's the only reliable way. If you can't afford a lawyer for everything, at least do compliance-heavy areas: FMLA, ADA, wage/hour, anti-discrimination, leave policies. Budget $1,500-3,000 per major policy review. If you're in a regulated industry (finance, healthcare), also include industry-specific policies. If someone gets hurt or sues, they'll have lawyers. Make sure you do too.
Q: What if my company operates in multiple states?
A: You need a multi-state policy or state-specific policies. Employment law varies wildly. California mandates paid sick leave; other states don't. Some states require notice before requiring remote work; others don't. Multi-state companies often have a "default policy" that meets the strictest state requirement, then additional policies for specific states. Ask your employment lawyer: "What do we need to do differently for employees in [state]?" They'll tell you. Then create state-specific addendums. Use AI to clarify these, not create them.
Q: How do I handle policy changes without angering people?
A: Announce changes clearly. Be honest about why. If it's a reduction in benefits, explain: "Here's the change, here's why (financial/legal/operational), here's what we're keeping, here's what we're offering instead." Use AI to help draft a clear, honest announcement, but you write the message and the reasoning. Employees can handle bad news if it's honest. They hate opacity.
Q: Can AI generate policies faster than a lawyer?
A: Yes. Much faster. But faster ≠ better. A policy that AI generated in 2 hours but creates legal liability is worse than a policy a lawyer spent a week on. You want both: AI makes clarity and efficiency work happen. The lawyer makes compliance happen. Use them together.
Q: What if I find a great template online?
A: Templates are starting points, not finished products. A template written for a 500-person financial services company might not fit your 30-person marketing agency. Customize heavily. Have a lawyer review before publishing. Template + customization + legal review = good policy. Template alone = risky.
What's Next
Policies guide how things work. Lesson 3.2 is about communicating those policies and changes to employees: announcements, difficult messages, and internal communications. How to use AI to draft messages that are clear, honest, and appropriate to sensitive topics.
Skill.re