An AI policy should help employees make good decisions at work. It should not be a 40-page document copied from a software company and stored where nobody can find it.

For most dealerships, the useful starting policy is two to four pages supported by an approved-tools list, a use-case register, and department SOPs. The policy establishes boundaries. The SOP explains how one workflow operates.

Name one accountable executive

Assign an executive sponsor who can approve use cases, require remediation, and stop a system. Day-to-day administration may sit with IT, marketing, operations, or a project lead, but risk cannot belong to “everyone.”

Create a small review group for customer-facing or data-sensitive work. Include the operating manager, security or IT lead, and appropriate legal or compliance reviewer. Add HR when employee data or employment decisions are involved.

Maintain an approved-tools list

The list should show:

  • Tool and vendor.
  • Approved users and departments.
  • Approved use cases.
  • Allowed data categories.
  • Prohibited data categories.
  • Required human review.
  • Contract owner and renewal date.
  • Security and legal review status.

Employees should know that public consumer AI accounts are not automatically approved for customer records, finance information, employee data, dealership credentials, contracts, or confidential business information.

Classify uses by risk

Lower risk

Brainstorming, rewriting non-confidential text, summarizing public information, preparing training outlines, or drafting internal checklists. Outputs still require human review.

Moderate risk

Drafting customer communications, analyzing approved call transcripts, prioritizing leads, summarizing operational reports, or generating advertising concepts. Require an owner, quality review, source validation, and defined data access.

Higher risk

Autonomous customer contact, pricing claims, credit or finance activity, employment decisions, safety guidance, legal interpretation, broad DMS access, biometric data, or actions that materially affect a consumer. Require formal approval, counsel, security review, testing, monitoring, and strong human control. Some uses should remain prohibited.

Define the data rule in one sentence

Use the minimum data needed, only in an approved system, only for the approved purpose, and retain it only as long as required.

That sentence should connect to the dealership’s broader information security program. The FTC’s Safeguards Rule guidance for automobile dealers describes written risk assessments, access controls, encryption, multifactor authentication, monitoring, training, service-provider oversight, and incident obligations for covered customer information.

An AI policy does not replace those controls. It should route AI use through them.

Require human accountability

State that employees remain responsible for verifying AI output before relying on it or sending it, unless a specifically approved automated workflow says otherwise. Require source checking for factual claims.

Human review must be meaningful. Clicking “approve” on hundreds of messages without time or context is automation wearing a human label. Set manageable queues and sample output quality after launch.

Establish customer communication rules

Customer-facing AI should:

  • Identify the dealership accurately.
  • Avoid deceptive claims or fabricated facts.
  • Respect channel consent and opt-outs.
  • Provide a practical path to a person.
  • Escalate complaints, threats, sensitive issues, and low-confidence responses.
  • Preserve the interaction in the approved system of record.

Require legal review for automated calling, texting, advertising, financing, and state-specific disclosure obligations. AI changes the production method, not the dealership’s responsibility for the message.

Keep a use-case register

For every approved workflow, record the purpose, owner, vendor, users, source data, actions, human controls, KPIs, risk metrics, approval date, next review date, and current status.

This register answers a question leadership will eventually ask: “Where is AI acting inside our store right now?” Without it, shadow AI spreads through browser tabs and vendor features.

Create an incident path

Employees need a simple method to report incorrect output, unauthorized data exposure, discriminatory behavior, misleading communication, security concerns, or unexpected automated action.

The response should include:

  1. Pause or contain the workflow.
  2. Preserve relevant logs and records.
  3. Notify the responsible owner and required internal teams.
  4. Assess affected people, data, systems, and obligations.
  5. Correct the process, test the correction, and document restart approval.

Do not allow a vendor to quietly “tune the model” without a record of what failed and how the dealership verified the fix.

Review quarterly and after material change

Review the policy, approved tools, incidents, adoption, and vendor access at least quarterly. Trigger an additional review when a vendor changes models, adds autonomous actions, changes data practices, introduces a new integration, or expands into another department.

NIST’s AI Risk Management Framework is voluntary, but its govern, map, measure, and manage structure is a useful backbone. A dealership can apply it proportionally without turning operations into a standards exercise.

Sources and further reading

This template is an operational starting point, not legal advice. Adapt it with qualified counsel and the dealership’s security, privacy, HR, advertising, communications, OEM, and state-law requirements.