What a policy can and cannot do
An AI policy is often asked to carry the whole framework. It cannot, and understanding its actual job prevents writing a long document that changes nothing.
A policy does three things well. It states which uses are permitted, prohibited, and conditional. It tells people where to go for a decision. And it establishes that someone in the organisation has thought about this, which matters both internally and to an auditor.
It does none of the following. It does not find systems, which is the inventory's job. It does not classify them. It does not make anyone competent. And it does not stop a determined person doing something unwise, particularly if the approved route is slower than the unapproved one.
The most common failure is a policy written as aspiration: we will use AI ethically, responsibly and transparently. Nobody can act on it and nobody can breach it, which makes it unfalsifiable and therefore useless as a control.
The test for every clause: could an employee tell, on Tuesday, whether they are complying with this? If not, rewrite it or delete it.

