AI policy implementation: full case study

Implementing human-centered AI policy in libraries

Robin Hastings designed and delivered a policy implementation system for libraries that needed to respond to AI already present in staff work, patron questions, and vendor platforms. The work paired durable policy language with guided drafting, staff training, tool governance, and a practical path from informal experimentation to accountable practice.

This case study draws on two completed 2026 engagements: a three-session California Libraries Learn workshop and a ByWater Solutions webinar. It describes the design and delivery of the implementation method. It does not claim that every participating institution adopted a final policy; participant-level adoption and board approval were outside the documented follow-up.

The problem

Libraries did not need another abstract debate about whether AI would arrive. It was already showing up through staff experimentation, patron use, search and office tools, and vendor features. The operational gap was shared guidance:

  • What work may AI assist?
  • What information may never enter an unvetted system?
  • Where must human judgment remain decisive?
  • Who reviews tools and vendor terms?
  • How will staff learn to apply the policy in daily work?

Without answers, decisions become inconsistent. Staff may either use AI without safeguards or avoid useful tools because the boundaries are unclear.

The constraints

The implementation had to work across organizations with different sizes, staffing levels, governance cycles, technical capacity, and appetite for experimentation. It also had to remain useful as product names and features changed.

That meant the policy could not become a catalog of current tools. Durable principles belonged in policy. Tool-specific instructions, examples, and approval steps belonged in procedures and training.

The workshop format added another constraint: three 90-minute online sessions had to move participants from shared vocabulary to policy drafting and then to implementation planning, while leaving time for discussion, breakout work, and peer feedback.

Stakeholder concerns translated into design requirements

Concern Design response
Staff fear or uncertainty Frame policy as permission with boundaries, then practice realistic decisions.
Patron privacy and confidentiality Make data minimization and approved-tool rules non-negotiable.
Accuracy and credibility Require verification of facts, citations, calculations, and claims.
Bias and unequal effects Build perspective checks into human review and training.
Leadership accountability Name owners, approval paths, escalation points, and review dates.
Vendor-created risk Move AI questions into procurement, renewal, and product review.
Fast-changing tools Keep principles durable; move product details into procedures.

The operating model

Human-AI-Human

  1. Define. A person sets the purpose, task, context, constraints, and acceptable inputs.
  2. Assist. AI produces options, drafts, patterns, summaries, or other bounded assistance.
  3. Review and own. A person checks accuracy, privacy, bias, tone, accessibility, and consequences, then decides what to accept, revise, verify, or reject.

The final human step is not ceremonial. It is where professional responsibility lives.

Three safeguards that travel together

  • Privacy: Keep patron, employee, credential, and confidential organizational data out of unvetted systems.
  • Accuracy: Verify facts, citations, calculations, and claims before use.
  • Judgment: Keep meaningful decisions and accountability with people.

None works alone. An accurate answer can still violate privacy. A private answer can still be wrong. A carefully edited answer can still represent an inappropriate delegation of judgment.

Policy as a system

The implementation model connects four layers:

  1. Policy establishes purpose, scope, principles, responsibilities, and boundaries.
  2. Procedures explain tool review, approved uses, documentation, incident response, and escalation.
  3. Training gives staff practice applying the policy to real decisions.
  4. Review uses feedback, vendor changes, incidents, and scheduled reassessment to keep the system current.

From template to implementation

Session 1: define the foundation

Participants mapped where AI was already appearing, examined the risks of having no shared policy, compared short and long templates, and drafted purpose, scope, and guiding principles.

Session 2: make operational decisions

Participants distinguished assistance from decision-making, drafted approved and prohibited uses, addressed patron support and data protection, and selected a workable approach to tool governance.

Session 3: make the policy usable

Participants peer-reviewed draft language, identified staff-training needs, connected the AI policy to collection development, privacy, acceptable use, programming, vendor review, and records management, and named the next steps for approval and rollout.

A practical rollout timeline

Days 1-30: discover and define

  • Inventory current staff, patron, and vendor uses.
  • Name an accountable policy owner and a small review group.
  • Draft purpose, scope, principles, and non-negotiable data boundaries.

Days 31-60: test and prepare

  • Test the draft against realistic scenarios.
  • Review privacy terms, retention, model-training use, and deletion rights.
  • Create tool-request and escalation procedures.
  • Train supervisors and early adopters.

Days 61-90: publish and reinforce

  • Move the policy through the library’s approval path.
  • Run hands-on staff exercises.
  • Publish approved-tool and disclosure guidance.
  • Set feedback channels, owners, and review dates.

The sequence is scalable. A small library may use one responsible owner and a staff meeting; a larger organization may use formal legal, privacy, IT, and procurement review.

Staff training strategy

Training mirrors the decisions the policy requires. Useful exercises include:

  • Compare an AI answer with trusted sources and document what needed correction.
  • Rewrite a prompt to remove personal or confidential data.
  • Decide whether a task is low risk, requires review, or should be prohibited.
  • Review a vendor’s privacy and data-retention terms.
  • Practice disclosing substantial AI assistance in public-facing material.
  • Work through a data incident or misleading-output scenario.
  • Identify a task where AI adds no value and explain why.

Sample policy language

These excerpts are starting points from Robin Hastings’s workshop templates and must be adapted to local policy, law, staffing, and governance.

AI will be used to support human judgment, not replace it. Human oversight is required in all meaningful decisions.

No confidential or personally identifiable patron data may be entered into non-approved AI systems.

AI outputs must always be reviewed before use.

This policy is considered a living document.

Documented delivery signals

  • Three 90-minute workshop sessions were delivered on August 4, 7, and 14, 2026.
  • The registration record contains 14 registrations; 10 records are marked as having attended workshops.
  • Participants received an integrated workbook, three session decks, short and long policy templates, guided drafting prompts, and implementation-planning tools.
  • The second workshop session ran the full 90 minutes, a qualitative signal that discussion and exercises sustained engagement.
  • A separate ByWater Solutions webinar was delivered successfully on August 12, 2026, demonstrating that the framework could be adapted from a multi-session working format to a single-session executive overview.
  • The material was subsequently distilled into a 19-slide conference presentation covering human oversight, risk-based guardrails, vendor review, staff training, and a 90-day path to implementation.

Evidence boundary

The program was designed to leave each participating library with a policy draft, related-policy checklist, and implementation plan. The available records do not verify how many institutions completed board approval or adopted a final policy. Those outcomes are therefore not presented as measured impact.

Lessons learned

  1. Policy publication is the beginning of implementation. Staff need examples, practice, feedback, and reinforcement.
  2. Durable policy and adaptable procedure are different jobs. Tool names and screenshots age quickly; principles and decision rights should not.
  3. Privacy, accuracy, and judgment must be taught together. Treating any one as sufficient leaves obvious gaps.
  4. A usable policy makes ownership visible. Staff need to know who approves a tool, where questions go, and when review happens.
  5. Honest evidence builds more credibility than inflated metrics. Delivery, participation, reusable assets, and transferability are documented; institutional adoption remains to be measured.

What this demonstrates

This work combines policy expertise, systems design, adult learning, facilitation, change management, and practical execution. The result is not only a policy template. It is a repeatable way to help organizations translate public-service values into daily decisions about AI.

Source record

  • Robin Hastings, Creating Generative AI Policies: A Guide for Public and Academic Libraries.
  • CALL workshop project index, participant workbook, policy templates, and Session 1-3 decks.
  • AI Policies for ByWater project index and presentation.
  • Human-Centered AI – MPLA/NLA 2026 presentation.
  • HQ end-of-day records for August 7 and August 12, 2026.

Return to the case-study overview