Mainframe Path Start learning free
Core10 min readLesson 3 of 3

Team policy, honest measurement and regulation

A short, clear team policy turns good intentions into everyday habits. Teams should measure AI's benefit honestly, including the time spent checking output and the defects it introduces, and stay aware that regulation of AI is growing and differs by country and industry.

Why a team policy

Organisation-wide AI policies are often broad. A team working on core banking batch needs to know concretely what is allowed on Tuesday morning. A good AI usage policy for a mainframe team is short enough to remember and specific enough to follow.

Policy areaExample content
ToolsWhich assistants are approved, for which data classes, and how to request new ones
DataNo production data, secrets or client-restricted code; how to sanitise logs
Use casesEncouraged: explanation, documentation drafts, test case ideas. Needs extra care: production code changes, JCL for production jobs
VerificationMinimum evidence: compile, tests, output comparison for logic changes, independent review
RecordingHow AI assistance is noted in commits or change records
LearningJuniors must be able to explain submitted code; pairing on AI-assisted work
IncidentsWhat to do if sensitive data was shared with a tool by mistake

Measuring benefit honestly

Claims about AI productivity range widely. The only numbers that matter for your team are your own, measured fairly. Count both sides:

Both sides of the ledger
Gains to measure
Time to understand an unfamiliar programTime to draft documentation or testsTest coverage addedOnboarding time for new joiners
Costs to measure
Time spent checking and correcting outputDefects traced to AI-assisted changesReview effortTool cost and administration

It is a perfectly good outcome to find AI helps a lot with explanation and documentation, a little with tests, and not at all — or negatively — with some production changes. Honest measurement lets the team use it where it pays off.

Regulatory awareness

You do not need to be a lawyer, but you should know that AI use sits inside a regulated environment. At a concept level:

What applies depends on your country, industry and how the tool is used. Your compliance and legal teams interpret it; your job is to follow the policy and raise questions when a use case looks new.

A one-page team policy extract (illustrative)
1. Use only assistants on the approved list, via company accounts.
2. Never include production data, secrets or client-restricted code.
3. Logic changes need tests and output comparison before review.
4. Note AI assistance in the commit message.
5. If in doubt, ask. If something leaked, report it the same day.

Common mistakes

Measuring only the gains

Time saved writing is offset by time spent checking. Count both or the numbers will mislead.

A policy nobody reads

Long policies are ignored. Keep the team version short, concrete and part of onboarding.

Hiding an accidental leak

Unreported leaks cannot be contained. Report immediately; good teams treat it as a process failure to fix.

What you will see at work

Key terms

Check your understanding.
Take this lesson's quiz and save your progress. Free.

Take the lesson quiz
← Accountability, audit and change controlBack to AI governance for mainframe teams