My test: if it generates a policy without asking about your stack, it is a mail merge with your logo on it. - Specificity first. It should ask which models you use, self-hosted or API, what data goes into prompts. No questions, no policy. - The forgotten sections: approved models with versions, data classification, vendor review triggers, exception sign-offs, violation consequences. - Maintenance: does it remind you to review, or sell you a PDF and disappear? Policies rot. The reminder is the product. - Export and ownership: your policy should live in your docs, version controlled, not locked inside someone's app. - Endgame: a short document the team has actually read and signed, reviewed quarterly. I compare 200 models, and PrivateLLM deploy sets up the licensed model on your own AWS for $50 plus usage.