policy templates

AI Acceptable Use Policy Template

A starting policy governing employee use of AI tools — what's permitted, what requires approval, and what's off-limits — built to be adapted, not used verbatim.

Legal and compliance staff drafting an AI acceptable use policy document
Photo: Carrie Allen www.carrieallen.com via Unsplash

This template covers the most common gap we see in early-stage AI governance: no written policy at all governing what employees are actually allowed to do with AI tools, which means the organization's real AI risk exposure is whatever individual employees happen to decide on their own. Adapt every bracketed section to your organization before adopting it — this is a starting point, not a finished legal document, and should be reviewed by counsel before formal adoption.

1. Purpose and scope

This policy governs the use of artificial intelligence tools — including generative AI, machine learning-based analysis tools, and AI features embedded in third-party software — by all employees, contractors, and temporary staff of [Company Name] ("the Company") in the course of their work.

This policy applies regardless of whether the AI tool is formally procured by the Company or independently adopted by an employee or team ("shadow AI"). Use of any AI tool in a work context is subject to this policy whether or not the tool appears on the approved tools list in Section 3.

2. Data handling rules

Employees must not input the following into any AI tool that has not been specifically approved for that data category by [designated approver, e.g., the Data Protection Officer or IT Security]:

  • Customer personal data, including names, contact information, financial information, or any data classified as sensitive under applicable privacy law
  • Confidential business information, including unreleased financial results, strategic plans, or trade secrets
  • Source code or credentials belonging to the Company or its customers
  • Any data the employee did not create or does not have clear authorization to share externally

Approved tools with a signed data processing agreement and confirmed enterprise-tier data handling (no training on submitted data) may be used for a broader set of data categories — see the approved tools list in Section 3 for tool-specific permissions.

3. Approved tools list

The Company maintains a current list of approved AI tools at [link to internal tools list], categorized by permitted data sensitivity level. Employees must not use AI tools outside this list for work purposes without requesting approval through [approval process/contact]. New tool requests are reviewed on a [timeframe, e.g., "within 5 business days"] basis.

4. Prohibited uses

Regardless of tool, the following uses are prohibited without explicit written approval from [designated approver]:

  • Using AI output as the sole basis for a decision materially affecting a customer, employee, or job applicant (employment, credit, pricing, or similar consequential decisions) without human review
  • Using AI to generate content that will be represented to a third party as human-authored without disclosure, where such disclosure is legally required or requested
  • Using AI tools to process data in a manner inconsistent with the Company's privacy policy or any applicable data processing agreement
  • Circumventing this policy's data handling rules by pre-processing data to obscure its sensitive nature before AI input

5. Disclosure requirements

Where an AI system is used in a way that materially influences a decision about a customer, employee, or job applicant, the affected individual must be given clear notice consistent with [Company's applicable legal obligations — reference specific jurisdiction requirements here, e.g., Colorado SB 205 consumer notice requirements]. Consult [legal/compliance contact] before deploying any new AI use case that could trigger a disclosure obligation.

6. Incident reporting

Any suspected policy violation, AI tool malfunction producing materially incorrect output used in a business decision, or suspected exposure of confidential/personal data through an AI tool must be reported to [incident reporting contact/process] within [timeframe, e.g., "24 hours of discovery"].

7. Policy review

This policy is reviewed [frequency, e.g., "every six months, or upon material regulatory change in a jurisdiction where the Company operates"] by [owner, e.g., the AI governance committee].


This template is provided for general guidance and does not constitute legal advice. Have this policy reviewed by qualified counsel familiar with the specific regulatory obligations in your operating jurisdictions before adoption. See our disclaimer for more.

Compliance team meeting around a table to review an AI governance framework
Photo: Beatriz Cattel via Unsplash
Most AI governance frameworks fail for the same reason: they're written to look complete in a slide deck, not to survive contact with a real model deployment. Here's what to build first, in what order, and why the sequence matters more than the paperwork.
Governome Editorial Team · 4 min read
Compliance reviewer working through a classification checklist at a desk
Photo: Zulfugar Karimov via Unsplash
Step through this checklist before concluding an AI system falls outside the EU AI Act's high-risk category. It mirrors the actual two-track Article 6 test, not a simplified summary of it.
Governome Editorial Team · 2 min read