policy templates
AI Acceptable Use Policy Template
A starting policy governing employee use of AI tools — what's permitted, what requires approval, and what's off-limits — built to be adapted, not used verbatim.
This template covers the most common gap we see in early-stage AI governance: no written policy at all governing what employees are actually allowed to do with AI tools, which means the organization's real AI risk exposure is whatever individual employees happen to decide on their own. Adapt every bracketed section to your organization before adopting it — this is a starting point, not a finished legal document, and should be reviewed by counsel before formal adoption.
1. Purpose and scope
This policy governs the use of artificial intelligence tools — including generative AI, machine learning-based analysis tools, and AI features embedded in third-party software — by all employees, contractors, and temporary staff of [Company Name] ("the Company") in the course of their work.
This policy applies regardless of whether the AI tool is formally procured by the Company or independently adopted by an employee or team ("shadow AI"). Use of any AI tool in a work context is subject to this policy whether or not the tool appears on the approved tools list in Section 3.
2. Data handling rules
Employees must not input the following into any AI tool that has not been specifically approved for that data category by [designated approver, e.g., the Data Protection Officer or IT Security]:
- Customer personal data, including names, contact information, financial information, or any data classified as sensitive under applicable privacy law
- Confidential business information, including unreleased financial results, strategic plans, or trade secrets
- Source code or credentials belonging to the Company or its customers
- Any data the employee did not create or does not have clear authorization to share externally
Approved tools with a signed data processing agreement and confirmed enterprise-tier data handling (no training on submitted data) may be used for a broader set of data categories — see the approved tools list in Section 3 for tool-specific permissions.
3. Approved tools list
The Company maintains a current list of approved AI tools at [link to internal tools list], categorized by permitted data sensitivity level. Employees must not use AI tools outside this list for work purposes without requesting approval through [approval process/contact]. New tool requests are reviewed on a [timeframe, e.g., "within 5 business days"] basis.
4. Prohibited uses
Regardless of tool, the following uses are prohibited without explicit written approval from [designated approver]:
- Using AI output as the sole basis for a decision materially affecting a customer, employee, or job applicant (employment, credit, pricing, or similar consequential decisions) without human review
- Using AI to generate content that will be represented to a third party as human-authored without disclosure, where such disclosure is legally required or requested
- Using AI tools to process data in a manner inconsistent with the Company's privacy policy or any applicable data processing agreement
- Circumventing this policy's data handling rules by pre-processing data to obscure its sensitive nature before AI input
5. Disclosure requirements
Where an AI system is used in a way that materially influences a decision about a customer, employee, or job applicant, the affected individual must be given clear notice consistent with [Company's applicable legal obligations — reference specific jurisdiction requirements here, e.g., Colorado SB 205 consumer notice requirements]. Consult [legal/compliance contact] before deploying any new AI use case that could trigger a disclosure obligation.
6. Incident reporting
Any suspected policy violation, AI tool malfunction producing materially incorrect output used in a business decision, or suspected exposure of confidential/personal data through an AI tool must be reported to [incident reporting contact/process] within [timeframe, e.g., "24 hours of discovery"].
7. Policy review
This policy is reviewed [frequency, e.g., "every six months, or upon material regulatory change in a jurisdiction where the Company operates"] by [owner, e.g., the AI governance committee].
This template is provided for general guidance and does not constitute legal advice. Have this policy reviewed by qualified counsel familiar with the specific regulatory obligations in your operating jurisdictions before adoption. See our disclaimer for more.
Suggested next reading
regulatory checklists