Répondez à dix questions sur votre organisation et regardez une politique IA sur mesure se construire, chaque section reliée aux référentiels qui comptent pour vous : AI Act européen, ISO 42001, NIST AI RMF, RGPD et HIPAA. Environ trois minutes. Aucun email requis pour voir la politique complète.
Comment s'appelle votre organisation ?
Nous l'utilisons pour personnaliser le texte de la politique et le titre du document.
Votre politique : 14 sections, 40 correspondances de référentiels
La politique générée est fournie en anglais.
the organisation
AI Acceptable Use Policy
Version 1.0 · 24 July 2026
CouvreISO/IEC 42001 Clause 5.2NIST AI RMF GOVERN 1.1
This policy sets the rules for how employees, contractors and third parties use Artificial Intelligence (AI) tools and services on behalf of the organisation. Its goal is to let people benefit from AI while protecting the organisation's data, customers, employees and legal position.
This policy takes effect on 24 July 2026 and applies until it is replaced or withdrawn.
CouvreISO/IEC 42001 A.2.2NIST AI RMF GOVERN 1.2
This policy applies to:
CouvreISO/IEC 42001 A.3.2NIST AI RMF GOVERN 2.1
This policy is owned by the policy owner, who maintains the approved tool list, handles approval requests and exceptions, coordinates training and receives incident reports.
Every person covered by this policy is responsible for:
CouvreISO/IEC 42001 A.9.4NIST AI RMF MAP 1.1ISO/IEC 42001 A.10.3NIST AI RMF GOVERN 6.1
the organisation maintains a register of approved AI tools, including their permitted use cases and the highest data classification each tool may handle. Tools not on the register require approval from the policy owner before business use. Current usage in scope for the register includes: the categories adopted as AI usage begins.
To request approval for a new AI tool, submit to the policy owner: the tool name, the intended use case, the data types involved and the vendor's security and privacy documentation. Requests are assessed for security, data handling, vendor terms and regulatory impact before the tool is approved, restricted or declined.
CouvreISO/IEC 42001 A.9.2NIST AI RMF GOVERN 4.1
Approved AI tools may be used for activities such as:
In every case the person using the tool remains accountable for the result. AI output is a draft input to human judgement, not a finished product.
CouvreISO/IEC 42001 A.9.2NIST AI RMF GOVERN 1.1NIST AI RMF GOVERN 1.2
The following are prohibited in all AI tools, approved or not:
AI tool usage by data classification:
| Data classification | AI tool usage |
|---|---|
| Public | Permitted with any approved tool |
| Internal | Permitted with approved enterprise tools only |
| Confidential | Prohibited unless the tool and workflow are explicitly approved for it |
| Restricted | Strictly prohibited in all AI tools |
If you are unsure how information is classified, treat it as Confidential and ask the policy owner before using it with AI.
CouvreISO/IEC 42001 A.9.2NIST AI RMF GOVERN 1.1ISO/IEC 42001 A.10.3NIST AI RMF GOVERN 6.1
Data entered into AI tools remains subject to the organisation's data protection obligations and policies. Before uploading documents or datasets to an AI tool, confirm their classification and your authority to use them. Where a tool offers it, disable chat history and the use of your inputs for model training.
AI vendors processing the organisation information must be under written terms covering confidentiality, security, data residency and the use of inputs for model training. Vendor terms are reviewed by the policy owner as part of tool approval and re-reviewed on material changes.
CouvreNIST AI RMF MEASURE 2.7
When using AI tools:
CouvreISO/IEC 42001 A.9.2NIST AI RMF GOVERN 4.1NIST AI RMF GOVERN 1.1ISO/IEC 42001 A.2.3
All AI output must be reviewed by a person with appropriate knowledge before it is relied on or shared. AI systems produce confident-sounding errors: verify facts, figures, citations and references against original sources. Accountability for work product always remains with the person, not the tool.
Content created with AI assistance in the course of work using company resources is the organisation work product. Be aware that AI output may resemble copyrighted material, and that AI-generated work may have limited copyright protection of its own. Disclose material AI assistance where authorship matters, and consult the policy owner on intellectual property questions before external use.
CouvreISO/IEC 42001 A.9.3NIST AI RMF GOVERN 4.1
Do not misrepresent AI-generated work as entirely human-made where the distinction matters, such as in research, reporting or performance evaluation. When AI has materially shaped a deliverable, say so when asked and in contexts where your audience would reasonably expect to know.
CouvreISO/IEC 42001 Clause 7.2ISO/IEC 42001 Clause 7.3NIST AI RMF GOVERN 2.2
Everyone covered by this policy completes AI acceptable-use training when joining the organisation and an annual refresher. People in roles that use AI heavily receive role-specific training. Training records are maintained by the policy owner.
CouvreISO/IEC 42001 A.3.3NIST AI RMF MANAGE 4.3
Report to the policy owner without delay:
Good-faith reports never result in retaliation. Fast reporting usually shrinks the impact of an incident; silence usually grows it.
CouvreNIST AI RMF MANAGE 4.1ISO/IEC 42001 A.9.2ISO/IEC 42001 Clause 5.2NIST AI RMF GOVERN 4.1
the organisation reserves the right to monitor AI tool usage on company systems and networks to enforce this policy, including network analysis, usage logs and periodic audits of AI-assisted work.
Violations of this policy may result in a warning, revocation of AI tool access, disciplinary action up to and including termination, and legal action where applicable. The response is proportionate to the intent and impact of the violation, and honest mistakes reported promptly are treated differently from concealment.
CouvreISO/IEC 42001 A.2.4NIST AI RMF GOVERN 1.1
This policy is reviewed by the policy owner at least annually, and sooner when relevant regulations change, new AI tools or use cases are adopted, or a significant AI-related incident occurs. Changes are versioned and communicated to everyone covered by the policy.
| Section de la politique | ISO/IEC 42001 | NIST AI RMF |
|---|---|---|
| 1. Purpose | Clause 5.2 | GOVERN 1.1 |
| 2. Scope | A.2.2 | GOVERN 1.2 |
| 3. Roles and Responsibilities | A.3.2 | GOVERN 2.1 |
| 4. Approved AI Tools | A.9.4, A.10.3 | MAP 1.1, GOVERN 6.1 |
| 5. Acceptable Use | A.9.2 | GOVERN 4.1 |
| 6. Prohibited Use and Data Rules | A.9.2 | GOVERN 1.1, GOVERN 1.2 |
| 7. Data Protection and Privacy | A.9.2, A.10.3 | GOVERN 1.1, GOVERN 6.1 |
| 8. Security Requirements | MEASURE 2.7 | |
| 9. Output Review and Intellectual Property | A.9.2, A.2.3 | GOVERN 4.1, GOVERN 1.1 |
| 10. Transparency and Disclosure | A.9.3 | GOVERN 4.1 |
| 11. Training and AI Literacy | Clause 7.2, Clause 7.3 | GOVERN 2.2 |
| 12. Incident Reporting | A.3.3 | MANAGE 4.3 |
| 13. Monitoring and Enforcement | A.9.2, Clause 5.2 | MANAGE 4.1, GOVERN 4.1 |
| 14. Policy Review | A.2.4 | GOVERN 1.1 |
This policy was generated with the Aona AI Policy Generator as a reviewed, framework-mapped starting point. It is not legal advice. Review it with your legal counsel and adapt it to your organisation's circumstances before adoption. Framework references indicate which requirements each section addresses; they are not a certification or a guarantee of conformity.
La plupart des organisations découvrent que leurs employés utilisent déjà bien plus d'outils IA que la politique ne l'anticipe. Aona vous montre ce que votre personnel fait réellement avec l'IA et applique votre politique au point d'usage.