AI Acceptable Use
Policy Template
Start with an editable employee AI policy. Review the six sections, adapt the tools and data rules, and name the people responsible for approval and review.
Make it your policy.
Replace the bracketed placeholders, then review the draft with your security, privacy and policy owners before sharing it with employees.
- 01Approved tools and uses
- 02Data that may be shared
- 03Reporting contact and review date
What this policy covers
An AI acceptable use policy is the employee-facing rulebook that defines how staff may use AI tools at work: which tools are approved, what data is allowed into them, and which uses are prohibited. In 2026 a usable policy has to cover six things, scope (who it applies to), an approved tools list and the process to add new tools, data classification rules for what can and cannot be entered into AI, prohibited uses, accountability and incident reporting, and a review cycle.
The Policy Template
Click each section to expand the policy text. Customise the highlighted placeholders for your organisation.
The DOCX is an English starting point. You can also copy the policy text from this page.
1Section 1, Purpose & Scope
This policy governs the use of artificial intelligence (AI) tools and services by all employees, contractors, and third parties acting on behalf of [Organisation Name]. It applies to all AI tools used for work purposes, whether accessed via company devices or personal devices.
2Section 2, Permitted AI Tools
Employees may use the following categories of AI tools for work purposes:
- Approved productivity AI tools on the company whitelist (see Appendix A)
- AI coding assistants approved by IT Security
- AI writing and summarisation tools approved by IT Security
Employees must not use unapproved AI tools for any work-related task involving company data.
3Section 3, Data Classification & AI Tools
Must NEVER be entered into any AI tool (approved or otherwise):
- Personal Identifiable Information (PII) of customers or employees
- Confidential business information (financial data, strategy, M&A activity)
- Credentials, API keys, passwords, or security configurations
- Client data or data subject to confidentiality agreements
- Source code unless the AI tool is explicitly approved for code use
MAY be used with approved AI tools:
- Non-confidential internal documentation
- Publicly available information
- Anonymised data that cannot be re-identified
4Section 4, Prohibited Uses
Employees must not use AI tools to:
- Generate content that discriminates against protected characteristics
- Create deepfakes, synthetic media, or impersonations without explicit authorisation
- Circumvent security controls or conduct security testing without approval
- Make autonomous decisions affecting individuals without human review
- Submit work entirely generated by AI without disclosure (where relevant)
- Use AI tools to exfiltrate, copy, or transfer sensitive data
5Section 5, Accountability & Reporting
Employees must report suspected AI security incidents, data leakage via AI tools, or policy violations to [IT Security Contact] within 24 hours. Non-compliance may result in disciplinary action.
6Section 6, Review & Updates
This policy will be reviewed annually or when significant changes to AI technology or regulations occur. The policy owner is responsible for initiating the review and communicating updates to all employees.
How to Adapt This Template for Your Organisation
The template above is a starting point. Follow these steps to turn it into an enforceable policy for your specific environment.
From a rule to a check
Test one rule before a wider rollout.
A written rule and an observed control are different evidence. Pick an AI app and a supported client, then check the action your policy requires.
What to check
- Name the app, account, client and input path.
- Choose the expected action for this rule.
- Repeat with harmless text as a comparison.
- Record the response, event and any unresolved gap.
- Illustrative policy rule
- Do not submit customer personal information to an AI tool unless your organisation has approved that use.
- Synthetic test input
- Summarise the renewal notes for Morgan Hale. Contact: morgan.hale@example.com.
FAQ
Frequently Asked Questions
What should an AI acceptable use policy cover?
What is the difference between an AI acceptable use policy and an AI policy?
How often should you update an AI acceptable use policy?
Do I need a separate policy for ChatGPT?
Is an AI acceptable use policy required under the EU AI Act?
How do I enforce an AI acceptable use policy?
Bring one rule. Review the control.
Bring the AI app, data type and employee action you need to evaluate. We will review the supported client and the evidence to collect.