30 Days Gen AI Risk Trial -Start Now
Skip to main content
Free AI Policy Template

AI Acceptable Use Policy Template

Start with an editable employee AI policy. Review the six sections, adapt the tools and data rules, and name the people responsible for approval and review.

Make it your policy.

Replace the bracketed placeholders, then review the draft with your security, privacy and policy owners before sharing it with employees.

  1. 01Approved tools and uses
  2. 02Data that may be shared
  3. 03Reporting contact and review date
What this policy covers

An AI acceptable use policy is the employee-facing rulebook that defines how staff may use AI tools at work: which tools are approved, what data is allowed into them, and which uses are prohibited. In 2026 a usable policy has to cover six things, scope (who it applies to), an approved tools list and the process to add new tools, data classification rules for what can and cannot be entered into AI, prohibited uses, accountability and incident reporting, and a review cycle.

The Policy Template

Click each section to expand the policy text. Customise the highlighted placeholders for your organisation.

The DOCX is an English starting point. You can also copy the policy text from this page.

1Section 1, Purpose & Scope

This policy governs the use of artificial intelligence (AI) tools and services by all employees, contractors, and third parties acting on behalf of [Organisation Name]. It applies to all AI tools used for work purposes, whether accessed via company devices or personal devices.

2Section 2, Permitted AI Tools

Employees may use the following categories of AI tools for work purposes:

  • Approved productivity AI tools on the company whitelist (see Appendix A)
  • AI coding assistants approved by IT Security
  • AI writing and summarisation tools approved by IT Security

Employees must not use unapproved AI tools for any work-related task involving company data.

3Section 3, Data Classification & AI Tools

Must NEVER be entered into any AI tool (approved or otherwise):

  • Personal Identifiable Information (PII) of customers or employees
  • Confidential business information (financial data, strategy, M&A activity)
  • Credentials, API keys, passwords, or security configurations
  • Client data or data subject to confidentiality agreements
  • Source code unless the AI tool is explicitly approved for code use

MAY be used with approved AI tools:

  • Non-confidential internal documentation
  • Publicly available information
  • Anonymised data that cannot be re-identified
4Section 4, Prohibited Uses

Employees must not use AI tools to:

  • Generate content that discriminates against protected characteristics
  • Create deepfakes, synthetic media, or impersonations without explicit authorisation
  • Circumvent security controls or conduct security testing without approval
  • Make autonomous decisions affecting individuals without human review
  • Submit work entirely generated by AI without disclosure (where relevant)
  • Use AI tools to exfiltrate, copy, or transfer sensitive data
5Section 5, Accountability & Reporting

Employees must report suspected AI security incidents, data leakage via AI tools, or policy violations to [IT Security Contact] within 24 hours. Non-compliance may result in disciplinary action.

6Section 6, Review & Updates

This policy will be reviewed annually or when significant changes to AI technology or regulations occur. The policy owner is responsible for initiating the review and communicating updates to all employees.

How to Adapt This Template for Your Organisation

The template above is a starting point. Follow these steps to turn it into an enforceable policy for your specific environment.

1
Add your organisation name
Replace all instances of [Organisation Name] with your legal entity name.
2
Build your approved tools list
Populate Appendix A with specific AI tools, versions, and any approved use-case restrictions. Name the IT Security contact for new tool requests.
3
Map data classification tiers
Align Section 3 with your existing data classification policy. Add tier names (e.g. Restricted, Confidential, Internal, Public) and any tool-specific rules.
4
Name your reporting contacts
Replace [IT Security Contact] with a named person or team alias. Include an escalation path for incidents that may involve regulatory notification.
5
Set your review cycle
Define the review frequency (annually is the minimum), name the policy owner, and add a version history table so auditors can track changes.

From a rule to a check

Test one rule before a wider rollout.

A written rule and an observed control are different evidence. Pick an AI app and a supported client, then check the action your policy requires.

What to check

  1. Name the app, account, client and input path.
  2. Choose the expected action for this rule.
  3. Repeat with harmless text as a comparison.
  4. Record the response, event and any unresolved gap.
Check supported product coverage
Illustrative policy rule
Do not submit customer personal information to an AI tool unless your organisation has approved that use.
Synthetic test input
Summarise the renewal notes for Morgan Hale. Contact: morgan.hale@example.com.
Illustrative test plan, not a completed test. Product coverage and policy outcomes depend on the selected configuration.

FAQ

Frequently Asked Questions

What should an AI acceptable use policy cover?
An AI acceptable use policy should cover: the scope of who it applies to (employees, contractors, third parties); a list of approved AI tools and the process for getting new tools approved; data classification rules specifying what data can and cannot be entered into AI tools; prohibited uses such as generating discriminatory content, creating deepfakes, or circumventing security controls; accountability and incident reporting obligations; and a review schedule. Without these elements the policy cannot be enforced and provides no legal basis for action.
What is the difference between an AI acceptable use policy and an AI policy?
An AI policy is the broad governing document that sets your organisation's overall position on AI: principles, roles, risk appetite, procurement standards, and how AI decisions are made and overseen. An AI acceptable use policy (AUP) is the narrower, employee-facing rulebook that sits inside that programme and tells staff exactly what they can and cannot do with AI tools day to day: which tools are approved, what data is allowed, and what is prohibited. In practice the AUP is the part employees sign and the part you actually enforce. Many organisations publish one combined document, but the acceptable use rules are the operative section.
How often should you update an AI acceptable use policy?
Review an AI acceptable use policy at least annually, and sooner whenever something material changes: a new AI tool is approved or banned, a vendor changes its data handling or training terms, your data classification scheme changes, or a regulation such as the EU AI Act reaches a new compliance milestone. Because the approved tools list and data rules move faster than the rest of the document, keep them in an appendix you can revise without reissuing the whole policy. Record a version number, the review date, and the owner so auditors can see the policy is actively maintained.
Do I need a separate policy for ChatGPT?
You do not need a separate ChatGPT policy if your AI acceptable use policy includes a clear approved tools list and data handling rules. Reference ChatGPT by name in your approved or prohibited tools list as appropriate. If ChatGPT Enterprise is approved for internal use, specify which version, which data tiers are permitted, and whether your contract with OpenAI includes a no-training clause. A single comprehensive policy that names specific tools is cleaner to enforce than multiple tool-specific documents.
Is an AI acceptable use policy required under the EU AI Act?
The EU AI Act does not prescribe an acceptable use policy by name, but it does require deployers of high-risk AI systems to implement appropriate governance measures, conduct fundamental rights impact assessments, and maintain human oversight. ISO 42001 (AI Management Systems) and NIST AI RMF both explicitly require documented AI use policies as part of a compliant AI governance programme. Regulators and auditors increasingly expect to see a documented AI policy as baseline evidence of AI governance maturity.
How do I enforce an AI acceptable use policy?
Enforcing an AI acceptable use policy requires both technical controls and procedural measures. Technical controls include blocking unapproved AI tools at the network or endpoint level, deploying data loss prevention (DLP) tools that detect sensitive data being sent to AI services, and using an AI security platform to monitor which AI tools employees are accessing. Procedural measures include requiring employees to sign the policy, training staff on their obligations, logging violations, and having a clear disciplinary process. A policy without technical enforcement is aspirational, not operational.
Put the policy into practice

Bring one rule. Review the control.

Bring the AI app, data type and employee action you need to evaluate. We will review the supported client and the evidence to collect.

AI Acceptable Use Policy Template (2026), Free Employee Download | Aona AI