Free template
AI acceptable use policy template
A ready-to-adapt outline for governing how your staff use generative AI tools, with sample policy language for each section. Copy it, replace the bracketed text and review it with your legal counsel before you adopt it.

Before you start
Why you need an AI policy, and how to use this one
Staff are already using AI tools to draft email, summarize documents and write code, often with personal accounts and without IT knowing. An AI acceptable use policy sets clear rules: which tools are approved, what data can go into them and who is accountable for the output.
This AI policy template is a starting point. Every organization’s regulatory obligations, contracts and risk tolerance differ, so review the final policy with your legal counsel, HR and security team before you publish it.
- Replace text in [brackets] with your organization’s details
- Delete sections that don’t apply, and add any your regulators or contracts require
- Keep a companion list of approved tools that you can update without rewriting the policy
- Train staff on the policy and have them acknowledge it
Disclaimer: This template is general guidance, not legal advice. Review it with qualified counsel before adoption.
The template
Generative AI acceptable use policy
1. Purpose
This policy sets the rules for using artificial intelligence (AI) tools at [Organization]. It is intended to let employees use AI to work more effectively while protecting confidential information, meeting our legal and contractual obligations and keeping people accountable for the work they produce.
2. Scope
This policy applies to all employees, contractors, interns and temporary staff (“users”) who use AI tools for [Organization] business, on any device, whether the tool is provided by [Organization], built into software we already use or accessed through a personal account.
3. Definitions
- AI tool: any software that generates text, images, code, audio or decisions using machine learning, including chatbots, writing assistants, copilots built into productivity software, code assistants, meeting transcription tools and browser extensions.
- AI agent: an AI tool that can take actions on a user’s behalf, such as sending email, changing files, calling APIs or making purchases.
- Approved AI tool: a tool listed on the [Approved AI Tools List] and configured under an [Organization] account.
- Confidential information: information classified as [Confidential or Restricted] under our data classification policy, including client data, personal information, health information, financial records, source code, credentials and non-public business plans.
4. Approved tools
Users may use only approved AI tools for [Organization] business. The [IT or Security team] maintains the Approved AI Tools List, including any restrictions on how each tool may be used. Using personal accounts or free versions of AI tools for work is prohibited unless the tool is explicitly approved for that use.
5. Acceptable uses
Users may use approved AI tools to support their work, for example to draft and edit documents, summarize non-confidential material, brainstorm, research public information, write or review code in approved environments and automate routine tasks, provided they follow this policy.
6. Prohibited uses
Users must not use AI tools to:
- Enter confidential information into any tool that is not approved for that classification of data
- Make or fully automate decisions about hiring, performance, credit, eligibility or other matters that significantly affect individuals without documented human review
- Create content that is unlawful, discriminatory, harassing or deceptive, including impersonating a real person
- Bypass security controls, generate malicious code or test systems without authorization
- Present AI output as professional advice to clients without review by a qualified person
- Connect AI agents to [Organization] systems, accounts or data without approval from [IT or Security]
7. Data protection
Before entering information into an AI tool, users must confirm the tool is approved for that data classification. [Public and Internal] information may be used in approved tools. [Confidential and Restricted] information may be used only in tools approved for that level, under [Organization] accounts where the provider does not use our data to train its models. Never enter passwords, API keys or other credentials into an AI tool.
8. Human review and accountability
AI output can be inaccurate, incomplete or biased. Users are responsible for reviewing and verifying any AI-generated content before relying on it, sharing it or sending it outside [Organization]. The person who uses the output is accountable for it, as if they had written it themselves.
9. Transparency and disclosure
Users must disclose the use of AI when [a client contract, regulation or professional standard requires it, or when content is published externally under the organization’s name]. Users must not represent AI-generated content as the work of a specific person without their approval.
10. Intellectual property
Users must respect copyright, licensing and confidentiality obligations when using AI tools. Do not enter third-party material that we are not permitted to share, and check AI-generated code and content for licensing concerns before using it in products or client deliverables.
11. Security requirements
- Sign in to approved AI tools with [Organization] single sign-on and multi-factor authentication where available
- Install AI browser extensions, plug-ins and integrations only if they are approved
- Grant AI agents the minimum permissions they need, and log the actions they take
- Treat content from AI tools, including links and code, with the same caution as any external source
12. Requesting new tools
Users who want to use a new AI tool must submit a request to [IT or Security] describing the business purpose and the data involved. New tools are reviewed for security, privacy, contract terms and data use before approval, following our third-party risk management process.
13. Reporting incidents
Users must report immediately to [Security contact or help desk] if they believe confidential information was entered into an unapproved tool, an AI tool produced harmful or unexpected output that was relied on, or an AI agent took an unintended action. Reports are handled under our incident response plan.
14. Training and acknowledgment
All users must complete AI awareness training [at onboarding and annually] and acknowledge that they have read and understood this policy.
15. Enforcement, exceptions and review
Violations of this policy may result in loss of access to AI tools and disciplinary action, up to and including termination, consistent with [Organization] policies. Exceptions must be approved in writing by [Policy owner]. This policy is owned by [Policy owner] and reviewed at least [annually] or when laws, tools or business needs change.
- Policy owner: [Name, title]
- Approved by: [Name, title]
- Effective date: [Date]
- Next review: [Date]
Rolling it out
Make the policy stick
A policy only works if people know it exists and the controls back it up.
FAQ
AI policy questions
Related services
Related services
Get help adapting this template
Turn this template into a policy that fits
Tell us about your organization and the AI tools you use or plan to adopt. An advisor will reply by email to talk through a review or a full AI governance program.
Prefer email? Write to [email protected] or call (858) 712-0040.
