Blog AI at Work published September 11, 2026

AI Acceptable Use Policy: How to Write One & Template

Hand checking an AI use policy beside a laptop, with icons for tools, data protection, review, disclosure, and reporting.

An AI acceptable use policy tells employees which AI tools they may use, what data must stay out of them, which work needs human review, and who to ask when they're unsure. You can draft a good one in a week, and it should fit on one to two pages. This tutorial walks through the process and offers a section-by-section template.

This is general guidance for writing an internal policy, and regulations differ by industry and region. Have counsel review your draft before it becomes binding, especially if you handle regulated data.

What You Need to Get Started:

If you haven’t already, check out our complete guide to AI governance at work to get familiar with the complete roadmap. For now, all you need is:

  • Your AI tool inventory, ideally from an amnesty survey. What AI tools are your employees already using without the policy in place? If AI usage is still invisible at your company (known as shadow AI), surface it first.
  • A draft owner, usually an operations lead, plus reviewers from IT or security and your heaviest AI users
  • Two or three real examples of how AI is used at your company today

Step 1: Decide what the AI use policy must answer

A usable policy answers five questions for employees:

  1. Which tools can I use?
  2. What information is prohibited to use?
  3. When does my AI-assisted work need someone else's review?
  4. Do I need to tell anyone I used AI?
  5. Who do I ask when I'm not sure?

Everything else is optional. If a section answers none of these five, cut it.

Step 2: List Approved AI Tools and Account Types

List the sanctioned tools by name, with the account type that's approved. Business and enterprise tiers usually carry different data terms than free consumer versions, so say which tier applies. Name a default tool for common tasks so new employees have an obvious starting point.

Then state the rule for everything unlisted: unlisted tools require a request, and requests get answered within a set number of days. A fast request lane helps to maintain compliance.

Step 3: Define What Data Employees Can Share With AI

This is the section that prevents the worst incidents, so make it concrete. List the categories that must never go into external AI tools, in your company's own vocabulary: customer personal information, financials, contracts, credentials and keys, unreleased product details, employee records. Give one example per category.

State the safe alternative next to each rule where one exists, such as an approved tool whose terms permit that data class. Rules with approved alternatives are more likely to be followed than rigid ones.

Step 4: Set Human Review and AI Disclosure Requirements

Use AI governance risk tiers to decide which tasks require additional review:

  • For low-risk internal tasks, use approved tools with permitted data and review your own output.
  • Work that reaches colleagues or customers: a named staff member reviews before it ships, and the reviewer owns the result.
  • Work affecting rights, money, health, or employment: requires explicit approval in advance, documented review, or in some cases AI should be prohibited.

Add a plain disclosure rule. A simple default might be: disclose AI involvement to whoever receives the work whenever they would reasonably want to know, and always when asked.

Step 5: Name the owner and the ask-first channel

Put a name, or a role, on the policy: who maintains it, who answers questions, who approves new tools. Then give the system a channel, like a Slack channel or an email alias. "Ask first, freely, and fast" is the culture the whole policy exists to create.

Step 6: Test, Review, and Launch Your AI Policy

Send the draft to your heaviest AI users and ask them: what would this stop you from doing that you currently do? Their answers reveal where the policy fights real workflows. Adjust to or consciously accept each conflict, get counsel's review, then announce your AI policy with a short training built around scenarios rather than rules. These practices can facilitate introducing AI while keeping employee trust.

Set a review date every quarter or two. Tools and vendor terms change quickly, so keep your policy updated.

One-Page AI Acceptable Use Policy Template

[Company] AI Acceptable Use Policy (v1.0, [date], owner: [name/role])

Approved tools. [Tool A, business tier] for [tasks]. [Tool B] for [tasks]. Other tools require a request in [channel]; answers within [X] days.

Never enter into external AI tools: [category: example], [category: example], [category: example]. When in doubt, ask in [channel] first.

Review requirements. Low-risk internal tasks using approved tools and permitted data: self-review. Work reaching colleagues or customers: review by [role] before use. Sensitive data or consequential decisions require approval from [role]. Work affecting rights, money, health, or employment: advance approval from [role], documented.

Disclosure. Tell recipients AI was involved whenever they would reasonably want to know, and always when asked.

Questions and incidents. Ask in [channel]. Report AI-related errors or close calls there too; reports made in good faith carry no penalty.

AI Policy Launch To-Do Items

You now have a short policy that answers the five questions, a named owner, a fast request lane, and a review cadence.

Before launch, confirm that:

  • approved tools and account types are named
  • data rules include examples
  • reviewers are assigned
  • the request channel works
  • training is scheduled
  • a policy review date is set

Having this AI use policy in place with clear approval processes will help improve your AI readiness as you begin implementing pilot programs.

This article is general information, not legal advice. Have qualified counsel review your policy before adoption.

For a rundown of practical AI techniques you can apply at work and the latest on AI news, subscribe to The Rundown newsletter.