TemplateAI Governance

Template · Markdown · copyable

AI Acceptable Use Policy Template

A starter acceptable-use policy your legal, security, and people teams can adapt. Markdown so it drops cleanly into any wiki or docs system.

Most organizations need an AI acceptable-use policy long before they need a full governance framework. This template gives you a starting structure — sections, prohibited-use language, and a review cadence — that you can adapt in an afternoon.

Run it past legal and information-security before publishing internally. The bracketed placeholders mark the parts you'll need to tailor for your jurisdiction, data-classification scheme, and approved-tools list.

Template · Markdown

AI Acceptable Use Policy

Adapt the bracketed placeholders to your organization. Versioned at the top so reviewers can spot stale copies.

# [Organization Name] AI Acceptable Use Policy

**Version:** 1.0 — [date]
**Owner:** [Function / Role]
**Review cadence:** Every 12 months or after a material AI-tooling change.

## 1. Purpose

This policy describes the conditions under which employees, contractors, and partners of [Organization Name] may use AI tools — including but not limited to generative AI assistants, third-party model APIs, and AI features embedded inside SaaS products.

## 2. Scope

This policy applies to all personnel with access to [Organization Name] systems and data, whether the AI tool is sanctioned by IT, embedded inside a sanctioned product, or accessed through a personal account.

## 3. Approved tools

Only AI tools on the current Approved AI Tools List ([link]) may be used with [Organization Name] data. The list is maintained by [Function] and reviewed [cadence].

## 4. Permitted use

- Drafting, summarizing, and editing internal documents that contain only public or internal-classification data.
- Generating code that will be reviewed by a human before merge.
- Research and exploration using public sources.

## 5. Prohibited use

- Submitting [confidential / restricted-classification] data to AI tools not explicitly approved for that classification.
- Using AI output as the sole basis for decisions that affect a customer, candidate, employee, or contractor.
- Sharing AI output that you have not reviewed for accuracy, bias, and confidentiality.
- Using personal AI accounts to process [Organization Name] data.

## 6. Disclosure

When AI materially contributed to a deliverable shared externally (a customer email, a published report, a customer-facing decision letter), disclose that fact per the [Communications Standard].

## 7. Incident reporting

Report any of the following to [security contact] within [timeframe]:

- Confidential data inadvertently submitted to an unapproved tool.
- AI output you suspect is materially incorrect after it influenced a decision.
- Suspected misuse of AI tooling by another person.

## 8. Review and revision

This policy is reviewed annually by [Function] in consultation with [Legal], [Security], and [People].

---

*By accessing AI tools using [Organization Name] credentials, you acknowledge this policy.*

Before you publish

This template is a starting point, not legal advice. Have your legal counsel review it against the jurisdictions, employment relationships, and customer contracts your organization operates under.