Template · Markdown · copyable
AI Acceptable Use Policy Template
A starter acceptable-use policy your legal, security, and people teams can adapt. Markdown so it drops cleanly into any wiki or docs system.
Most organizations need an AI acceptable-use policy long before they need a full governance framework. This template gives you a starting structure — sections, prohibited-use language, and a review cadence — that you can adapt in an afternoon.
Run it past legal and information-security before publishing internally. The bracketed placeholders mark the parts you'll need to tailor for your jurisdiction, data-classification scheme, and approved-tools list.
AI Acceptable Use Policy
Adapt the bracketed placeholders to your organization. Versioned at the top so reviewers can spot stale copies.
# [Organization Name] AI Acceptable Use Policy **Version:** 1.0 — [date] **Owner:** [Function / Role] **Review cadence:** Every 12 months or after a material AI-tooling change. ## 1. Purpose This policy describes the conditions under which employees, contractors, and partners of [Organization Name] may use AI tools — including but not limited to generative AI assistants, third-party model APIs, and AI features embedded inside SaaS products. ## 2. Scope This policy applies to all personnel with access to [Organization Name] systems and data, whether the AI tool is sanctioned by IT, embedded inside a sanctioned product, or accessed through a personal account. ## 3. Approved tools Only AI tools on the current Approved AI Tools List ([link]) may be used with [Organization Name] data. The list is maintained by [Function] and reviewed [cadence]. ## 4. Permitted use - Drafting, summarizing, and editing internal documents that contain only public or internal-classification data. - Generating code that will be reviewed by a human before merge. - Research and exploration using public sources. ## 5. Prohibited use - Submitting [confidential / restricted-classification] data to AI tools not explicitly approved for that classification. - Using AI output as the sole basis for decisions that affect a customer, candidate, employee, or contractor. - Sharing AI output that you have not reviewed for accuracy, bias, and confidentiality. - Using personal AI accounts to process [Organization Name] data. ## 6. Disclosure When AI materially contributed to a deliverable shared externally (a customer email, a published report, a customer-facing decision letter), disclose that fact per the [Communications Standard]. ## 7. Incident reporting Report any of the following to [security contact] within [timeframe]: - Confidential data inadvertently submitted to an unapproved tool. - AI output you suspect is materially incorrect after it influenced a decision. - Suspected misuse of AI tooling by another person. ## 8. Review and revision This policy is reviewed annually by [Function] in consultation with [Legal], [Security], and [People]. --- *By accessing AI tools using [Organization Name] credentials, you acknowledge this policy.*
Before you publish
This template is a starting point, not legal advice. Have your legal counsel review it against the jurisdictions, employment relationships, and customer contracts your organization operates under.