AI Policy Template for Companies (Free Acceptable Use Policy Example)

An AI policy template gives your company a ready structure for an AI acceptable use policy: which AI tools staff may use, what data may go into them, which uses are off limits, who reviews AI output, and how people get a new tool approved. Below is a free, copy-ready template written for small and mid-size companies, followed by how to tailor it, roll it out and keep it current.

Most companies already have AI in daily use whether they planned it or not. Surveys of knowledge workers keep finding that a large share use AI tools at work without telling their manager, often on free consumer accounts. A short, clear AI policy does not slow that down. It makes it safe, and it gives people permission to use AI properly instead of quietly.

What an AI acceptable use policy needs to cover

An AI acceptable use policy (AUP) is the employee-facing part of AI governance. It does not need to be long. It needs to answer the questions people actually have on a Tuesday afternoon with a deadline:

  • Which tools am I allowed to use? A named list of approved tools and accounts, not "approved AI tools".
  • What can I paste in? Rules tied to your data classes: public, internal, confidential and restricted.
  • What is off limits? A short list of prohibited uses with concrete examples.
  • Who checks the output? Human review rules that scale with risk.
  • Do we tell customers? Disclosure rules for AI-generated content and AI in customer interactions.
  • How do I get a new tool approved? A simple request route with a named owner and a response time.
  • What if something goes wrong? How to report a data leak, a wrong output that reached a customer, or a complaint.

If your team already uses AI widely, add a one-time amnesty: people can disclose the tools they use today without penalty so you can approve or replace them. That is how you find shadow AI instead of driving it further underground.

Free AI policy template (copy and adapt)

Replace everything in [square brackets]. The template assumes a company of roughly 20 to 500 people using business accounts of tools such as ChatGPT, Claude, Microsoft Copilot or Gemini. It is a starting point, not legal advice: have it reviewed against your contracts, your sector rules and the laws where you operate.

AI policy template - Acceptable Use of AI Tools

1. Purpose and scope

This policy explains how [Company] employees, contractors and temporary staff may use artificial intelligence tools, including generative AI chat assistants, AI features built into existing software and AI coding tools. It applies to all work done for [Company], on any device. Owner: [role, e.g. Head of Operations]. Effective: [date]. Next review: [date + 6 months].

2. Our position on AI

We want people to use AI to work faster and better. AI is a tool that assists your work; you remain responsible for everything you produce, send or decide, whether or not AI helped.

3. Approved tools

Tool Account type Allowed data Notes
[e.g. ChatGPT Business / Team] Company workspace, SSO Up to Confidential Training on our data disabled
[e.g. Claude Team] Company workspace Up to Confidential Use Projects for shared context
[e.g. Microsoft 365 Copilot] Company tenant Up to Confidential Follows existing file permissions
Free or personal AI accounts Personal Public only Never for company or client data

Any tool not on this list, including browser extensions, meeting recorders and AI features switched on inside other apps, needs approval first (section 8).

4. Data rules

Data class Examples In approved AI tools?
Public Published website copy, press releases Yes
Internal Internal process docs, meeting notes without personal data Yes
Confidential Client documents, contracts, financials, source code Yes, approved business tools only
Restricted Health data, payment card data, passwords and keys, special category personal data, data a client contract forbids sharing No, unless a specific use case is approved in writing

Remove names and identifiers when you do not need them. Never paste passwords, API keys or access tokens into any AI tool.

5. Allowed, restricted and prohibited uses

Allowed: drafting and editing text, summarising documents you are allowed to read, brainstorming, research with sources checked, analysing non-restricted data, writing and reviewing code in approved tools, preparing first drafts of presentations and reports.

Restricted (needs manager or owner approval): AI output sent directly to customers without edit, AI used in hiring, performance or other decisions about people, AI-generated content published under the company name, automations or agents that act in other systems.

Prohibited: entering Restricted data into unapproved tools; using AI to make final decisions about people without human review; creating deceptive content, deepfakes or impersonation; bypassing security controls; presenting AI output as verified fact without checking it; using AI in any way that breaks law, contract or our code of conduct.

6. Human review and accuracy

Check AI output before you rely on it. Facts, numbers, quotes, citations and legal or technical statements must be verified against a source. The higher the stakes, the more review: anything going to a customer, a regulator, a contract or a decision about a person needs a second human reviewer or a documented check.

7. Transparency and disclosure

Tell customers when they are interacting with an AI system, for example a chatbot. Label substantially AI-generated images, audio or video where people could be misled. Internally, be open about AI use when a colleague asks how work was produced.

8. Requesting a new AI tool

Send requests to [email or form]. Include the tool, the use case, the data it will touch and the cost. [Owner] reviews security, data protection terms, cost and value and replies within [10 working days]. Approved tools are added to section 3.

9. Training

Everyone completes AI basics training within [30 days] of starting or of this policy taking effect, with a refresher every [12 months]. Teams that use AI in higher-risk work receive role-specific training.

10. Incidents

Report immediately to [security or data protection contact] if you think confidential or restricted data went into an unapproved tool, if AI output caused harm or reached a customer in error, or if you receive a complaint about our AI use. Reporting quickly is never punished; hiding an incident is.

11. Roles

[Policy owner]: maintains the policy and the approved tools list. [IT or security]: reviews tools and access. Managers: make sure their team follows the policy and approve restricted uses. Every employee: follows the policy and asks when unsure.

12. Breaches and review

Breaches are handled under our normal disciplinary process, taking intent and impact into account. This policy is reviewed every six months and whenever we add a major tool or a relevant law changes.

Acknowledgement

I have read and understood the [Company] AI Acceptable Use Policy. Name: ______ Date: ______

Tailor it in 20 minutes
AI Acceptable Use Policy Writer
AI Acceptable Use Policy Writer
$7this skill vs $2,000+a lawyer-drafted policy

Answers a short interview about your size, industry, tools and data, then writes the full policy, a one-page employee summary, an acknowledgement form and the rollout email. Works in Claude or ChatGPT.

View the AI Policy Writer →

How to tailor the template to your company

Start from your real tools and data

Before you edit a word, list the AI tools people actually use. Ask managers, check expense reports and look at browser extensions. Then map your existing data classification onto section 4. If you have no classification, the four classes above are enough for a first version.

Adjust for your industry

  • Professional services and agencies: client contracts often restrict where client data may be processed. Check them and add client-specific rules to the Restricted class.
  • Healthcare: treat any patient information as Restricted and require a documented approval for every AI use case that touches it.
  • Finance: add record-keeping requirements for AI-assisted advice and communications, and route model-based decisions through your existing risk process.
  • Software companies: add rules for AI coding assistants: approved tools, no secrets in prompts, licence checks on generated code and normal code review for everything.
  • HR and recruiting: AI used in hiring or evaluating people is high-stakes. Keep a human decision-maker and document how AI was used.

Keep it short enough to be read

The full policy can run to three or four pages. Pair it with a one-page summary of do and do not rules that people can keep open next to their AI tool. A policy nobody reads protects nobody.

The EU AI Act and your AI policy

If you operate in the EU or serve EU customers, the EU AI Act is worth a paragraph in your planning. It entered into force on 1 August 2024. The bans on prohibited practices and the AI literacy duty in Article 4 have applied since 2 February 2025, and most obligations for high-risk systems apply from 2 August 2026. For most companies that only use general-purpose AI assistants for everyday work, the practical takeaways are: make sure staff have adequate AI literacy, be transparent when people interact with AI, and check whether any use case falls into a high-risk area such as hiring or credit decisions. Training records and an acknowledged policy are simple evidence that you took AI literacy seriously. This is general information, not legal advice; ask counsel to confirm what applies to you.

How to roll out the policy

  1. Get one executive sponsor to sign it. A policy sent by IT alone reads like a restriction. A policy introduced by leadership reads like permission.
  2. Announce it with the approved tools ready. If you ban free accounts, the business accounts must exist on day one, or people will keep using the free ones.
  3. Run a 45-minute session. Walk through the data table and five real examples from your own work. Pair it with role-based training; the AI Training Program Designer builds that curriculum for you.
  4. Collect acknowledgements. A form or an HR system checkbox is enough.
  5. Open the amnesty window. Two weeks for people to disclose tools they already use.
  6. Review after 90 days. Look at tool requests, incidents and questions, and update the policy.

Check where you stand first

A policy is one part of being ready for AI. Take the free AI readiness assessment: 20 questions that score your company across strategy, data, people, tools and governance and tell you which gap to close first. If governance is your lowest score, the template above is the right first step. If tools and processes come out lowest, plan your first pilots with the AI Implementation Roadmap Planner. For a deeper, interview-based report, the AI Readiness Assessment Consultant skill runs the full assessment.

Common mistakes in AI policies

  • Banning everything. A blanket ban pushes usage onto personal phones and free accounts, where you have no control at all.
  • Vague tool lists. "Approved AI tools" with no list means every employee decides for themselves.
  • No data rules. The real risk is what goes into the tool, so the data table is the heart of the policy.
  • No owner and no review date. AI tools change monthly. A policy without an owner is out of date within a quarter.
  • Policy without training. People follow rules they understand. Short, practical training does more than a longer policy.
Everything for an AI rollout
AI Rollout Kit
AI Rollout Kit
$246 skills, one-time

Policy writer, readiness assessment, training program designer, implementation roadmap planner, plus an AI adoption lead and an AI governance specialist. Six skills that take a company from first policy to measured rollout.

View the AI Rollout Kit →

常見問題

What should an AI policy template include?+

At minimum: purpose and scope, a named list of approved AI tools, data rules tied to your data classes, allowed, restricted and prohibited uses, human review requirements, disclosure rules, a process to request new tools, training, incident reporting, roles and a review date. An acknowledgement form and a one-page employee summary help people actually follow it.

What is an AI acceptable use policy?+

An AI acceptable use policy is the employee-facing set of rules for using AI tools at work. It tells staff which tools they may use, what data they may put into them, which uses are off limits and who checks AI output before it reaches customers or decisions.

Should a small company have an AI policy?+

Yes. Small teams often use AI the most and on personal accounts. A two to four page policy with clear data rules and approved business accounts reduces the risk of client or personal data leaking into consumer tools and gives staff permission to use AI properly.

Does the EU AI Act require an AI policy?+

The EU AI Act does not name an acceptable use policy as such, but since 2 February 2025 organizations that use AI must take measures to ensure sufficient AI literacy among staff. A written policy plus training records is a simple way to show those measures. This is general information, not legal advice.

How often should an AI policy be reviewed?+

Every six months, and whenever you approve a major new AI tool or a relevant law changes. AI tools change quickly, so name an owner who keeps the approved tools list current.

~/get-started

實用的 Skills。不說空話。

瀏覽商店中的每個技能、prompt 套件和 agent。

瀏覽所有技能 →或試試免費工具