An AI policy template gives your company a ready structure for an AI acceptable use policy: which AI tools staff may use, what data may go into them, which uses are off limits, who reviews AI output, and how people get a new tool approved. Below is a free, copy-ready template written for small and mid-size companies, followed by how to tailor it, roll it out and keep it current.
Most companies already have AI in daily use whether they planned it or not. Surveys of knowledge workers keep finding that a large share use AI tools at work without telling their manager, often on free consumer accounts. A short, clear AI policy does not slow that down. It makes it safe, and it gives people permission to use AI properly instead of quietly.
What an AI acceptable use policy needs to cover
An AI acceptable use policy (AUP) is the employee-facing part of AI governance. It does not need to be long. It needs to answer the questions people actually have on a Tuesday afternoon with a deadline:
- Which tools am I allowed to use? A named list of approved tools and accounts, not "approved AI tools".
- What can I paste in? Rules tied to your data classes: public, internal, confidential and restricted.
- What is off limits? A short list of prohibited uses with concrete examples.
- Who checks the output? Human review rules that scale with risk.
- Do we tell customers? Disclosure rules for AI-generated content and AI in customer interactions.
- How do I get a new tool approved? A simple request route with a named owner and a response time.
- What if something goes wrong? How to report a data leak, a wrong output that reached a customer, or a complaint.
If your team already uses AI widely, add a one-time amnesty: people can disclose the tools they use today without penalty so you can approve or replace them. That is how you find shadow AI instead of driving it further underground.
Free AI policy template (copy and adapt)
Replace everything in [square brackets]. The template assumes a company of roughly 20 to 500 people using business accounts of tools such as ChatGPT, Claude, Microsoft Copilot or Gemini. It is a starting point, not legal advice: have it reviewed against your contracts, your sector rules and the laws where you operate.
AI policy template - Acceptable Use of AI Tools
1. Purpose and scope
This policy explains how [Company] employees, contractors and temporary staff may use artificial intelligence tools, including generative AI chat assistants, AI features built into existing software and AI coding tools. It applies to all work done for [Company], on any device. Owner: [role, e.g. Head of Operations]. Effective: [date]. Next review: [date + 6 months].
2. Our position on AI
We want people to use AI to work faster and better. AI is a tool that assists your work; you remain responsible for everything you produce, send or decide, whether or not AI helped.
3. Approved tools
| Tool | Account type | Allowed data | Notes |
|---|---|---|---|
| [e.g. ChatGPT Business / Team] | Company workspace, SSO | Up to Confidential | Training on our data disabled |
| [e.g. Claude Team] | Company workspace | Up to Confidential | Use Projects for shared context |
| [e.g. Microsoft 365 Copilot] | Company tenant | Up to Confidential | Follows existing file permissions |
| Free or personal AI accounts | Personal | Public only | Never for company or client data |
Any tool not on this list, including browser extensions, meeting recorders and AI features switched on inside other apps, needs approval first (section 8).
4. Data rules
| Data class | Examples | In approved AI tools? |
|---|---|---|
| Public | Published website copy, press releases | Yes |
| Internal | Internal process docs, meeting notes without personal data | Yes |
| Confidential | Client documents, contracts, financials, source code | Yes, approved business tools only |
| Restricted | Health data, payment card data, passwords and keys, special category personal data, data a client contract forbids sharing | No, unless a specific use case is approved in writing |
Remove names and identifiers when you do not need them. Never paste passwords, API keys or access tokens into any AI tool.
5. Allowed, restricted and prohibited uses
Allowed: drafting and editing text, summarising documents you are allowed to read, brainstorming, research with sources checked, analysing non-restricted data, writing and reviewing code in approved tools, preparing first drafts of presentations and reports.
Restricted (needs manager or owner approval): AI output sent directly to customers without edit, AI used in hiring, performance or other decisions about people, AI-generated content published under the company name, automations or agents that act in other systems.
Prohibited: entering Restricted data into unapproved tools; using AI to make final decisions about people without human review; creating deceptive content, deepfakes or impersonation; bypassing security controls; presenting AI output as verified fact without checking it; using AI in any way that breaks law, contract or our code of conduct.
6. Human review and accuracy
Check AI output before you rely on it. Facts, numbers, quotes, citations and legal or technical statements must be verified against a source. The higher the stakes, the more review: anything going to a customer, a regulator, a contract or a decision about a person needs a second human reviewer or a documented check.
7. Transparency and disclosure
Tell customers when they are interacting with an AI system, for example a chatbot. Label substantially AI-generated images, audio or video where people could be misled. Internally, be open about AI use when a colleague asks how work was produced.
8. Requesting a new AI tool
Send requests to [email or form]. Include the tool, the use case, the data it will touch and the cost. [Owner] reviews security, data protection terms, cost and value and replies within [10 working days]. Approved tools are added to section 3.
9. Training
Everyone completes AI basics training within [30 days] of starting or of this policy taking effect, with a refresher every [12 months]. Teams that use AI in higher-risk work receive role-specific training.
10. Incidents
Report immediately to [security or data protection contact] if you think confidential or restricted data went into an unapproved tool, if AI output caused harm or reached a customer in error, or if you receive a complaint about our AI use. Reporting quickly is never punished; hiding an incident is.
11. Roles
[Policy owner]: maintains the policy and the approved tools list. [IT or security]: reviews tools and access. Managers: make sure their team follows the policy and approve restricted uses. Every employee: follows the policy and asks when unsure.
12. Breaches and review
Breaches are handled under our normal disciplinary process, taking intent and impact into account. This policy is reviewed every six months and whenever we add a major tool or a relevant law changes.
Acknowledgement
I have read and understood the [Company] AI Acceptable Use Policy. Name: ______ Date: ______

Answers a short interview about your size, industry, tools and data, then writes the full policy, a one-page employee summary, an acknowledgement form and the rollout email. Works in Claude or ChatGPT.
View the AI Policy Writer →How to tailor the template to your company
Start from your real tools and data
Before you edit a word, list the AI tools people actually use. Ask managers, check expense reports and look at browser extensions. Then map your existing data classification onto section 4. If you have no classification, the four classes above are enough for a first version.
Adjust for your industry
- Professional services and agencies: client contracts often restrict where client data may be processed. Check them and add client-specific rules to the Restricted class.
- Healthcare: treat any patient information as Restricted and require a documented approval for every AI use case that touches it.
- Finance: add record-keeping requirements for AI-assisted advice and communications, and route model-based decisions through your existing risk process.
- Software companies: add rules for AI coding assistants: approved tools, no secrets in prompts, licence checks on generated code and normal code review for everything.
- HR and recruiting: AI used in hiring or evaluating people is high-stakes. Keep a human decision-maker and document how AI was used.
Keep it short enough to be read
The full policy can run to three or four pages. Pair it with a one-page summary of do and do not rules that people can keep open next to their AI tool. A policy nobody reads protects nobody.
The EU AI Act and your AI policy
If you operate in the EU or serve EU customers, the EU AI Act is worth a paragraph in your planning. It entered into force on 1 August 2024. The bans on prohibited practices and the AI literacy duty in Article 4 have applied since 2 February 2025, and most obligations for high-risk systems apply from 2 August 2026. For most companies that only use general-purpose AI assistants for everyday work, the practical takeaways are: make sure staff have adequate AI literacy, be transparent when people interact with AI, and check whether any use case falls into a high-risk area such as hiring or credit decisions. Training records and an acknowledged policy are simple evidence that you took AI literacy seriously. This is general information, not legal advice; ask counsel to confirm what applies to you.
How to roll out the policy
- Get one executive sponsor to sign it. A policy sent by IT alone reads like a restriction. A policy introduced by leadership reads like permission.
- Announce it with the approved tools ready. If you ban free accounts, the business accounts must exist on day one, or people will keep using the free ones.
- Run a 45-minute session. Walk through the data table and five real examples from your own work. Pair it with role-based training; the AI Training Program Designer builds that curriculum for you.
- Collect acknowledgements. A form or an HR system checkbox is enough.
- Open the amnesty window. Two weeks for people to disclose tools they already use.
- Review after 90 days. Look at tool requests, incidents and questions, and update the policy.
Check where you stand first
A policy is one part of being ready for AI. Take the free AI readiness assessment: 20 questions that score your company across strategy, data, people, tools and governance and tell you which gap to close first. If governance is your lowest score, the template above is the right first step. If tools and processes come out lowest, plan your first pilots with the AI Implementation Roadmap Planner. For a deeper, interview-based report, the AI Readiness Assessment Consultant skill runs the full assessment.
Common mistakes in AI policies
- Banning everything. A blanket ban pushes usage onto personal phones and free accounts, where you have no control at all.
- Vague tool lists. "Approved AI tools" with no list means every employee decides for themselves.
- No data rules. The real risk is what goes into the tool, so the data table is the heart of the policy.
- No owner and no review date. AI tools change monthly. A policy without an owner is out of date within a quarter.
- Policy without training. People follow rules they understand. Short, practical training does more than a longer policy.

Policy writer, readiness assessment, training program designer, implementation roadmap planner, plus an AI adoption lead and an AI governance specialist. Six skills that take a company from first policy to measured rollout.
View the AI Rollout Kit →

