Judging AI governance
AI acceptable use policy: a copyable template
Short answerAn AI acceptable use policy tells people which AI tools they may use, which data must stay out, who reviews the output, how to report a problem, and who owns the rules. Start with the short template below, replace the bracketed fields, and have counsel review it before adoption.
A useful AI policy for companies is short enough to read during work and specific enough to answer a real question. It names the approved path, the information that stays out of AI tools, the person who checks important output, and the person who receives a report when something goes wrong.
An AI policy generator can supply a generic draft. A usable policy still needs the company’s real tool list, data rules, reporting channel, owner, and review by counsel.
Copy this AI use policy template
AI acceptable use policy
Company: [company name] · Owner: [name or role] · Effective date: [date]
1. Scope
This policy applies to every employee and contractor who uses an AI tool for [company name], including tools reached through a website, app, browser extension, coding assistant, or API.
2. Approved tools
Use only these company-approved AI tools for work: [list tools and approved accounts]. Ask [owner] before using another AI tool or connecting an AI tool to company data.
3. Data that must never go into AI tools
Never enter customer records, personal data, passwords, API keys, account numbers, confidential company information, or material covered by a client agreement unless [owner] has approved the exact tool, account, data, and purpose in writing.
4. Review of output
A person must check AI output before it is sent to a customer, published, used in code, or used to make a decision. The reviewer remains responsible for accuracy, confidentiality, tone, and the final action.
5. Reporting
Report an accidental disclosure, unsafe output, unexpected tool behavior, or suspected policy breach to [reporting contact] through [channel] as soon as it is found. Preserve the relevant prompt, output, time, and tool name when it is safe to do so.
6. Owner
[Owner name or role] approves tools and exceptions, answers questions, records decisions, and reviews this policy on [review schedule] and after a reported incident or material tool change.
Make the policy usable
- Replace every bracketed field. A blank owner or reporting channel leaves the rule without a next step.
- List approved tools by product and account type so an employee can identify the approved path.
- Put the policy where people work, include it in onboarding, and give employees one place to ask questions.
- Test the reporting route with a made-up incident and record who receives it.
- Review the policy when a tool, contract, workflow, or material risk changes.
Connect the words to a control
A policy tells people what the company expects. A control can check a request while the work happens. SUPERWISE® Sentinel replaces emails, phone numbers, account numbers, and API keys with placeholders before a prompt leaves the PC, and logs every request. Its documented scope covers those four data types and the request log.
Use the policy to name approved tools, restricted data, review, reporting, and ownership. Use the AI glossary to define terms consistently, and read why an organization needs an approved path in Should a company ban AI at work?.
Frequently asked questions
- What is an AI acceptable use policy?
- An AI acceptable use policy is a company rule that defines who may use AI for work, which tools are approved, which data is restricted, how output is reviewed, how problems are reported, and who owns the policy.
- What should be included in an AI policy?
- Include scope, approved tools, restricted data, human review of output, a reporting route, and a named owner. Add the company-specific contract, workforce, and industry rules identified through legal review.
- How do you write an AI usage policy?
- List the people and tools in scope, name the data that must stay out, state when a person reviews output, give employees one reporting route, assign an owner, and have counsel review the completed draft.
- Does a company need an AI policy?
- A company that allows AI at work needs written rules employees can find and follow. The policy should match the tools, data, contracts, decisions, and reporting process used by that company.
Reviewed