AI acceptable use policy examples: five clauses most companies get wrong

AI acceptable use policy examples: five clauses most companies get wrong

Most AI acceptable use policies fail the same way. Legal writes them, nobody reads them, and they're full of lines like "employees must use AI responsibly" that nobody can act on. Then someone pastes a customer spreadsheet into a free chatbot, and the policy turns out to have said nothing useful about it.

A policy people follow is short and specific. It answers the questions staff actually have at 4pm on a Thursday: can I use this tool, can I paste this document, do I need to tell the client? That comes down to five clauses. Below you'll find AI acceptable use policy examples for each one, the weak wording most companies use next to wording that works, plus a full one-page sample you can adapt.

The short version

  • Name the approved tools, and say what happens with personal accounts.
  • List the data that never goes into AI, in words staff recognise.
  • Say exactly which outputs a person must check, and who is responsible.
  • Pick one disclosure rule and write it down.
  • Give the policy an owner, a help channel and a review date.

What's in this guide

  1. What an AI acceptable use policy is (and isn't)
  2. Clause 1: which tools are approved
  3. Clause 2: what data can go in
  4. Clause 3: when a human has to check
  5. Clause 4: when to say AI was used
  6. Clause 5: who owns the policy
  7. A complete one-page sample policy
  8. Six mistakes that make policies fail
  9. How to roll it out in two weeks
  10. Questions people ask

What an AI acceptable use policy is (and isn't)

An AI acceptable use policy tells employees what they may and may not do with AI tools at work. It's written for the person using the tool, not for the board. If a line doesn't change what someone does on Monday morning, it probably belongs somewhere else.

It's worth separating three documents that often get mashed together:

Document Who reads it What it covers
Acceptable use policy Every employee Approved tools, data rules, checking, disclosure, where to ask
AI governance policy Leadership, IT, risk, legal How tools get approved, risk assessment, monitoring, reporting
Vendor or tool assessments IT and procurement Data processing terms, security review, retention settings for each tool

Most companies need all three eventually. The acceptable use policy comes first, because it's the one that stops real mistakes this week. If you're in the EU, the AI Act has also required organisations using AI to take steps towards staff AI literacy since February 2025, and a clear acceptable use policy plus basic training is a sensible part of that. The EU has proposed changes to how that duty works, so check the current position with your legal team.

Clause 1: which tools are approved

Name them. "Approved AI tools" with no list means everyone decides for themselves, and they'll decide based on whatever they already have open in a browser tab.

Weak:   Employees may use approved generative AI tools.

Better: You may use Microsoft 365 Copilot and ChatGPT Enterprise
        with your work account. Any other AI tool, including free
        versions of the same products on a personal account, needs
        sign-off from IT before you put work content into it.

The personal-account line matters more than it looks. The free version of a tool and the business version often have different data terms: whether your inputs can be used for training, how long they're kept, who can see them. Staff rarely know which one they're logged into. Make it explicit.

Three extra lines worth adding:

  • AI features inside other tools. Meeting recorders, writing assistants in your CRM, browser extensions. Say whether they count. Usually they should: a meeting bot that joins client calls is an AI tool processing client data.
  • How to request a new tool. One sentence and a link. If there's no route, people use tools quietly instead.
  • Where the list lives. Put the approved list on the intranet, not inside the policy, so you can update it without reissuing the whole document.

Clause 2: what data can go in

This is the clause that prevents real damage. Use categories people recognise, not classification codes they've never seen. "Restricted Tier 2 data" means nothing to a sales rep. "Customer phone numbers" does.

Never put into any AI tool:
- Customer personal data (names with contact details, account
  numbers, health or financial information)
- Employee personal data (pay, performance, health, disciplinary)
- Passwords, keys or access tokens
- Unannounced financial results or deal terms
- Anything a client contract marks as confidential

Fine in approved tools:
- Drafts of your own writing
- Public information
- Internal documents with no personal or client data

If in doubt: remove the names and numbers first, or ask in
#ai-help.

The "if in doubt" line is important. Most real questions sit in the grey zone: a customer complaint email, a spreadsheet with first names only, meeting notes that mention a client. Telling people how to strip identifying details (replace names with "Customer A", delete the account number) turns a "no" into a safe "yes" for a lot of useful work.

Check this clause against your privacy notices and client contracts. Some client agreements ban any third-party processing of their material without consent, which can include AI tools even when your own policy would allow it.

Clause 3: when a human has to check

"Review all AI outputs" is unenforceable. Nobody reviews the AI-suggested subject line on an internal email, and the policy shouldn't pretend they will. Say which outputs need checking, and who does it.

A person must read and approve AI-assisted work before it:
- goes to a client or the public
- is used in a hiring, pay or performance decision
- states a number, legal position or technical claim as fact
- is merged into production code

The person who sends it is responsible for it, whatever tool
helped write it.

That last sentence does more work than the rest of the policy combined. It removes "the AI said so" as an excuse, and it means you don't need a separate rule for every kind of mistake. If someone sends a client a made-up statistic, the question isn't what the tool did, it's why they sent it.

For decisions about people (hiring, promotion, discipline, pay), many companies go further and say AI can help with wording but must not rank, score or recommend. Automated decisions about individuals carry legal risk in several countries. Our guide to AI prompts for HR shows the safe side of that line.

Clause 4: when to say AI was used

Companies land in different places here, and that's fine. Some require disclosure on anything external. Others only disclose where a client contract asks for it. The mistake is not deciding, which leaves each employee to guess.

Tell the client when AI generated a substantial part of a
deliverable, or when their contract requires it. You do not
need to flag AI help with spelling, formatting or summarising
your own notes.

Never present AI-generated images, voices or quotes as real
people or real events.

A few sectors have their own rules on top: regulated advice, journalism, academic work, some public-sector contracts. If you work in one, add a line pointing to the rule that applies.

Clause 5: who owns the policy

The clause almost everyone forgets. Tools change monthly. A policy with no owner and no review date is out of date within a quarter, and staff learn to ignore it.

Owner: Head of Operations
Questions: #ai-help channel, answered within one working day
Report a mistake: tell your manager or #ai-help the same day.
  Reporting quickly is never a disciplinary issue in itself.
Review: every six months, or when we add a new tool

The "report a mistake" line is worth its weight. If people fear punishment for admitting they pasted the wrong file into a chatbot, they won't admit it, and you lose the chance to fix it.

A complete one-page sample policy

Here's how the five clauses fit together. Replace the bracketed parts and it's usable as it stands.

[COMPANY] AI ACCEPTABLE USE POLICY
Version [1.0], effective [date], owner [role]

1. APPROVED TOOLS
You may use [tools] with your work account. The current list is
at [link]. Any other AI tool, including free or personal versions,
needs IT sign-off before you put work content into it. This
includes AI features in other apps, browser extensions and meeting
recorders. Request a new tool at [link].

2. DATA
Never put into any AI tool: customer or employee personal data,
passwords or keys, unannounced financials or deal terms, or
anything a client contract marks confidential.
Fine in approved tools: your own drafts, public information,
internal documents with no personal or client data.
If unsure, remove names and numbers first or ask in [channel].

3. CHECKING
A person must read and approve AI-assisted work before it goes
to a client or the public, is used in a decision about a person,
states a fact, figure or legal position, or goes into production.
AI must not rank, score or recommend people in hiring, pay or
performance decisions. The person who sends work is responsible
for it.

4. DISCLOSURE
Tell clients when AI generated a substantial part of a
deliverable or when their contract requires it. Never present
AI-generated images, voices or quotes as real.

5. HELP AND REVIEW
Questions: [channel], answered within one working day.
Mistakes: report the same day to your manager or [channel].
This policy is reviewed every six months.

You can also start from our free AI policy template, and see a finished version for an invented manufacturing firm on the example policy page.

Six mistakes that make policies fail

1. Banning everything

A blanket ban doesn't stop AI use. It moves it to personal phones and personal accounts, where you have no control over data at all. Approving one or two good tools is safer than approving none.

2. Writing for lawyers

If a policy needs a legal glossary, staff won't read it. Write the rules in plain sentences and keep the legal detail in the governance document.

3. No examples

"Confidential information" means different things to different people. Two or three concrete examples per clause ("a customer's complaint email with their name in it") settle most questions before they're asked.

4. Rules nobody can check

"Always verify AI output" can't be audited. "The sender is responsible" can. Prefer rules that put responsibility on a named person over rules that describe a process nobody tracks.

5. Forgetting the tools people already have

Copilot in Office, Gemini in Workspace, AI summaries in Zoom and Teams. These are often switched on by default. Your policy should cover them, and IT should check their settings match what the policy promises.

6. Publishing and walking away

A PDF on the intranet isn't a rollout. Which brings us to the next part.

How to roll it out in two weeks

Days 1 to 3: draft and test. Write the five clauses. Then give the draft to three people outside legal and ask each one a real question: can I paste this customer email into ChatGPT? Can I use Claude to draft a job ad? Do I need to tell the client? If you get three different answers, rewrite the clause they disagreed on.

Days 4 to 7: sign-off. Legal and IT review, with one rule: they can tighten a line, but they can't make it vaguer. Check that tool settings (data retention, training opt-outs) match what the policy says.

Days 8 to 10: launch. A short message from a senior leader, a one-page version, and a 20-minute session with worked examples. Open the help channel the same day.

Days 11 to 14: listen. Read every question in the help channel. The repeated ones tell you which clause is unclear. Fix it now, not at the six-month review.

The companies that get the most out of this go one step further: they build the rules into the AI assistants themselves, so the tool reminds people of the data rule when they start to paste a customer record. A document tells people the rules. A set-up assistant applies them every time.

Questions people ask

How long should an AI acceptable use policy be?

One to two pages for the rules staff follow. Supporting detail such as vendor assessments and risk procedures can live in a separate governance document.

Is an AI acceptable use policy the same as an AI governance policy?

No. Acceptable use tells employees what they can do. Governance covers how the company approves tools, manages risk and reports on it. Most companies need both, and the acceptable use one first.

Do we need legal to sign it off?

Yes, especially the data clause, since it touches privacy law and client contracts. Just don't let the legal review turn plain rules back into vague ones.

Should we ban free AI tools?

Ban putting work content into them, rather than banning the tools outright. That's enforceable in principle, and it gives people a clear reason: the free versions often have weaker data terms.

Can employees use AI to write code?

Usually yes, in approved tools, with the same rule as everything else: a person reviews it before it goes into production, and nobody pastes secrets, keys or customer data into a prompt.

How often should the policy be updated?

Review it every six months, and whenever you approve a new tool. Keep the approved tools list outside the policy so it can change more often.

Put the rules inside every AI your team uses

AI Setup for Your Company gives ChatGPT, Claude, Gemini and Copilot the same company rules (spending, data, steps, when to check with a person) plus six team helpers for sales, marketing, finance, support, people and operations. One company licence, $247.

See AI Setup for Your Company

Leave a comment: