Artificial Intelligence (AI) AUP

⚠️ Disclaimer

This document is an example policy provided for informational purposes only.
It does not constitute legal advice, HR guidance, or regulatory compliance documentation.
Organizations should review, modify, and approve this policy with their HR department, legal counsel, and compliance team before adopting it.

Artificial Intelligence (AI) Acceptable Use Policy

1) Purpose

This policy defines how employees and contractors may use Artificial Intelligence (AI) safely and responsibly at [Company Name]. Our goals are to:

  • Protect Company, client, and regulated data

  • Reduce legal, ethical, and security risk

  • Enable high-value, secure AI adoption that supports our business

AI is a productivity accelerator — but only when used thoughtfully and with proper safeguards.

2) Scope

This policy applies to all employees, contractors, interns, and third parties using:

  • General AI assistants (e.g., enterprise chatbots)

  • AI features inside SaaS tools (e.g., Copilot, Gemini)

  • Company-built AI automations and workflows

  • Any Company-approved AI Service (AAS)

Use of consumer, personal, or unapproved AI tools for Company work is prohibited.

3) Key Definitions (Simplified)

Artificial Intelligence (AI): Systems that generate or analyze content, automate tasks, or make predictions.
Approved AI Service (AAS): AI tools reviewed and authorized by IT/Security and listed in the Approved AI Registry.
Confidential/Regulated Data: Client data, financials, internal documents, IP, PII, PHI, or anything not public.
Model Training: Use of our data to improve vendor models — AAS must have this disabled.

4) Roles & Responsibilities

  • AI Program Owner: Maintains this policy, the Approved AI Registry, and adoption guardrails.

  • IT/Security & Legal: Review vendors, risk, compliance, and approve exceptions.

  • Managers: Ensure team compliance and training completion.

  • Employees/Contractors: Use AI responsibly and only through AAS.

5) Approved AI Registry

The Company maintains a living list of approved tools and their guardrails (data residency, retention, model training settings, and allowed uses).

Example (replace with your systems):

Service Owner Model Training Allowed Use
ChatGPT Enterprise/Team IT/Security Disabled Drafting, summarization, code help, internal work content
Microsoft 365 Copilot IT Not used for foundation training Work content inside M365
Google Gemini for Workspace IT Not used for cross-customer training Workspace content per permissions

If a tool is not on the list, it is not approved.

6) Data Handling Rules

AI usage must follow the matrix below:

Data Type Examples Consumer AI Approved AI
Public Marketing content, published info Allowed Allowed
Internal Non-public internal docs Not allowed Allowed with care
Confidential Client data, contracts, IP Prohibited Allowed only with safeguards
Regulated PII, PHI, payment data Prohibited Allowed only if AAS meets regulatory requirements

Guiding principles:

  • Share minimum necessary.

  • Redact or tokenize sensitive fields.

  • Do not paste raw data dumps.

  • Prefer system-to-system integrations where possible.

7) Mandatory Safeguards (AAS Only)

Before entering Confidential or Regulated data into an AAS, ALL must be true:

  1. Model training is disabled.

  2. Retention is limited or off per Company policy.

  3. SSO/MFA and tenant isolation are enabled.

  4. AI only accesses content the user is already permitted to view.

  5. Prompts and outputs can be logged for auditing.

  6. Sensitive data is minimized, masked, or summarized.

  7. Human review is required for external output or decision-making.

  8. Third-party plugins/GPTs are disabled unless approved.

  9. Vendor security and compliance have been reviewed.

8) Acceptable & Prohibited Uses

Acceptable Examples

  • Brainstorming, drafting, tone cleanup

  • Internal/external communications (with human review)

  • Code assistance, documentation

  • Summaries of documents the user already has access to

  • Synthetic data generation for testing

Prohibited Examples

  • Using unapproved AI tools for Company work

  • Uploading Confidential/Regulated data into consumer AI

  • Using AI to bypass access controls or exfiltrate data

  • Relying on AI output without verification

  • Entering credentials, secrets, or unpublished vulnerabilities

9) Prompt Hygiene & Quality Standards

Good prompts protect the business and improve results. Use the C.H.A.T. Framework:

  • C — Context: What is the task, format, or purpose?

  • H — Hone: Be specific about length, style, constraints.

  • A — Audience: Who will read or use the output?

  • T — Tone: Align with Company brand and intent.

After receiving output:
Fact-check, review for bias, verify accuracy, and ensure compliance.

10) Embedded AI in SaaS

AI features built into SaaS platforms must be evaluated before enabling. Treat each feature as a separate processor and confirm safeguards match or exceed this policy.

11) Incident Response

Report any AI-related security, privacy, or data-handling concerns to IT/Security within 24 hours.
Examples: data leakage, unsafe outputs, unauthorized plugin use, or accidental upload of regulated data.

12) Training

All personnel must complete Company AI safety training, including:

  • How to recognize hallucinations/inaccurate output

  • How to handle sensitive data with minimization/redaction

  • When and how to use AAS

  • Required verification steps

Refresher training will be provided periodically.

13) Exceptions

Exceptions require documented approval from IT/Security & Legal and must include compensating controls and an expiration date.

14) Enforcement

Violations of this policy may result in disciplinary action up to and including termination, and legal action where required.

15) Review & Updates

This policy will be reviewed annually or as regulations and technology evolve. Updated versions will be distributed to all users.