⚠️ Disclaimer
This document is an example policy provided for informational purposes only.
It does not constitute legal advice, HR guidance, or regulatory compliance documentation.
Organizations should review, modify, and approve this policy with their HR department, legal counsel, and compliance team before adopting it.
Artificial Intelligence (AI) Acceptable Use Policy
1) Purpose
This policy defines how employees and contractors may use Artificial Intelligence (AI) safely and responsibly at [Company Name]. Our goals are to:
-
Protect Company, client, and regulated data
-
Reduce legal, ethical, and security risk
-
Enable high-value, secure AI adoption that supports our business
AI is a productivity accelerator — but only when used thoughtfully and with proper safeguards.
2) Scope
This policy applies to all employees, contractors, interns, and third parties using:
-
General AI assistants (e.g., enterprise chatbots)
-
AI features inside SaaS tools (e.g., Copilot, Gemini)
-
Company-built AI automations and workflows
-
Any Company-approved AI Service (AAS)
Use of consumer, personal, or unapproved AI tools for Company work is prohibited.
3) Key Definitions (Simplified)
Artificial Intelligence (AI): Systems that generate or analyze content, automate tasks, or make predictions.
Approved AI Service (AAS): AI tools reviewed and authorized by IT/Security and listed in the Approved AI Registry.
Confidential/Regulated Data: Client data, financials, internal documents, IP, PII, PHI, or anything not public.
Model Training: Use of our data to improve vendor models — AAS must have this disabled.
4) Roles & Responsibilities
-
AI Program Owner: Maintains this policy, the Approved AI Registry, and adoption guardrails.
-
IT/Security & Legal: Review vendors, risk, compliance, and approve exceptions.
-
Managers: Ensure team compliance and training completion.
-
Employees/Contractors: Use AI responsibly and only through AAS.
5) Approved AI Registry
The Company maintains a living list of approved tools and their guardrails (data residency, retention, model training settings, and allowed uses).
Example (replace with your systems):
| Service | Owner | Model Training | Allowed Use |
|---|---|---|---|
| ChatGPT Enterprise/Team | IT/Security | Disabled | Drafting, summarization, code help, internal work content |
| Microsoft 365 Copilot | IT | Not used for foundation training | Work content inside M365 |
| Google Gemini for Workspace | IT | Not used for cross-customer training | Workspace content per permissions |
If a tool is not on the list, it is not approved.
6) Data Handling Rules
AI usage must follow the matrix below:
| Data Type | Examples | Consumer AI | Approved AI |
|---|---|---|---|
| Public | Marketing content, published info | Allowed | Allowed |
| Internal | Non-public internal docs | Not allowed | Allowed with care |
| Confidential | Client data, contracts, IP | Prohibited | Allowed only with safeguards |
| Regulated | PII, PHI, payment data | Prohibited | Allowed only if AAS meets regulatory requirements |
Guiding principles:
-
Share minimum necessary.
-
Redact or tokenize sensitive fields.
-
Do not paste raw data dumps.
-
Prefer system-to-system integrations where possible.
7) Mandatory Safeguards (AAS Only)
Before entering Confidential or Regulated data into an AAS, ALL must be true:
-
Model training is disabled.
-
Retention is limited or off per Company policy.
-
SSO/MFA and tenant isolation are enabled.
-
AI only accesses content the user is already permitted to view.
-
Prompts and outputs can be logged for auditing.
-
Sensitive data is minimized, masked, or summarized.
-
Human review is required for external output or decision-making.
-
Third-party plugins/GPTs are disabled unless approved.
-
Vendor security and compliance have been reviewed.
8) Acceptable & Prohibited Uses
Acceptable Examples
-
Brainstorming, drafting, tone cleanup
-
Internal/external communications (with human review)
-
Code assistance, documentation
-
Summaries of documents the user already has access to
-
Synthetic data generation for testing
Prohibited Examples
-
Using unapproved AI tools for Company work
-
Uploading Confidential/Regulated data into consumer AI
-
Using AI to bypass access controls or exfiltrate data
-
Relying on AI output without verification
-
Entering credentials, secrets, or unpublished vulnerabilities
9) Prompt Hygiene & Quality Standards
Good prompts protect the business and improve results. Use the C.H.A.T. Framework:
-
C — Context: What is the task, format, or purpose?
-
H — Hone: Be specific about length, style, constraints.
-
A — Audience: Who will read or use the output?
-
T — Tone: Align with Company brand and intent.
After receiving output:
Fact-check, review for bias, verify accuracy, and ensure compliance.
10) Embedded AI in SaaS
AI features built into SaaS platforms must be evaluated before enabling. Treat each feature as a separate processor and confirm safeguards match or exceed this policy.
11) Incident Response
Report any AI-related security, privacy, or data-handling concerns to IT/Security within 24 hours.
Examples: data leakage, unsafe outputs, unauthorized plugin use, or accidental upload of regulated data.
12) Training
All personnel must complete Company AI safety training, including:
-
How to recognize hallucinations/inaccurate output
-
How to handle sensitive data with minimization/redaction
-
When and how to use AAS
-
Required verification steps
Refresher training will be provided periodically.
13) Exceptions
Exceptions require documented approval from IT/Security & Legal and must include compensating controls and an expiration date.
14) Enforcement
Violations of this policy may result in disciplinary action up to and including termination, and legal action where required.
15) Review & Updates
This policy will be reviewed annually or as regulations and technology evolve. Updated versions will be distributed to all users.