Skip to content

BlogFree template

Free AI Acceptable Use Policy Template

This free template gives you a ready-to-use AI acceptable use policy. It names an owner, lists approved tools and accounts, sorts company information into what can and can’t go into AI, makes employees responsible for anything they create with AI, and says how to report mistakes. Copy it, fill in the bracketed decisions, and ask everyone to acknowledge it.

Joring · Last updated October 2026 · 11 min read

What is an AI acceptable use policy?

An AI acceptable use policy is a set of rules that tells employees which AI tools they may use, what information they can put into them, and that they’re responsible for anything they create with AI. You may also see it called an AI usage policy, an AI policy for employees or a generative AI policy.

A good policy is both complete and followed. For completeness, this template draws on established frameworks, including NIST’s AI Risk Management Framework, which recommends that organizations document the laws that apply to their AI use, give people clear roles and train staff. To encourage compliance, this template is short and gives people an approved way to use AI.

Why your business needs an AI policy now

Your employees are almost certainly using AI already. A 2025 study surveyed 48,340 people in 47 countries. Among those who use AI at work (University of Melbourne and KPMG, 2025):

  • 70% use free public AI tools
  • 48% have uploaded company information into a public AI tool
  • 44% have used AI in ways that go against company policies or guidelines
  • 57% have hidden their AI use or passed off AI work as their own

However, only 38% of organizations have a formal, comprehensive AI policy, and 25% have none (ISACA, 2026). Among organizations that had a data breach, 63% had no AI governance policy or were still writing one (IBM and Ponemon Institute, 2025).

Why banning AI doesn’t work

A ban feels safe, but it doesn’t stop risky use. In the same KPMG study, uploading company information or copyrighted material to AI was more common where employers had banned generative AI (67%) than where they had no policy at all (33%).

Free AI acceptable use policy template

Copy the policy below into your own document, or download it for Word or as a PDF. Replace everything in [brackets] with your own decision.

Example

AI Acceptable Use Policy

Company
[Company name]
Policy owner
[name, role]
Backup
[name, role]
Effective
[date]
Last reviewed
[date]
  1. 1. Purpose and scope

    We want everyone at [Company] to use AI to do better work, faster, without putting customer, employee or company information at risk. This policy explains which AI tools you may use, what information you can put into them, and makes clear the expectation that you are responsible for anything you create with AI.

    It applies to all employees [, contractors and temporary staff] who use AI for [Company] work, on any device or account.

    “AI tools” means any product that creates text, images, code, audio or analysis from a prompt. That includes chat assistants such as ChatGPT, Claude, Gemini and Microsoft Copilot, AI features inside other software, browser extensions, meeting note-takers and AI agents.

  2. 2. Who to ask

    [Policy owner] owns this policy. Send questions, tool requests and reports of mistakes to [email or chat channel]. If [policy owner] is away, contact [backup].

  3. 3. Approved AI tools

    You may use these tools for work, signed in with your company account:

    • [Tool and plan, for example ChatGPT Business]: up to [Confidential] information
    • [Tool and plan]: up to [Internal] information
    • AI features inside software we already approve, such as [writing help in Microsoft 365 or Google Workspace]: same rules as the software itself

    Don’t use personal AI accounts for [Company] work, even for tools on this list. Personal accounts can let the vendor use what you type to improve its AI, and they aren’t covered by our contracts. [Decide whether to allow any exceptions.]

  4. 4. Asking for a new tool

    If you want to use a tool that isn’t on the list, ask [policy owner] at [link or email]. We will check:

    • whether the vendor trains its AI on our data, and whether we can turn that off
    • how long it keeps our data and who can see it
    • whether we have a business agreement that protects our information
    • whether it fits what our customer contracts allow

    We aim to answer within [five working days]. Until a tool is approved, use it only with Public information.

  5. 5. Information rules

    Before you put anything into an AI tool, check which level it belongs to:

    • Public: already published, such as our website, press releases and public documents. Fine in any tool.
    • Internal: everyday work that isn’t meant for outsiders, such as process documents and general meeting notes. Approved tools only.
    • Confidential: customer and employee information, contracts, pricing, financial results, source code and unreleased plans. Only in tools approved for confidential information in section 3. [Remove names and account numbers first where you can.]
    • Never: passwords, API keys and other credentials; payment card and bank account numbers; Social Security and other government ID numbers; health information; and anything a contract says we can’t share. Never put these into any AI tool.

    If you’re not sure, treat it as the higher level or ask [policy owner]. [If you already have a data classification policy, use its levels here instead.]

  6. 6. What you can use AI for

    Allowed (in approved tools, within the information rules):

    • drafting and editing emails, documents and posts
    • summarizing documents and meeting notes you’re allowed to see
    • brainstorming, first-pass research and explaining unfamiliar topics
    • writing, explaining and reviewing code
    • [your team’s common tasks]

    Ask [policy owner] first:

    • uploading whole files or datasets that contain Confidential information
    • creating content that will be published or sent to many customers at once
    • using AI in a new customer-facing process, such as a support chatbot
    • connecting AI to company systems (see section 10)

    Never:

    • making or recommending decisions about hiring, firing, pay, promotion or discipline (see section 9)
    • creating content that is deceptive, discriminatory, harassing or illegal
    • copying a real person’s voice or likeness without their permission
    • getting around this policy, for example by switching to a personal account when a work tool says no
  7. 7. Check AI output before you use it

    AI tools can sound confident and still be wrong. They can invent facts, numbers, quotes, sources and legal citations. You are responsible for anything you create with AI.

    Before AI-assisted work leaves your hands, check:

    • facts, numbers, names and dates against a trusted source
    • every link, quote and citation, by opening it
    • whether it copies someone else’s work, such as text, images or code
    • code, by reviewing and testing it like any other code
    • anything customers will see, for accuracy and tone

    [For legal, financial, medical or safety content, a second person must review it: [role].]

  8. 8. Being open about AI use

    Be honest about how you used AI. If someone asks, don’t present AI work as entirely your own. Tell [your manager] when AI did most of the work on [a client deliverable or anything published under our name]. Tell customers they’re dealing with AI when [for example, they’re chatting with an AI assistant, or their contract requires it].

  9. 9. Decisions about people

    Don’t use AI to make or recommend decisions about hiring, firing, promotion, pay or discipline [unless [policy owner] and [HR or legal] have approved the tool and the process in writing]. Some laws require notices or bias audits for these uses.

  10. 10. Connecting AI to company systems

    Get written approval from [policy owner] [and IT] before you:

    • connect an AI tool to email, calendars, shared drives, customer records or code repositories
    • install AI browser extensions or plug-ins
    • use an AI meeting note-taker or recorder (and tell everyone in the meeting)
    • set up AI agents that can act for you, such as sending messages, changing records or making purchases
  11. 11. Reporting mistakes

    If you put information into the wrong tool, or AI output caused a problem, tell [policy owner] at [contact] within [24 hours]. Stop using the tool, keep a copy of what you entered and what it produced, and don’t delete anything until [policy owner] says so. The sooner we know, the sooner we can fix it. [No one will be disciplined for promptly reporting an honest mistake.]

  12. 12. Training and acknowledgment

    Everyone completes [a short AI training] when they join and [every year]. You’ll be asked to confirm that you’ve read this policy. We keep a record of both.

  13. 13. How we check this policy is working

    [Company] may review which AI tools are used on company devices, networks and accounts, to make sure this policy works and to learn which tools people need. [Describe what you review and how often.]

  14. 14. Breaking the rules

    Breaking this policy is handled under [our disciplinary policy]. Nothing in this policy limits your rights under the law, including your right to discuss pay and working conditions. [Ask your lawyer whether to include this line.]

  15. 15. Review

    [Policy owner] reviews this policy [every quarter or at least once a year], and also when we adopt a major new AI tool, a customer contract changes what we can do, a new law applies, or something goes wrong.

Acknowledgment

I have read and understand the AI Acceptable Use Policy.

Name
Signature
Date

How to fill in the template

1. Pick an owner

Choose one person to answer questions and approve new tools, plus a backup. In a smaller business this is often the operations lead, the IT lead or your managed IT provider. What matters is speed: if a tool request takes weeks, people will find a workaround.

2. Choose approved tools and accounts

As of October 2026:

  • OpenAI doesn’t train on ChatGPT Business, Enterprise or API data by default, but does use data from its services for individuals (OpenAI). Individuals can opt out by turning off “Improve the model for everyone” (OpenAI Help Center).
  • Anthropic trains on Claude Free, Pro and Max chats when the user’s setting is on, and keeps that data for five years. This doesn’t apply to Claude for Work (Team and Enterprise) or the API (Anthropic, 2025).
  • Microsoft says Microsoft 365 Copilot prompts, responses and company data aren’t used to train its foundation models (Microsoft Learn).

Vendor terms change, so check them again when you review your policy. People use personal accounts when the approved option is missing or worse.

3. Provide guidelines on which data is safe to use for AI tools

In a 2025 survey of 1,000 US adults, nearly half of employees (46%) admitted pasting company information into public AI tools like ChatGPT, sometimes without knowing whether it was sensitive or confidential (Laserfiche, 2025).

In summer 2025, the acting head of CISA, the US government’s cybersecurity agency, uploaded contracting documents marked “for official use only” to a public version of ChatGPT, which set off multiple automated security alerts (Politico, 2026).

Provide guidelines on which kinds of information are Public, Internal or Confidential, and which must never go into AI. Section 5 of the template sets out all four levels, with examples.

4. Keep AI out of decisions about people

Illinois, New York City and Colorado all have laws on AI in employment decisions (details below). The simplest choice for most businesses is a ban, with exceptions only after HR or legal approval.

How to roll out your AI policy

  1. Announce it with the reason: you want people to use AI safely, not to catch them out. Name the owner.
  2. Ask which AI tools people already use, with no penalty for answering. The answers tell you what to approve.
  3. Walk through the examples in a short team meeting. Most questions will be “Can I use this tool for that task?”
  4. Collect a signed acknowledgment from everyone, and keep a record of who completed training.
  5. Add the policy and training to onboarding, so new hires get it on day one.

The frameworks behind this template

  • NIST AI Risk Management Framework (US government, 2023, free and voluntary). Its “Govern” section asks organizations to document the laws that apply, set clear roles, train staff and have policies for third-party AI (NIST). Template sections 2, 4 and 12.
  • NIST Generative AI Profile (2024). Recommends “transparent acceptable use policies” for generative AI, and lists risks such as made-up answers, data privacy, information security and intellectual property (NIST). Sections 5 and 7.
  • ISO/IEC 42001 (2023). The international standard for managing AI in an organization. It includes writing an AI policy, aligning it with your other policies and reviewing it at planned intervals (ISO). Sections 5 and 15.
  • Future of Privacy Forum generative AI checklist (2023, updated 2024). Advises reminding employees to check AI output for accuracy, timeliness, bias and intellectual property, and revisiting your existing privacy, data use and information classification policies so they cover AI (FPF). Sections 5 and 7.
  • OWASP LLM AI Cybersecurity and Governance Checklist (2024). Calls “Shadow AI”, meaning employees using unapproved AI tools, browser plug-ins and apps, the most pressing LLM threat for many organizations that doesn’t come from attackers. Recommends publishing a table of how employees may use each generative AI tool (OWASP). Sections 3, 12 and 13.

Laws to check with your legal team

  • EU AI Act. Since 2 February 2025, companies that provide or use AI systems must support their staff’s AI literacy. No certificate is needed; an internal training record is enough. National authorities enforce it from August 2026 (European Commission).
  • Illinois. Since January 1, 2026, employers may not use AI that discriminates in hiring, promotion, discipline or firing, and must tell employees when they use AI for these decisions (Illinois Public Act 103-0804).
  • New York City. Automated hiring tools need a bias audit within the past year, published results and notices to candidates (NYC Department of Consumer and Worker Protection).
  • Colorado. A new law signed in May 2026 replaces the state’s 2024 AI law and takes effect January 1, 2027. It covers automated tools used in “consequential decisions”, including employment (Colorado General Assembly).
  • Health information. A business covered by HIPAA may share protected health information with a vendor acting for it only under a business associate agreement (HHS).
  • Law firms. Lawyers using generative AI must weigh competence, confidentiality, client communication, supervision and fees (ABA Formal Opinion 512).
  • Copyright. AI output is protected only where a human decided enough of its expressive content. Prompts alone don’t count (US Copyright Office, 2025).

Also ask your lawyer about the discipline wording in section 14, the employee-rights line, any monitoring of employee AI use in section 13, and your customer contracts.