AI Policy March 24, 2026 9 min read

AI Acceptable Use Policy Template

An AI acceptable use policy is a short written document that tells your employees which AI tools they may use, what data they may put into those tools, and who is accountable for the output. Below is a free, editable template you can copy and paste in full, download as Word or PDF, and adapt to your company — plus a section-by-section guide to what each part should say. Written for HR managers and operations leads who need to act fast without a 50-page legal document.

Jump to the full copy-and-paste template ↓

A year ago, an AI policy was something large enterprises put in their roadmaps for next quarter. Today it's something employees are asking for by name — and something auditors, insurers, and enterprise customers are starting to require before signing contracts.

The good news: you don't need a legal team or a six-month project to have one. You need clarity on seven things. This guide walks through each one.

63% of companies have no formal AI governance policy — despite the majority of their employees already using AI tools at work daily. IBM Institute for Business Value, 2025

What should be in an AI acceptable use policy?

A good AI acceptable use policy is short, specific, and enforceable. At a minimum it should cover eight things:

The template below contains all eight, written in plain language with fill-in-the-blank fields you can edit. Read on, or copy the whole thing.

The full AI acceptable use policy template (copy, paste & edit)

This is a complete, generic AI acceptable use policy you can use as a starting point. Replace every [bracketed] field with your own details, delete what doesn't apply, and have it reviewed before adoption.

Download or copy this template
Prefer Google Docs? Download the Word file and open it with File → Open in Google Docs, or paste the plain-text version into a new doc.
Already have a policy? Check it for gaps in 30 seconds → — see how many of the 9 essential sections and 25 high-risk AI tools it actually covers.
This free template
A generic skeleton you finish yourself
  • You replace every [bracket] and make each call yourself
  • A 3-row example tier table you fill in by hand
  • No manager FAQ; a basic acknowledgment block
  • Static — you re-check it against the law on your own
[COMPANY NAME] — AI Acceptable Use Policy
Effective date: [DATE] · Version: [1.0] · Policy owner: [NAME / ROLE] · Review cycle: [Quarterly / Biannual]

1. Purpose

This policy explains how workers at [Company Name] may use artificial intelligence (AI) tools in the course of their work. Its goals are to let people use AI productively while protecting [Company Name]'s data, customers, employees, and legal obligations.

2. Scope

This policy applies to [all employees, contractors, interns, and temporary workers] who use [Company Name] devices, accounts, systems, or data. It covers all AI tools — generative AI assistants, AI writing and coding tools, AI meeting note-takers, and AI features built into other software — whether accessed through a company account or a personal account, when used for work purposes.

[Choose one: This policy applies to AI use on personal devices during work hours / only to company-owned devices and company accounts.]

3. Definitions

4. Roles and responsibilities

5. Approved, limited, and prohibited tools (tool tier list)

[Company Name] classifies AI tools into three tiers. The current tier list is maintained at [link or location] and reviewed every [period]. Before using any AI tool that is not on the list, request approval from [role].

6. Data handling rules

Do not enter the following into any AI tool unless that specific tool is approved for that data type:

Rule of thumb: if you would not post it publicly, do not put it into a non-approved AI tool. When in doubt, ask [role] before sharing.

7. Human oversight and accountability

The person who uses an AI tool is responsible for its output. All AI-generated work — emails, documents, code, and analysis — must be reviewed and verified by a qualified person before it is sent, published, or relied upon. AI must not make final decisions on [hiring, promotion, discipline, lending, or other high-stakes matters] without documented human review and sign-off.

8. Disclosure and transparency

Disclose AI use where required, for example: [AI-generated content shared externally with clients or the public; AI-assisted analysis in executive or board materials; AI used in any regulated process; AI-generated code deployed to production]. Follow any client or contractual disclosure requirements that apply to your work.

9. Acceptable uses

Encouraged uses, with non-confidential data and human review, include: drafting and editing, brainstorming, summarizing public material, writing and debugging code, research starting points, and learning.

10. Prohibited uses

Do not use AI tools to: enter prohibited data (Section 6); generate content that is unlawful, harassing, discriminatory, or infringing; present AI output as independently verified when it is not; attempt to bypass security or access controls; or make prohibited automated decisions (Section 7).

11. Incident reporting

If you accidentally share confidential data with an AI tool, act on harmful or incorrect AI output, or notice a possible policy violation, report it to [role / contact] promptly. Reporting is non-punitive; reporting early limits harm.

12. Enforcement

Violations may result in [graduated consequences: a coaching conversation, a formal warning, up to termination] depending on severity and intent, consistent with [Company Name]'s [disciplinary / HR] policies.

13. Review schedule

This policy is reviewed at least every [six months] and is updated when major AI tools change their data practices, when a new tool category becomes widely used, or when relevant regulations change. Policy owner: [name / role].

14. Employee acknowledgment

By signing below, I confirm that I have read and understood [Company Name]'s AI Acceptable Use Policy and agree to follow it.

Employee name: ____________________________

Signature: ____________________________

Date: ____________________________

Who this is for

This guide is written for HR managers, operations directors, and compliance leads at companies between 50 and 500 employees. You probably don't have a dedicated AI governance team. You may not have a CISO. What you do have is employees who are using ChatGPT, Copilot, Claude, and a dozen other tools to do their jobs — and no documented rules about how.

Enterprise guides for this topic are written for IT departments with six-figure tooling budgets. This one isn't. The goal is a policy you can actually draft, communicate, and enforce with the team you have.

The 7 sections every AI acceptable use policy needs

Section 1

Purpose and scope

This section answers: why does this policy exist, and who does it apply to? Be specific about scope — does it cover contractors and vendors, or only direct employees? Does it apply to personal AI use on company devices, or only AI used for work tasks?

Decision to make: Does this policy apply to personal device usage during work hours, or only to company-owned devices and company accounts?
Section 2

Tool classification: approved, limited, and prohibited

This is the heart of the policy. Employees need to know which tools they can use without asking, which require approval or have specific restrictions, and which are off-limits entirely. The three-tier structure works better than a binary approved/banned list because it prevents the policy from being so restrictive that people ignore it.

A basic tier structure looks like this:

Tier What it means Example tools
Tier 1 — Approved Use freely for work tasks with standard data handling ChatGPT Enterprise, Microsoft Copilot (enterprise), Claude Teams
Tier 2 — Limited Approved with specific restrictions on data types ChatGPT Free, Gemini (personal), Perplexity
Tier 3 — Prohibited Not approved for any work use Unknown/unvetted AI tools, tools with no data processing agreements
Decision to make: What's your process when an employee finds a new AI tool they want to use? Define the approval path — even a simple "email your manager and IT" is better than silence.
Section 3

Data handling rules

This is the section that prevents the actual expensive mistakes. Employees need to know which categories of information should never be entered into an AI tool, and why. The rule of thumb that works well in plain language: if you wouldn't post it publicly on the internet, don't put it in a free AI tool.

Categories to address:

Decision to make: Paid enterprise tiers of most AI tools include contractual commitments that your data won't be used for training. Free tiers typically don't. Do you want to allow free-tier tool use for any work tasks?
38% of employees report sharing sensitive company data with AI tools without explicit permission from their employer. CybSafe / National Cybersecurity Alliance, 2024
Section 4

Human oversight requirements

AI output is the responsibility of the person who used it. This section makes that explicit. Every AI-generated output — whether it's a contract summary, a customer email, a performance review, or a code commit — must be reviewed by a qualified human before it's used or sent.

For higher-stakes decisions, go further: AI should not make final decisions on hiring, promotions, disciplinary action, or lending/credit without documented human review and sign-off.

Decision to make: Which job functions in your company carry the highest AI output risk? Those roles may need more specific guidance beyond the general policy — for example, customer-facing staff, finance, and legal.
Section 5

Disclosure and transparency

When does your company require disclosure that AI was used? This varies by use case and industry. A marketing team using AI to draft a first-pass blog post may have different disclosure requirements than a legal team using AI to summarize a contract.

Common disclosure requirements to consider:

Decision to make: Does your industry have existing regulations that require AI disclosure? Healthcare, financial services, and legal all have sector-specific rules developing rapidly in 2026.
Section 6

Incident reporting

Employees need a simple, non-punitive way to report when something goes wrong — when they realize they pasted customer data into the wrong tool, when they notice a colleague doing something the policy doesn't allow, or when an AI output caused a problem with a client or partner.

The goal is to surface issues early before they become expensive. A culture where mistakes get reported quickly is worth far more than the threat of discipline that ensures mistakes get hidden.

Decision to make: Who owns AI incident reports in your company? HR, IT, Legal, or a combination? Designate a named person or role, not a committee.
Section 7

Enforcement and review schedule

A policy with no enforcement mechanism is a suggestion. Outline consequences for policy violations — typically a graduated scale from coaching conversation to formal warning to termination for serious or repeat violations.

More importantly: commit to a review schedule. AI tools, regulations, and best practices are moving fast in 2026. A policy that made sense when you wrote it in Q1 may need meaningful updates by Q3. Quarterly or biannual review is appropriate for most companies.

Decision to make: Who owns policy updates? Assign a named policy owner — not a committee — who is responsible for initiating each review cycle.

How to draft an AI acceptable use policy (step by step)

If you're drafting an AI acceptable use policy from scratch, work through it in this order. It mirrors the seven sections above and keeps the drafting process from stalling on the hard calls:

  1. Set the scope first. Decide who the policy covers and whether it applies to personal devices during work hours — everything else depends on this.
  2. Inventory the AI tools already in use. A quick anonymous survey beats guessing; you can't tier tools you don't know about.
  3. Draft the data-handling rules. List the categories of information that must never go into a non-approved tool. This is the section that prevents the expensive mistakes.
  4. Sort tools into the three tiers. Approved, limited, and prohibited — with named tools, not vague categories.
  5. Add human-oversight and disclosure rules. State that a person is accountable for every AI output before it is sent or published.
  6. Write the enforcement, review, and acknowledgment sections. Name a policy owner and a review cadence, and attach a signature block.
  7. Circulate a draft, then communicate it. A walkthrough or Q&A produces far better compliance than emailing a PDF.

Drafting from the template above collapses this from a multi-week project into an afternoon. If you'd rather not draft it by hand at all, the AI policy generator produces a completed draft — tool tier list included — in about ten minutes.

AI policy example: what a completed one looks like

The bracketed template above is the skeleton. Here is a short AI policy example with the blanks filled in, so you can see the level of specificity that makes a policy enforceable rather than aspirational:

Northwind Consulting — AI Acceptable Use Policy (excerpt)
Effective date: March 1, 2026 · Version: 1.0 · Policy owner: Head of Operations · Review cycle: Quarterly

Data handling (example)

Do not enter client names, engagement details, financial figures, or any document marked "Confidential" into any AI tool that is not on the Tier 1 approved list. When in doubt, ask the Head of Operations before pasting.

Tool tiers (example)

AI tool usage policy vs. AI acceptable use policy — is there a difference?

In practice, no. "AI tool usage policy," "AI use policy," "generative AI policy," and "AI acceptable use policy" all describe the same document: the written rules for which AI tools employees may use and how. The template on this page works under any of those titles — pick whichever name your team recognizes and change the heading to match.

What a good policy doesn't do

The worst AI policies are either so restrictive that everyone ignores them, or so vague that they provide no real guidance. Both failures are expensive.

A blanket "no AI tools" policy is effectively unenforceable at most companies. Research consistently shows that employees continue using personal AI accounts even after organizational bans — they just become less likely to tell anyone when something goes wrong. Driving shadow AI further underground is worse than the alternatives.

"Only 15% of organizations have updated their acceptable use policies to address AI tools — despite the behavior being near-universal." — ISACA, 2025

A good policy doesn't try to ban innovation. It creates a clear structure that lets employees use AI productively while protecting the company from the specific risks that actually matter: data leakage, compliance violations, and unreviewed AI output making its way to clients or regulators.

The section most templates skip

Most free AI policy templates are static documents — a Word file with a date at the top. They're missing two things that are essential for the policy to actually work:

A tool tier list. Telling employees what categories of data they can share with AI tools is half the job. Telling them specifically which tools fall into which tier — so they can look up whether the tool they just found is approved before using it — is the other half. Without a tier list, the data handling rules have no anchor.

An employee acknowledgment form. Distributing a policy document by email and assuming people read it is not the same as having employees formally acknowledge it. An acknowledgment form creates a documented record that the policy was communicated and understood — relevant if an enforcement conversation happens later, and increasingly relevant as cyber liability insurers and enterprise customers ask for evidence of AI governance programs.

How long does this take?

Written from scratch by HR or legal, drafting an AI acceptable use policy typically takes two to four weeks — including stakeholder review cycles, legal sign-off, and rollout communication. That timeline is compressible if you start from a well-structured template rather than a blank page.

The rollout matters as much as the document itself. A policy communicated well — with a team walkthrough, a Q&A session, and a designated point of contact for questions — produces materially better employee behavior than the same policy distributed as a PDF attachment to an all-hands email.

Skip the blank page. Generate your policy in 10 minutes.

Shadow AI Policy generates a tailored 4-document kit for your company — the policy plus a tier list that sorts 20+ named AI tools for your industry and data, a 12-question manager FAQ, and an e-signature-ready acknowledgment form. Add monthly updates and it stays current as tools and regulations change.

Generate my policy kit →

Writing this for several clients rather than one company? MSPs, IT consultancies and fractional CISOs keep a roster of client kits that refresh monthly, under their own branding — see partner plans →

A note on keeping it current

AI regulation is moving fast in 2026. Texas and Illinois both enacted AI-related employer regulations that took effect in January. Colorado's SB 24-205 has faced legal challenges and a shifting effective date — see our AI policy news hub for the current status. California's CCPA rules around automated decision-making require employer compliance by January 2027. The EU AI Act is rolling out enforcement for high-risk systems, though a proposed "Digital Omnibus" reform could shift some deadlines.

None of these require a 50-page enterprise compliance program for a 100-person company. But they do mean that an AI policy written in early 2026 will likely need at least one meaningful update before the end of the year. Build the review cycle into the policy from day one so it actually happens.

Summary: your AI acceptable use policy checklist