Regulation & governance8 min read

How to Write an AI Acceptable Use Policy for Your Team

How to write an AI acceptable use policy: the sections to include, a copyable outline, a traffic-light data rule, rollout steps and mistakes to avoid.

An AI acceptable use policy tells employees how they may use AI tools at work. A useful policy is short and practical: it lists approved tools, sets clear rules on what data may be entered where, requires people to check and take responsibility for AI output, names uses that are not allowed or need approval, and says who to ask. Write it in plain language, explain the reasons behind the rules, train people on it, and review it regularly. Below is an outline you can adapt.

This article is general guidance, not legal advice. Depending on your sector and country, data protection, employment law and regulations such as the EU AI Act may require additional content. Have the final policy reviewed by someone qualified, and involve employee representatives where required.

Why an AI policy is worth the effort

Without rules, every employee decides individually which tools to use and what to paste into them. The typical risks:

  • Confidential or personal data entered into tools whose terms allow retention or training on inputs.
  • AI-generated errors reaching customers because nobody checked.
  • Unclear ownership of content and decisions.
  • Inconsistent quality and tone across the team.
  • Uses that touch regulated areas, such as evaluating job applicants, without anyone noticing.

A policy does not solve these alone, but it makes expectations clear and gives people a reference when they are unsure.

Principles for a policy people will follow

  • Enable, then restrict. Approve good tools first. A policy that only forbids pushes use underground.
  • Be concrete. "Use AI responsibly" means nothing. "Do not enter customer names or contact details into tools not on the approved list" is clear.
  • Explain why. People follow rules they understand.
  • Keep it short. Two to four pages, with details in appendices or linked guides.
  • Name owners. Who approves tools, who answers questions, who updates the policy.
Section Content
1. Purpose and scope Why the policy exists, who it applies to, which tools count as AI
2. Approved tools List of tools, what each may be used for, how to request new ones
3. Data rules What data may be entered into which tools
4. Using outputs Checking, responsibility, labelling, intellectual property
5. Prohibited and restricted uses What is not allowed and what needs approval
6. Transparency When to disclose AI use to customers or the public
7. Security Accounts, access, integrations, incidents
8. Training and support What training is required, where to get help
9. Responsibilities Roles: policy owner, tool owners, managers, employees
10. Review and changes Review cycle and version history

Section by section

1. Purpose and scope

State that the policy applies to all employees, contractors and anyone using AI tools on the company's behalf, and that it covers generative AI assistants, AI features inside other software, and AI systems built or integrated by the company.

2. Approved tools

List each approved tool with its permitted uses. For example: "General AI assistant (business account): drafting, summarising, research help. Not for customer personal data." Explain how to request a new tool and who evaluates it. Make clear that personal accounts of AI tools must not be used for company data.

3. Data rules

This is the most important section. A traffic-light system is easy to remember:

Category Examples Rule
Green: public or non-sensitive Published marketing texts, general questions, anonymised examples Allowed in approved tools
Amber: internal Internal processes, non-confidential project notes Allowed only in approved tools with business data terms
Red: confidential or personal Customer and employee personal data, contracts, financials, trade secrets, passwords Not allowed, unless a specific tool is approved for that data type

Add: "When in doubt, treat data as red and ask." Adjust the categories to your company's data classification if you already have one.

4. Using outputs

  • Employees remain responsible for any work they produce with AI assistance.
  • AI output must be checked for accuracy before use, especially facts, figures, names, legal or technical statements. Explain that AI can produce convincing but false content; link to internal guidance or to an explainer such as how to reduce AI hallucinations.
  • Customer-facing or consequential outputs must be reviewed by a person before they are sent or published.
  • Do not present AI output as the verified opinion of an expert unless an expert has checked it.
  • Be aware of intellectual property: do not ask tools to reproduce copyrighted material, and check terms on ownership of outputs.

5. Prohibited and restricted uses

Not allowed, for example:

  • Using AI to make final decisions about individuals' employment, pay, promotion or termination.
  • Uses that may fall under the practices prohibited by the EU AI Act, such as emotion recognition of employees at the workplace.
  • Creating misleading content, impersonating real people, or generating content that violates law or company values.
  • Entering red-category data into tools not approved for it.

Requires approval, for example:

  • Any AI use in recruitment, performance evaluation, credit decisions or other areas that may be high-risk under the EU AI Act.
  • Customer-facing chatbots or automated communication.
  • Integrations that connect AI tools to company systems or customer data.
  • Publishing AI-generated images, audio or video of real people.

The EU AI Act risk checker helps you identify which planned uses deserve closer review, and EU AI Act risk categories explains the tiers.

6. Transparency

Define when AI use must be disclosed, for example: chatbots must identify themselves as AI, and AI-generated or manipulated images, audio or video that could appear authentic must be labelled. These reflect transparency duties under the EU AI Act; your rules can go further, for example stating your company's position on disclosing AI assistance in customer communication.

7. Security

  • Use company accounts with single sign-on or strong authentication where available.
  • Never enter passwords, API keys or access credentials into AI tools.
  • Integrations need approval and secure storage of keys.
  • Report incidents, such as confidential data entered into the wrong tool, immediately to [contact], without fear of blame for honest mistakes.

8. Training and support

State what training employees receive before using AI tools and where to find help, such as an internal channel or named contact. In the EU, the AI Act requires measures for sufficient AI literacy; see AI literacy under the EU AI Act for how to approach this.

9. Responsibilities

Role Responsibility
Policy owner Maintains the policy, approves tools, handles questions
Tool owners Configure tools, manage access, monitor terms and costs
Managers Make sure their team knows and follows the policy
Employees Follow the rules, check outputs, report problems

10. Review and changes

Set a review date, keep a version history, and announce changes.

A one-page short version

Many teams benefit from a summary alongside the full policy:

  1. Use only approved AI tools with your company account.
  2. Never enter personal, confidential or financial data unless the tool is approved for it.
  3. You are responsible for what you produce with AI. Check facts before using output.
  4. A person reviews anything that goes to customers or the public.
  5. Do not use AI to decide about people's jobs, pay or access to services.
  6. Label AI-generated media of real people and say when customers talk to a bot.
  7. Ask [contact] when in doubt. Report mistakes immediately.

Rolling it out

  1. Find out what is already used. A short anonymous survey often reveals widespread use of personal accounts.
  2. Approve tools before publishing the policy, so people have a compliant alternative.
  3. Draft with input from the people who use AI daily. They know the real use cases.
  4. Review with legal, data protection and, where applicable, employee representatives.
  5. Launch with a short session, not just an email. Show examples of allowed and not allowed use.
  6. Collect questions in the first weeks and add answers to an FAQ.
  7. Review after three months, then at least yearly.

Common mistakes

  • Banning everything. People will use AI anyway, without guidance.
  • Writing for lawyers instead of employees. If staff cannot apply it in a minute, they will not.
  • No approved tools. Rules without alternatives create workarounds.
  • Forgetting AI inside existing software. Office, CRM and HR tools increasingly include AI features.
  • Never updating. Tools and rules change quickly.
  • No link to the bigger picture. Connect the policy to your AI adoption plan and use case inventory, as described in the AI readiness checklist.

Summary

A good AI acceptable use policy is short, specific and enabling: approved tools, clear data rules, responsibility for outputs, a list of restricted uses and a named contact. Draft it with the people who use AI, have it checked by qualified advisers, train the team, and review it regularly. For the regulatory side, continue with EU AI Act obligations for deployers.

FAQ

What is an AI acceptable use policy?

It is a company document that sets out how employees may use AI tools at work: which tools are approved, what data may be entered, how outputs must be checked, which uses are not allowed and who to ask.

Does a small business need an AI policy?

If staff use AI tools for work, yes. Even a one- or two-page policy prevents the most common problems, especially confidential or personal data being pasted into unapproved tools.

Should an AI policy ban tools like ChatGPT?

Outright bans tend to push use into personal accounts where you have no control. A better approach is to approve suitable business tools, set clear data rules and explain the reasons.

How often should an AI policy be updated?

Review it at least once a year and whenever you approve a new tool, start a new type of use case, or relevant law or guidance changes.

Related articles

Regulation & governance9 min read

EU AI Act for Deployers: What Businesses Must Do

EU AI Act obligations for deployers: AI literacy, transparency duties, high-risk use rules, when a user becomes a provider, and a practical checklist.

Regulation & governance9 min read

EU AI Act Risk Categories Explained With Examples

The four EU AI Act risk categories explained with business examples: prohibited, high-risk, transparency and minimal risk, plus GPAI rules and borderline cases.

← Back to the blog