AI acceptable use policy template
The example below was written by the policy generator for a company operating in the US, EU and UK. Answer the 12 questions to get a version written for your organisation.
A template, not legal advice.
Example Co: AI acceptable use policy Version 1.0 · 28 September 2026 · Owner: Chief Operating Officer · Review every 6 months 1. Purpose This policy lets people at Example Co use AI tools that help their work while protecting the sensitive information we handle. It says which tools may be used, what may be shared with them, and who decides. 2. Scope Everyone who works for or with Example Co (employees, contractors and temporary staff), on any device, whenever the work involves Example Co information. It covers chat assistants, coding assistants, meeting recorders and note-takers, ai features inside software you already use, your own apps calling ai model apis, and any AI feature added to software we already use. 3. Approved tools Only AI tools on the approved list may be used with Example Co information, signed in with a company account. IT and Security keeps the list and decides on requests. Using an unapproved tool for work is not allowed; asking for one to be approved is encouraged. 4. What must never be entered into an AI tool - Passwords, API keys, tokens or other credentials - Customers' personal data, unless the tool is approved for it - Employee or HR records - Client confidential information without the client's agreement If in doubt, don't paste it; ask IT and Security. 5. Checking AI output AI output can be wrong, out of date or biased. The person who uses it is responsible for checking it before it is sent, published or relied on, and for the final decision. 6. AI that customers see Customers are told when they are dealing with an AI system or reading content substantially generated by AI, and can reach a person. Customer-facing AI is approved by Chief Operating Officer before launch and monitored for wrong or harmful answers. The EU AI Act sets transparency obligations for AI systems that interact with people (Article 50). 7. Meeting recorders Only the approved recorder may be used. Everyone in the meeting is told it is being recorded before it starts, and recordings and transcripts are deleted after [90] days unless they are needed as a record. 8. Software that calls AI Applications and scripts that send Example Co data to an AI model use company-owned keys held in the secrets manager, have a named owner, and are listed in the AI inventory. Personal API keys must not be used for company work. 9. AI literacy Everyone who uses AI tools at work completes Example Co's AI awareness session when they join and once a year, covering this policy, what not to share, checking output, and spotting AI-enabled fraud. Chief Operating Officer keeps the completion records. In the EU, Article 4 of the AI Act requires providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy of their staff (applying since 2 February 2025). 10. Inventory and monitoring IT and Security keeps an inventory of approved AI tools and agents, reviews network and sign-in logs for unapproved AI services [monthly], and updates the approved list. The aim is to find tools people need, not to discipline them. 11. Reporting problems Report any accidental sharing of restricted information with an AI tool, any harmful or wrong AI output that reached a customer, and any suspected AI-enabled fraud (for example a voice or video impersonating a manager) to IT and Security straight away. 12. UK data protection When AI processes personal data, Example Co follows UK GDPR, including a data protection impact assessment where the processing is likely to be high risk. The ICO's guidance on AI and data protection is the reference. 13. Breaches of this policy Breaches are handled under the disciplinary policy. Honest mistakes reported quickly are treated as the right thing to do. Approved by: ____________________ Role: Chief Operating Officer Date: ____________