AI agent policy template
For organisations whose AI agents can take actions. The example below was written by the policy generator with a $250 approval threshold; your answers change it.
A template, not legal advice.
Example Co: AI agent policy Version 1.0 · 28 September 2026 · Owner: Chief Operating Officer · Review every 6 months 1. Purpose and scope An AI agent is software that uses an AI model to decide on and take steps, such as reading systems, calling tools or APIs, sending messages or making payments, with limited or no human input for each step. Example Co uses AI agents that can take actions. This policy applies to every one of them now. It covers agents we build, agents in software we buy, and agents staff set up themselves. 2. Register and owner Every agent is registered in the AI inventory before it goes live, with: its purpose; a named owner who is accountable for what it does; the systems and data it can reach; its tools; and its approval rules. An agent without an owner is switched off. 3. Identity and permissions - Each agent has its own identity and credentials, never a person's account or a shared service account. - It gets only the permissions its task needs (least privilege), read-only wherever possible, limited to specific resources. - No admin, owner, wildcard or tenant-wide permissions without written approval from Chief Operating Officer. - Credentials are short-lived where the platform allows it, held in the secrets manager, and never written into prompts or code. - Permissions are reviewed at least quarterly and whenever the agent's task changes. 4. Human approval A named person approves, before it happens, any agent action that: - sends information outside Example Co (email, messages, uploads, posts); - moves money, issues a refund or makes a purchase above $250; - deletes or overwrites records; - changes who has access to anything; - affects a decision about a person. Approval is enforced by the system the agent acts through, not by an instruction in the agent's prompt. Payments up to $250 may run without approval only within a daily limit set by the owner and an allow-list of payees. 5. Untrusted content Agents that read email, web pages, documents or tickets treat that content as data, never as instructions. An agent that reads untrusted content must not also be able to send sensitive data out without approval. 6. Logging Every tool call and action is logged with the agent's identity, the time, the input, the result and any approval, and kept for [12] months. The owner reviews unusual activity. 7. Kill switch Every agent can be stopped at once, with its credentials revoked, by its owner and by IT and Security. The steps are documented, tested before go-live and at least twice a year, and anyone who sees an agent behaving unexpectedly reports it to IT and Security straight away. 8. Testing before go-live Before an agent goes live, and after each significant change, it is tested for prompt injection, data leakage, misuse of its tools and actions outside its purpose. Results and fixes are recorded. 9. Vendors Agents in purchased software are assessed like any vendor: what data the agent sees, whether a person approves its actions, how it can be switched off, what it logs, and which models and sub-processors it uses. These terms go into the contract. 10. Agents that affect people Customers are told when they are dealing with an agent and can reach a person. 11. Incidents An agent that acts outside its purpose, is manipulated by content it reads, or leaks data is an incident: stop it, revoke its credentials, preserve its logs, and follow the incident response plan. Approved by: ____________________ Role: Chief Operating Officer Date: ____________