Free practical resource

Free AI Acceptable Use Policy Template

Set clear employee rules for using ChatGPT, Microsoft Copilot, Claude, Gemini and other AI tools at work. The editable Word template covers approved tools, data restrictions, output verification, high-impact uses, AI agents, incidents and accountability.

No email gate · Editable Word document · Global starter · Published by Evidelis / Ingenii OÜ

What a practical employee AI policy needs to answer

The policy should remove guesswork. Staff need to know which tools they may use, what information they may share, what they must verify and when they need approval or specialist review.

Tools & data

✓ Which AI tools and account types are approved?

✓ What data may or may not be entered?

✓ How are new tools approved?

Human responsibility

✓ Who checks important output?

✓ Which decisions must remain human?

✓ When may automation act externally?

Escalation & evidence

✓ How are incidents reported?

✓ Who owns exceptions and review?

✓ What records should be retained?

Copy-ready AI acceptable use policy template

Replace the bracketed fields, remove sections that do not apply and add stricter rules where your contracts, industry or local law require them. The downloadable Word version also includes approved-tool and data-handling appendices.

1. Purpose

Policy rule. This policy sets the conditions under which people working for [ORGANISATION NAME] may use artificial intelligence systems for company work.

Objective. The organisation supports useful and responsible AI use while protecting confidential information, personal information, intellectual property, customers, workers, business decisions and operational integrity.

2. Scope

This policy applies to employees, directors, contractors, temporary staff, interns and other authorised workers. It covers generative AI assistants, copilots, image/audio/code generators, transcription and summarisation tools, AI agents, automated scoring or recommendation systems, plugins, browser extensions and AI features embedded in other software.

3. Core principles

Use approved tools. Use AI services approved for the relevant type of work and data.

Keep a human accountable. An identified person remains responsible for material outputs, decisions and actions.

Protect information. Do not enter information unless its use is permitted by organisational rules, contracts and applicable law.

Verify before relying. Treat AI output as unverified until a competent person checks it to the level appropriate for the task.

4. Approved tools and accounts

Company work may be performed only with tools listed on the organisation’s approved list or approved through its tool-approval process. Where a business or enterprise account is provided, use it rather than a personal account for company work.

5. Permitted uses

AI may be used for low- and moderate-risk work where the tool, data and workflow are approved and the output receives appropriate human review. Examples may include drafting, summarisation, brainstorming, translation, coding assistance, document structuring, research support, meeting notes and data analysis.

6. Prohibited and restricted uses

Do not use AI for unlawful or harmful activity, to bypass company controls, or to present unverified AI output as verified fact, professional advice, evidence or an authorised company position.

Do not allow an AI system to make or materially determine high-impact decisions about people or essential outcomes unless the use case has received the required specialist review and approval.

7. Data and confidentiality

Only enter data permitted for the specific approved tool and account configuration. Unless specifically approved, do not enter passwords, authentication secrets, private keys, trade secrets, customer-confidential information, sensitive personal data, regulated data or information subject to contractual non-disclosure restrictions.

Treat file uploads, connectors, plugins, integrations, memory features and agent access as data sharing.

8. Output verification and human oversight

Check factual claims, calculations, citations, quotations, legal or technical assertions and other material content before use. AI-generated drafts must not be automatically sent, published, executed or used to trigger consequential actions unless that automation has been separately approved.

9. Intellectual property and external content

Respect licences, contracts and intellectual-property rights. Do not upload proprietary company content to services whose terms, configuration or data-handling practices have not been approved for that content.

10. AI agents and automated actions

AI agents may act only within explicitly approved systems, permissions, spending limits and task boundaries. Define where a human must approve messages, transactions, account changes, publication, purchases, data deletion or other consequential actions.

11. Approval of new tools and use cases

Seek approval before using a new AI tool or materially new AI use case where the organisation’s process applies. Approval may consider data handling, security, vendor terms, affected people, decision impact, intellectual property, accuracy, human oversight, regulatory exposure and operational dependency.

12. Incidents and concerns

Report suspected AI-related data exposure, unsafe output, discriminatory behaviour, security issues, unauthorised tool use or material errors to [CONTACT / CHANNEL]. Preserve relevant prompts, outputs, screenshots and logs where appropriate for investigation.

13. Roles and responsibilities

All users follow the policy and verify outputs. Managers set expectations and escalate higher-risk uses. [POLICY OWNER] maintains the policy and coordinates exceptions. Specialist legal, privacy, security and technical owners review matters within their areas where required.

14. Training, acknowledgement and records

Complete required AI awareness or role-specific training. Where required, acknowledge the policy. The organisation may maintain records of approved tools, use cases, risk assessments, exceptions, training, incidents and policy versions.

15. Exceptions, enforcement and review

Exceptions require documented approval from [ROLE / BODY] with a stated scope, rationale, controls and expiry or review date. Review the policy at least [QUARTERLY / EVERY SIX MONTHS / ANNUALLY] and after material changes in AI use, incidents, vendors, law or company risk appetite.

Important: this is a general governance drafting aid, not legal advice and not a compliance certificate. It does not replace privacy, security, employment, sector-specific, model-validation or regulatory review where those are required.

A policy gives staff rules. Governance makes those rules operational.

A mature AI governance system also needs an AI inventory, use-case approval, risk assessment, vendor review, incident handling, human oversight, training evidence and recurring management review. Evidelis connects those controls into one operating model.

Frequently asked questions

What is an AI acceptable use policy?

An AI acceptable use policy sets practical rules for how employees and contractors may use AI tools at work, including approved tools, data restrictions, output verification, prohibited uses, accountability and incident reporting.

Should an AI policy name approved tools?

Yes. A workable policy should identify approved tools or define a clear approval process because data handling and contractual protections can differ between consumer, business and enterprise accounts.

Does an AI acceptable use policy make a company compliant?

No. A policy is one governance control. It does not by itself establish legal or regulatory compliance and may need to be supplemented by privacy, security, risk, procurement, sector-specific and specialist review.

Read the practical AI Governance Framework guide →

Reference: NIST AI Risk Management Framework (AI RMF), a voluntary framework for organisations managing AI risks: NIST AI RMF. The Evidelis template is not a NIST certification or conformance tool.