Free AI Acceptable Use Policy Template
Set clear employee rules for using ChatGPT, Microsoft Copilot, Claude, Gemini and other AI tools at work. The editable Word template covers approved tools, data restrictions, output verification, high-impact uses, AI agents, incidents and accountability.
No email gate · Editable Word document · Global starter · Published by Evidelis / Ingenii OÜ
What a practical employee AI policy needs to answer
The policy should remove guesswork. Staff need to know which tools they may use, what information they may share, what they must verify and when they need approval or specialist review.
Tools & data
✓ Which AI tools and account types are approved?
✓ What data may or may not be entered?
✓ How are new tools approved?
Human responsibility
✓ Who checks important output?
✓ Which decisions must remain human?
✓ When may automation act externally?
Escalation & evidence
✓ How are incidents reported?
✓ Who owns exceptions and review?
✓ What records should be retained?
Copy-ready AI acceptable use policy template
Replace the bracketed fields, remove sections that do not apply and add stricter rules where your contracts, industry or local law require them. The downloadable Word version also includes approved-tool and data-handling appendices.
1. Purpose
Policy rule. This policy sets the conditions under which people working for [ORGANISATION NAME] may use artificial intelligence systems for company work.
Objective. The organisation supports useful and responsible AI use while protecting confidential information, personal information, intellectual property, customers, workers, business decisions and operational integrity.
2. Scope
This policy applies to employees, directors, contractors, temporary staff, interns and other authorised workers. It covers generative AI assistants, copilots, image/audio/code generators, transcription and summarisation tools, AI agents, automated scoring or recommendation systems, plugins, browser extensions and AI features embedded in other software.
3. Core principles
Use approved tools. Use AI services approved for the relevant type of work and data.
Keep a human accountable. An identified person remains responsible for material outputs, decisions and actions.
Protect information. Do not enter information unless its use is permitted by organisational rules, contracts and applicable law.
Verify before relying. Treat AI output as unverified until a competent person checks it to the level appropriate for the task.
4. Approved tools and accounts
Company work may be performed only with tools listed on the organisation’s approved list or approved through its tool-approval process. Where a business or enterprise account is provided, use it rather than a personal account for company work.
5. Permitted uses
AI may be used for low- and moderate-risk work where the tool, data and workflow are approved and the output receives appropriate human review. Examples may include drafting, summarisation, brainstorming, translation, coding assistance, document structuring, research support, meeting notes and data analysis.
6. Prohibited and restricted uses
Do not use AI for unlawful or harmful activity, to bypass company controls, or to present unverified AI output as verified fact, professional advice, evidence or an authorised company position.
Do not allow an AI system to make or materially determine high-impact decisions about people or essential outcomes unless the use case has received the required specialist review and approval.
7. Data and confidentiality
Only enter data permitted for the specific approved tool and account configuration. Unless specifically approved, do not enter passwords, authentication secrets, private keys, trade secrets, customer-confidential information, sensitive personal data, regulated data or information subject to contractual non-disclosure restrictions.
Treat file uploads, connectors, plugins, integrations, memory features and agent access as data sharing.
8. Output verification and human oversight
Check factual claims, calculations, citations, quotations, legal or technical assertions and other material content before use. AI-generated drafts must not be automatically sent, published, executed or used to trigger consequential actions unless that automation has been separately approved.
9. Intellectual property and external content
Respect licences, contracts and intellectual-property rights. Do not upload proprietary company content to services whose terms, configuration or data-handling practices have not been approved for that content.
10. AI agents and automated actions
AI agents may act only within explicitly approved systems, permissions, spending limits and task boundaries. Define where a human must approve messages, transactions, account changes, publication, purchases, data deletion or other consequential actions.
11. Approval of new tools and use cases
Seek approval before using a new AI tool or materially new AI use case where the organisation’s process applies. Approval may consider data handling, security, vendor terms, affected people, decision impact, intellectual property, accuracy, human oversight, regulatory exposure and operational dependency.
12. Incidents and concerns
Report suspected AI-related data exposure, unsafe output, discriminatory behaviour, security issues, unauthorised tool use or material errors to [CONTACT / CHANNEL]. Preserve relevant prompts, outputs, screenshots and logs where appropriate for investigation.
13. Roles and responsibilities
All users follow the policy and verify outputs. Managers set expectations and escalate higher-risk uses. [POLICY OWNER] maintains the policy and coordinates exceptions. Specialist legal, privacy, security and technical owners review matters within their areas where required.
14. Training, acknowledgement and records
Complete required AI awareness or role-specific training. Where required, acknowledge the policy. The organisation may maintain records of approved tools, use cases, risk assessments, exceptions, training, incidents and policy versions.
15. Exceptions, enforcement and review
Exceptions require documented approval from [ROLE / BODY] with a stated scope, rationale, controls and expiry or review date. Review the policy at least [QUARTERLY / EVERY SIX MONTHS / ANNUALLY] and after material changes in AI use, incidents, vendors, law or company risk appetite.
A policy gives staff rules. Governance makes those rules operational.
A mature AI governance system also needs an AI inventory, use-case approval, risk assessment, vendor review, incident handling, human oversight, training evidence and recurring management review. Evidelis connects those controls into one operating model.
Frequently asked questions
What is an AI acceptable use policy?
An AI acceptable use policy sets practical rules for how employees and contractors may use AI tools at work, including approved tools, data restrictions, output verification, prohibited uses, accountability and incident reporting.
Should an AI policy name approved tools?
Yes. A workable policy should identify approved tools or define a clear approval process because data handling and contractual protections can differ between consumer, business and enterprise accounts.
Does an AI acceptable use policy make a company compliant?
No. A policy is one governance control. It does not by itself establish legal or regulatory compliance and may need to be supplemented by privacy, security, risk, procurement, sector-specific and specialist review.
Read the practical AI Governance Framework guide →
Reference: NIST AI Risk Management Framework (AI RMF), a voluntary framework for organisations managing AI risks: NIST AI RMF. The Evidelis template is not a NIST certification or conformance tool.