Publish Your AI Acceptable-Use Policy This Month (3-Tier Template)

A friendly robot assistant pinning a blank glowing document with three colored bands onto a board while a young man employee reads it and nods

“We’re drafting one.” It’s the most common answer I get when I ask whether an organization has an AI acceptable use policy, and in a lot of cases it has been the answer for a year. Legal has a draft. HR wants changes. Someone is waiting for the approved tool decision before finishing it. The draft is getting better, and it’s protecting nobody.

While it sits in review, the absence of a policy is itself a policy, and that policy is “anything goes.” This post gives you a complete AI acceptable use policy template you can adapt and publish this month, plus the approval and rollout plan that gets it out of the drafting loop. A one-page policy that’s published beats a twelve-page policy that isn’t, and you can improve it at the first scheduled review.

How this relates to your shadow AI policy

If you’ve read the shadow AI policy your IT team actually needs, you’ve seen the core of this: three data tiers, named approved tools, and the right order of operations for curbing unsanctioned AI use. That post explains why the approach works. This one gives you the full document around it, section by section, with suggested wording, and the plan to get it approved, published, and acknowledged. The data tiers are identical in both, deliberately, so your guidance never contradicts itself.

Here’s how the assessment asks the question, and the 0 to 4 ladder I score it against:

G1. Do you have an AI acceptable use policy?

  1. No
  2. Drafting one
  3. Published, but no training or acknowledgment
  4. Published, trained, and acknowledged by employees
  5. Reviewed on a set schedule and backed by technical controls

Notice that “drafting one” scores a 1. The ladder rewards publishing, then training, then enforcement. The fastest single improvement for most organizations is to get from 1 to 3 within a month, which is exactly what the plan below is for.

The asset: an AI acceptable use policy template

Ten short sections. Keep the whole thing to two pages at most, written in plain language. Adapt the wording to your organization and your regulations.

1. Purpose and scope

“This policy explains how employees and contractors may use AI tools for work. It covers any AI tool, including AI features built into software we already use.”

2. The three data tiers

  • Never in any AI tool: customer personal data, employee and HR records, financial results before release, credentials and keys, anything under legal hold. Add anything your regulations require.
  • Only in approved tools: internal documents, code, process documentation, and drafts containing company information.
  • Fine anywhere: public information, general questions, and learning.

3. Approved tools

“Approved AI tools are listed on [intranet page]. To request a new tool, use [request form]; requests are reviewed within [number] business days.” Keep the list on a separate page so you can update it without re-approving the policy. A fast request process is what keeps people from routing around the policy.

4. Using AI output

“You are responsible for any AI output you use. Check facts, figures, and code before relying on them. Anything sent to customers or published externally must be reviewed by a person first.”

5. Prohibited uses

  • Making decisions about individuals, such as hiring, performance, or eligibility, based solely on AI output without human review.
  • Creating content that impersonates a real person.
  • Using AI to get around security controls.
  • Entering information you’re contractually obliged to keep confidential, such as material under a client NDA, into any tool not approved for it.

The first item matters more each year, as rules on automated decisions about people spread, particularly in hiring. Mapping your regulatory obligations covers how to check which apply to you.

6. Disclosure

“When AI has substantially produced content for customers or external audiences, follow your team’s disclosure guidance.” Leave the specifics to teams; a marketing team and a legal team will need different rules.

7. Privacy and monitoring notice

“Use of approved AI tools is logged for security and compliance purposes.” Saying this plainly is both fair and effective; people behave differently when they know.

8. Building with AI

“Automations, agents, or integrations that connect AI to company systems require IT approval before use.” This closes the gap where an enthusiastic employee connects an AI tool to a business system with their own credentials. The standards behind the approval are in APIs before agents.

9. Violations

“A first issue is handled through a conversation and retraining. Repeated or serious issues go through our standard HR process.” Proportionate consequences keep people reporting mistakes instead of hiding them.

10. Ownership and review

“This policy is owned by [role]. It is reviewed every six months, or sooner when significant new AI tools are adopted. Version [number], effective [date].”

Getting it approved fast

Serial email review is what keeps policies in draft. Replace it with one meeting. Invite legal, HR, security, IT, and your executive sponsor, send the draft two days ahead, and aim to leave with approval of version 1. Two framings help:

  • “Approve it for six months.” A policy with a scheduled review feels less final, which takes the perfectionism out of the room.
  • “What’s the risk of another quarter with no policy?” Put that question on the agenda. It tends to settle debates about wording.

If you have an AI council, this is its natural first decision.

A 30-day plan from draft to acknowledged

  1. Week 1: adapt the template. Fill in the approved tools list and the request process.
  2. Week 2: the single review meeting. Leave with version 1 approved and a six-month review date.
  3. Week 3: publish and announce it together with the approved tools, framed as “here’s how to use AI here.” Run a ten-minute training with real examples from your own work: “here’s a customer email; which tier is it?”
  4. Week 4: collect acknowledgments through the policy tool you already use, and follow up with managers whose teams haven’t completed it.

At the end of the month you’re at level 3.

Level 4: back the policy with controls

Level 4 adds a review schedule and technical controls. Map each policy section to the control that enforces it:

  • The “never” tier is enforced by DLP and sensitivity labels, as described in labels and DLP before AI.
  • Approved tools are enforced by SSO, web filtering of unapproved AI sites, and restricted app consent, covered in identity as your AI control plane.
  • The monitoring notice is backed by audit logging.
  • The building-with-AI section is backed by consent restrictions and an inventory of integrations.

Where a policy line has no control behind it, note it as a gap. That list becomes your next quarter’s work.

Mistakes I see at this stage

Writing it in legalese. If a new employee can’t understand it in five minutes, it won’t be followed.

Publishing without an approved tool. A policy that says “only approved tools” with nothing approved is a ban in disguise.

Publishing without training. Level 2 is common, and it’s fragile. Ten minutes of examples does more than the policy text.

No owner or review date. AI tools change quickly; a policy with no review date goes stale within a year.

Where does your team actually stand?

The acceptable use policy is one of 24 questions in the AI Readiness assessment, which covers six dimensions: data, security, infrastructure, skills, use cases, and governance. The free version is 10 questions and gives you a score in a few minutes.

Get your free AI Readiness Score →

Want to see what the full assessment covers first? Flip through a complete 38-page sample report.

Related guides

Frequently asked questions

What should an AI acceptable use policy include?

Ten short sections: purpose and scope, three data tiers, approved tools and how to request new ones, responsibilities for AI output, prohibited uses, disclosure, a privacy and monitoring notice, rules for building with AI, how violations are handled, and ownership with a review date.

How long should an AI acceptable use policy be?

Two pages at most, written in plain language. If a new employee can't understand it in five minutes, it won't be followed. Keep the approved tools list on a separate page so you can update it without re-approving the policy.

How do we get an AI policy approved quickly?

Replace serial email review with one meeting of legal, HR, security, IT, and the executive sponsor. Send the draft two days ahead, and ask them to approve version 1 for six months with a scheduled review. The scheduled review takes the perfectionism out of the room.

Is publishing the policy enough?

No. Published but untrained scores a 2 on the assessment ladder. Pair the policy with a ten-minute training using real examples from your own work, collect acknowledgments, and over time back each section with a technical control such as DLP, SSO, or restricted app consent.

Scroll to Top