AI Usage Policy Starter
A plain-language policy that sets out where staff may use AI tools, what data is off limits, and who signs off on higher-risk use.
Most teams adopt AI tools faster than they write down the rules for using them. This starter gives you a short, readable policy you can put in front of staff this week. It covers the questions people actually ask: which tools are allowed, what they can and cannot paste into them, and what to do when they are not sure. Fill in the bracketed parts, cut what does not apply, and have it reviewed before you publish it.
Inside the editable version
- An editable document you can rename and brand as your own
- Bracketed fields for your approved tools, owners, and data rules
- A one-page summary version for staff who will not read the full policy
- A short acknowledgement line you can attach to onboarding
The template
Purpose and scope
This policy explains how [Company] staff and contractors may use artificial intelligence tools in their work. It applies to any tool that generates or analyzes text, code, images, or data using a language model or similar system, whether the tool is paid for by the company or used for free. The goal is simple: let people use these tools to do better work, while keeping client data, regulated data, and the reputation of the company protected. If a situation is not covered here, treat it as needing approval and ask the policy owner.
Approved tools
Staff may use the following tools for the listed purposes: [list each approved tool and what it is approved for, for example drafting internal documents, summarizing public information, or writing code]. Tools that are not on this list are not approved by default. To request a new tool, contact [policy owner] with the tool name, the vendor, and what you want to use it for. Do not enter company or client data into a tool until it has been approved, because once data is sent to an outside service you cannot always get it back or control where it goes.
Data you must never enter
Do not paste any of the following into an AI tool unless the tool is explicitly approved for that data and a written agreement is in place: client records, personal information about identifiable people, health or financial information, login credentials or secrets, anything covered by a confidentiality agreement, and anything you would not be comfortable seeing outside the company. When in doubt, leave it out and ask first. Removing names and obvious identifiers helps but does not always make data safe to share, so check with [policy owner] before assuming redaction is enough.
Review before you rely on output
AI tools can produce confident answers that are wrong, out of date, or made up. You are responsible for anything you send to a client or put into a deliverable, no matter what tool helped you write it. Check facts, figures, citations, and names against a trusted source before you rely on them. For anything that goes to a client, a regulator, or the public, a person other than the tool must read and approve it first.
Higher-risk use needs sign-off
Some uses carry more risk and require approval from [approver] before you proceed: using AI to make or recommend a decision that affects a person (such as hiring, credit, eligibility, or care), connecting a tool to live company systems or customer data, letting a tool take actions on its own rather than only producing drafts, and any use in a regulated workflow. For these, write down what the tool will do, what data it will touch, and who will review the result. See the companion approval gate matrix for which actions need which level of review.
Disclosure and record keeping
Tell clients when AI played a meaningful role in work delivered to them, in line with [Company] client agreements and any rules your industry sets. Keep a simple record of which tools are approved, who approved them, and when, so the policy stays current and you can answer questions about how a piece of work was produced. Review this policy at least once a year, or sooner when a major new tool or rule appears.
If something goes wrong
If you think regulated or confidential data went into a tool it should not have, or a tool produced output that caused a problem, report it to [policy owner] the same day. Early reporting limits the damage and is treated as the right thing to do, not as a reason for blame. The policy owner will decide what notification, if any, is required.
This is a starting template, not a finished policy. Adapt it to how your business actually works, and have it reviewed by the right people before you rely on it.
Want this built into how your AI actually runs?
A template is a starting point. A short working session turns it into a plan: where AI creates leverage for you, and what guardrails to put in place first.