Skip to main content

How to Write an AI Policy (Template)

Every organization using AI tools needs a clear, enforceable policy that protects the business while empowering teams to work effectively. Whether your staff is experimenting with ChatGPT or deploying AI across entire departments, a well-crafted AI acceptable use policy sets expectations, reduces risk, and creates a foundation for responsible adoption.

This guide walks you through each section of a complete AI policy, provides template language you can adapt, and includes the data classification framework that many organizations overlook until it's too late.

info

This content was developed with AI assistance and is regularly reviewed for accuracy.

What you'll learn:

  • Why an AI policy is essential and what happens without one
  • The eight core sections every AI policy should include
  • Ready-to-adapt template language for each section
  • A data classification framework tailored to AI usage
  • How to implement and maintain your policy over time

Why Every Organization Needs an AI Policy

AI tools are already in your workplace. Successive McKinsey "State of AI" surveys have shown that the vast majority of organizations now use AI in at least one business function, and individual employees are experimenting with AI tools whether or not leadership has sanctioned their use. Without a policy, you're exposed on multiple fronts.

Data leakage is the most immediate risk. Employees who paste customer records, financial data, or proprietary code into public AI tools may be inadvertently sharing sensitive information with third-party providers. Several high-profile incidents, including Samsung's accidental exposure of source code through ChatGPT, have demonstrated how quickly this can happen.

Inconsistent usage creates quality and brand risks. When some teams use AI for customer communications while others prohibit it, you get uneven quality, conflicting messaging, and no way to audit what's been generated versus what's been written by humans.

Compliance violations grow more likely as regulations evolve. The EU AI Act's transparency obligations (Article 50) — requiring clear disclosure when someone is interacting with an AI system or encountering AI-generated content in scope — become applicable on August 2, 2026 (with one narrow exception: the machine-readable marking requirement for synthetic content already on the market before that date was pushed to December 2, 2026). Separately, the Act's high-risk AI system requirements, originally due the same date, have been delayed to December 2, 2027 (standalone systems) and August 2, 2028 (AI embedded in regulated products) under the EU's "Digital Omnibus on AI," which received final sign-off from the Council and Parliament in June 2026. Because these dates have already shifted once, confirm current deadlines with legal counsel before finalizing your policy rather than relying on any single date in this guide. State-level AI transparency laws and industry-specific regulations add further layers of disclosure and documentation requirements that vary by jurisdiction.

Liability exposure rounds out the picture. If an AI-generated contract clause, medical recommendation, or financial analysis causes harm, your organization needs to have demonstrated that it took reasonable steps to govern AI use.

A well-designed policy doesn't slow innovation. Instead, it gives teams clear guardrails that make them more confident about adopting AI tools, because they know exactly what's expected and what's off-limits.

Essential Policy Sections

A complete AI acceptable use policy covers eight areas. Each section addresses a distinct aspect of AI governance, from defining who the policy applies to, through to how the policy itself gets updated over time.

The sections build on each other logically:

  1. Purpose and Scope establishes what the policy covers and why it exists
  2. Approved AI Tools defines which tools employees can use
  3. Acceptable Use draws the lines between encouraged, conditional, and prohibited uses
  4. Data Classification for AI Use provides the framework for deciding what information can be shared with AI tools
  5. Disclosure Requirements sets expectations for transparency
  6. Quality and Accuracy Standards ensures AI output meets organizational standards
  7. Training Requirements makes sure everyone knows how to follow the policy
  8. Review and Update Process keeps the policy current as technology evolves

The template language below is designed to be adapted. Replace bracketed placeholders with your organization's specific details, and adjust the tone to match your existing policy documents.

Template: AI Acceptable Use Policy

Section 1: Purpose and Scope

This section frames the entire policy. It should clearly state why the policy exists, who must follow it, and what it covers.

Template Language

1.1 Purpose

This policy establishes guidelines for the responsible use of artificial intelligence tools and services by [Organization Name] employees, contractors, and authorized third parties. The policy is designed to enable productive use of AI technologies while protecting organizational data, maintaining quality standards, and ensuring compliance with applicable laws and regulations.

1.2 Scope

This policy applies to:

  • All employees, regardless of department or seniority
  • Contractors, consultants, and temporary staff with access to organizational systems or data
  • Third-party partners who process organizational data using AI tools

This policy covers:

  • Generative AI tools (e.g., ChatGPT, Claude, Gemini, Copilot)
  • AI-powered features embedded in existing software (e.g., AI summarization in email clients, AI-assisted code completion)
  • Custom AI models or applications developed by or for [Organization Name]
  • Any tool or service that uses machine learning to generate, analyze, or transform content

1.3 Effective Date and Authority

This policy is effective as of [Date] and is approved by [Approving Authority]. It supersedes any prior guidance on AI tool usage. Violations may result in disciplinary action up to and including termination.

When drafting your scope section, err on the side of inclusion. AI capabilities are increasingly embedded in everyday software, and your policy should cover these ambient AI features alongside standalone tools.

Section 2: Approved AI Tools

Maintaining an approved tools list prevents shadow AI adoption and gives IT and security teams visibility into what's being used across the organization.

Template Language

2.1 Approved Tools

[Organization Name] maintains an approved AI tools list, available at [internal link]. Only tools on this list may be used for organizational work. The current approved tools include:

ToolApproved Use CasesData RestrictionsLicense Type
[Tool 1][e.g., Content drafting, research summarization][e.g., Public and Internal data only][e.g., Enterprise]
[Tool 2][e.g., Code assistance, debugging][e.g., Public data only][e.g., Team]
[Tool 3][e.g., Data analysis, reporting][e.g., Up to Confidential with approval][e.g., Enterprise]

2.2 Requesting Approval for New Tools

Employees who wish to use an AI tool not on the approved list must submit a request to [designated team/individual] using the AI Tool Evaluation Form. Requests will be evaluated based on:

  • Data handling and privacy practices of the tool provider
  • Security certifications and compliance status
  • Integration requirements with existing systems
  • Cost and licensing terms
  • Business justification and expected value

Evaluation will be completed within [timeframe, e.g., 15 business days] of submission.

Review your approved tools list quarterly at minimum. AI tools evolve rapidly, and a tool that was acceptable six months ago may have changed its data retention policies or terms of service.

Section 3: Acceptable Use

This section is the operational heart of the policy. It needs to be specific enough to be actionable but flexible enough to accommodate the variety of ways teams use AI.

Template Language

3.1 Encouraged Uses

The following uses of approved AI tools are encouraged and do not require additional approval:

  • Drafting and editing internal communications, provided the output is reviewed before sending
  • Brainstorming and ideation for projects, campaigns, and strategies
  • Summarizing publicly available research and industry reports
  • Generating first drafts of non-sensitive documents such as meeting agendas, internal presentations, and project plans
  • Learning new concepts or exploring unfamiliar subject areas

3.2 Conditional Uses (Requires Manager Approval)

The following uses require written approval from your direct manager or department head before proceeding:

  • Generating customer-facing content, including marketing materials, support responses, and product documentation
  • Using AI for analysis that will inform business decisions involving budgets above [threshold]
  • Integrating AI tools into automated workflows or business processes
  • Using AI to process Internal-classified data (see Section 4)

3.3 Prohibited Uses

The following uses of AI tools are prohibited under all circumstances:

  • Inputting Confidential or Restricted data into any AI tool without explicit written approval from the Chief Information Security Officer (or equivalent)
  • Using AI to generate legal contracts, regulatory filings, or compliance documents without legal department review
  • Representing AI-generated content as original human work in contexts where disclosure is required
  • Using AI tools to make or inform employment decisions (hiring, termination, performance evaluation) without Human Resources involvement
  • Using AI to conduct surveillance of employees or customers
  • Bypassing security controls to access unauthorized AI tools or services

The distinction between "encouraged," "conditional," and "prohibited" gives employees practical guidance. Rather than reading a long list of rules, they can quickly identify where their intended use falls and act accordingly.

Section 4: Data Classification for AI Use

Data classification is the single most important safeguard in your AI policy. Without it, employees have no framework for deciding what information is safe to share with AI tools.

ClassificationDescriptionAI Usage RulesExamples
PublicInformation intended for public consumption or already publicly availableMay be used freely with any approved AI toolPublished blog posts, press releases, publicly listed product specifications, open-source code
InternalInformation meant for internal use that would not cause significant harm if disclosedMay be used with approved enterprise AI tools that have data processing agreements in place; requires manager approvalInternal memos, meeting notes, project timelines, non-sensitive operational data, internal training materials
ConfidentialSensitive business information whose disclosure could cause material harmRequires CISO approval before any AI processing; must use enterprise tools with contractual data protections; no free-tier or consumer AI toolsCustomer lists, financial forecasts, unreleased product plans, employee compensation data, proprietary methodologies
RestrictedHighly sensitive information subject to legal, regulatory, or contractual protectionsProhibited from use with external AI tools under all circumstances; may only be processed by internally hosted AI systems with appropriate security controlsPersonal health information (PHI), Social Security numbers, payment card data, trade secrets, information under NDA or legal hold

Understanding this framework matters because AI tools process your input data in ways that may not be immediately obvious. Even enterprise AI tools with strong privacy commitments may use input data for model improvement unless you've opted out. Consumer-tier tools typically offer fewer data protections than their enterprise counterparts.

Before entering any data into an AI tool, ask yourself three questions: What classification does this data fall under? Is the tool I'm using approved for that classification level? Have I obtained any required approvals? If you're unsure about a data classification, treat it as Confidential and seek guidance from your manager or the IT security team.

Section 5: Disclosure Requirements

Transparency about AI usage protects your organization's credibility and ensures compliance with emerging regulations. Disclosure expectations vary based on context.

Template Language

5.1 Internal Documents

AI-assisted work products shared internally should include a brief notation such as "Drafted with AI assistance" or "AI-assisted analysis" when the AI contribution is substantial (more than minor editing or formatting). This notation can appear as a footnote, header note, or metadata tag, depending on the document type.

5.2 External Communications

All customer-facing, partner-facing, or publicly distributed content that was substantially generated or informed by AI must include appropriate disclosure. The specific disclosure format should follow industry norms and any applicable regulatory requirements. When in doubt, disclose.

5.3 Regulated Outputs

Content subject to regulatory oversight, including financial reports, legal filings, healthcare documentation, and compliance submissions, must follow all applicable AI disclosure requirements under relevant laws and regulations. The [Legal/Compliance] department maintains current guidance on regulatory disclosure obligations.

5.4 Code and Technical Deliverables

AI-generated or AI-assisted code must be documented in commit messages, code comments, or project documentation. This ensures proper attribution and helps with future maintenance and auditing.

Disclosure norms are still evolving, and your policy should acknowledge this. Build in flexibility by referencing "applicable regulations" rather than citing specific laws that may change. Review disclosure requirements at each policy update cycle to incorporate new regulatory guidance.

Section 6: Quality and Accuracy Standards

AI tools can generate confident-sounding content that is factually incorrect, outdated, or subtly biased. Your policy needs to establish clear expectations for human review and quality assurance.

Template Language

6.1 Human Review Requirement

All AI-generated content must be reviewed by a qualified human before being finalized, shared, or published. The reviewer is responsible for verifying:

  • Factual accuracy of all claims and data points
  • Consistency with organizational messaging, brand voice, and style guides
  • Absence of bias, stereotyping, or inappropriate content
  • Proper handling of any included data or references

6.2 Fact-Checking Standards

AI output that includes statistics, citations, historical claims, or technical specifications must be independently verified against authoritative sources. AI tools may fabricate references, invent statistics, or present outdated information as current. Never assume AI-generated facts are accurate.

6.3 Accountability

The person who submits, publishes, or distributes AI-assisted content bears responsibility for its accuracy and appropriateness, regardless of how it was generated. Using an AI tool does not transfer or reduce individual accountability for work products.

The accountability clause in Section 6.3 is critical. It reinforces that AI is a tool, not a decision-maker, and that individuals remain responsible for the work they produce. This framing helps prevent the "the AI did it" deflection that can erode quality standards over time.

Section 7: Training Requirements

A policy that nobody understands is a policy that nobody follows. Training turns your written guidelines into practiced behavior.

Template Language

7.1 Required Training

All employees must complete the following AI training within [timeframe, e.g., 30 days] of this policy's effective date or their start date, whichever is later:

  • AI Acceptable Use Policy Overview (provided by [HR/IT/Learning & Development])
  • Data Classification for AI Use (provided by [IT Security])
  • Role-specific AI tool training (provided by department managers)

7.2 Ongoing Education

Employees who use AI tools regularly (more than [frequency, e.g., weekly]) must complete at least [number, e.g., 2 hours] of AI-related continuing education annually. This may include vendor-provided training, industry webinars, internal workshops, or approved online courses.

7.3 Documentation

Training completion must be recorded in [Learning Management System or tracking method]. Managers are responsible for ensuring their direct reports meet training requirements. Training completion status will be reviewed during [performance reviews/quarterly check-ins].

Consider making training modular and role-specific. A marketing team member needs different AI guidance than a software engineer or a finance analyst. Generic training covers the policy basics, while role-specific modules address the practical scenarios each team actually encounters.

Section 8: Review and Update Process

AI technology changes faster than most policy review cycles. Build in mechanisms for regular updates and rapid responses to significant developments.

Template Language

8.1 Scheduled Reviews

This policy will be reviewed and updated at least [frequency, e.g., every six months]. The review will be led by [responsible role, e.g., the AI Governance Committee] and will incorporate input from IT Security, Legal, HR, and business unit representatives.

8.2 Triggering Events

In addition to scheduled reviews, this policy will be reviewed promptly when any of the following occur:

  • A significant AI-related security incident affecting the organization
  • New legislation or regulation impacting AI use in our industry or jurisdiction
  • Major changes to the terms of service or data handling practices of approved AI tools
  • Organizational adoption of a new AI tool or platform at scale

8.3 Proposing Changes

Any employee may propose a policy change by submitting a request to [designated contact or channel]. Proposals should include the specific change requested, the rationale, and any supporting information.

8.4 Version Control

All policy versions must be archived with effective dates, change summaries, and approval records. The current version must be readily accessible to all employees at [location].

A six-month review cycle strikes a reasonable balance between staying current and avoiding policy fatigue. If your organization operates in a heavily regulated industry or is adopting AI aggressively, consider quarterly reviews for the first year.

Implementation Checklist

Drafting the policy is only half the work. Successful implementation requires a structured rollout.

  • Draft policy with input from IT, Legal, HR, Security, and business unit stakeholders
  • Conduct legal review to ensure compliance with applicable regulations and employment law
  • Obtain leadership approval and secure executive sponsorship
  • Communicate the policy to all staff through multiple channels (email, town hall, intranet)
  • Develop and deliver training aligned with the policy's requirements
  • Establish the approved tool list and tool evaluation process
  • Set up reporting channels for questions, concerns, and policy change proposals
  • Schedule the first policy review date on the governance calendar

Give your organization time to absorb the policy before enforcing it strictly. A 30- to 60-day grace period with active support, Q&A sessions, and accessible guidance helps teams transition from informal AI use to policy-compliant practices. After the grace period, enforce consistently.

Key Takeaways

  • Every organization using AI needs a policy, regardless of size or industry. Without one, you're exposed to data leakage, compliance violations, and inconsistent quality.
  • Data classification is the linchpin. If employees don't know how to categorize information, they can't make good decisions about what to share with AI tools.
  • Separate use into encouraged, conditional, and prohibited categories to give employees clear, actionable guidance rather than a blanket of restrictions.
  • Accountability stays with the human. AI tools assist, but the person who publishes or submits the work remains responsible for its accuracy and appropriateness.
  • Training transforms policy into practice. Invest in modular, role-specific training that makes the policy real for each team.
  • Build in regular reviews. A policy written today will be outdated within months if not actively maintained. Schedule reviews and make it easy for employees to propose updates.

Next Steps

Ready to deepen your understanding of AI governance and put your policy into a broader strategic context? Continue with these resources: