Key takeaways
- Most employees already use generative AI at work, so having no policy usually means unmanaged use rather than no use.
- A data classification table with clear examples is the part of the policy people use most.
- An approved tools list with business accounts reduces the pull toward personal accounts.
- Ownership works best shared between IT or security, legal and an operational business lead.
What an AI acceptable use policy should include
A useful AI usage policy for employees starts with scope: which tools count as AI, including chat assistants, copilots inside existing software, browser extensions and meeting note takers. Then list approved tools and the account type required, such as a company ChatGPT Enterprise, Claude or Microsoft 365 Copilot workspace rather than a personal login. Add a data table: public information is fine, internal information only in approved tools, and customer personal data, credentials or regulated data never, unless a specific system is cleared for it.
The second half covers behaviour. Staff remain responsible for anything they send, publish or decide using AI output, so a person reviews AI-drafted content before it goes to a customer, regulator or the public. Say when AI use must be disclosed, how to report a mistake or data leak, and how to request a new tool. Close with the owner, the review date and a link to training. Plain examples beat legal phrasing every time.
Sample AI policy for employees: a working structure
A generative AI policy for employees can follow a simple structure. Section one: purpose and scope in three sentences. Section two: approved tools and how to get access. Section three: the data table with green, amber and red examples drawn from your own business, such as 'drafting a job ad is green, pasting a customer contract is amber, pasting payroll data is red'. Section four: review and disclosure rules. Section five: prohibited uses, such as automated decisions about people without human review.
Most AI acceptable use policy examples published by companies and industry bodies share this shape, and the differences come from sector rules. A healthcare or financial services firm will add sector-specific data restrictions, while a software company may add rules about code and licences. If you operate in the EU, link the policy to your AI literacy training, since the EU AI Act expects deployers to take measures on staff AI literacy. This page is guidance, not legal advice, so have counsel review the final version.
How to enforce an AI usage policy without blocking work
Enforcement works best when the approved path is the easy path. Give people business accounts for good tools, single sign-on and clear guidance, and most personal-account use fades. Then add technical controls where the risk is real: data loss prevention rules in Microsoft Purview or a secure web gateway that flags sensitive data being pasted into unapproved AI sites, and admin settings that turn off training on your data in the approved tools.
Pair controls with habits. Include a short policy module in onboarding, ask managers to cover it in team meetings, and run a quarterly review of new tools people are requesting. Treat first mistakes as a training moment and repeated or deliberate data exposure as a disciplinary matter, the same as other security policies. Track requests and incidents so the policy changes as tools change, which in this area is every few months.
How it works
- 1
Map current AI use
We survey teams and review network and SaaS logs to see which AI tools are already in use and for what tasks.
- 2
Draft the policy and data table
We write a two to three page policy with a data table built from your own examples, plus a one-page summary for staff.
- 3
Set up approved tools and controls
We configure business accounts, single sign-on, retention and data loss prevention rules so the approved path is also the easiest.
- 4
Train and launch
Short team sessions walk through real scenarios, and the policy goes live with a named owner and a clear route for questions.
- 5
Review with approvals built in
Any AI agent or workflow that sends external messages, makes payments or deletes data is set to wait for a person to approve, and the policy is reviewed quarterly.
Before and after
Typical ranges from comparable deployments. Your baseline is measured before anything is built.
Tools it works with
- ChatGPT Enterprise
- Claude
- Microsoft 365 Copilot
- Google Gemini
- Microsoft Purview
- Netskope
- Okta
- Microsoft Entra ID
- Slack