Skip to content
Velum

Enterprise AI rollout

AI acceptable use policy: a template your team will follow

Short answer

An AI acceptable use policy template should cover five things: which AI tools are approved, what data may and may not be entered, when a person must review AI output, how AI use is disclosed, and who to ask when something is unclear. Keep it to two or three pages with concrete examples. A short policy that staff actually read does more than a long one that sits on the intranet.

Key takeaways

  • Most employees already use generative AI at work, so having no policy usually means unmanaged use rather than no use.
  • A data classification table with clear examples is the part of the policy people use most.
  • An approved tools list with business accounts reduces the pull toward personal accounts.
  • Ownership works best shared between IT or security, legal and an operational business lead.

What an AI acceptable use policy should include

A useful AI usage policy for employees starts with scope: which tools count as AI, including chat assistants, copilots inside existing software, browser extensions and meeting note takers. Then list approved tools and the account type required, such as a company ChatGPT Enterprise, Claude or Microsoft 365 Copilot workspace rather than a personal login. Add a data table: public information is fine, internal information only in approved tools, and customer personal data, credentials or regulated data never, unless a specific system is cleared for it.

The second half covers behaviour. Staff remain responsible for anything they send, publish or decide using AI output, so a person reviews AI-drafted content before it goes to a customer, regulator or the public. Say when AI use must be disclosed, how to report a mistake or data leak, and how to request a new tool. Close with the owner, the review date and a link to training. Plain examples beat legal phrasing every time.

Sample AI policy for employees: a working structure

A generative AI policy for employees can follow a simple structure. Section one: purpose and scope in three sentences. Section two: approved tools and how to get access. Section three: the data table with green, amber and red examples drawn from your own business, such as 'drafting a job ad is green, pasting a customer contract is amber, pasting payroll data is red'. Section four: review and disclosure rules. Section five: prohibited uses, such as automated decisions about people without human review.

Most AI acceptable use policy examples published by companies and industry bodies share this shape, and the differences come from sector rules. A healthcare or financial services firm will add sector-specific data restrictions, while a software company may add rules about code and licences. If you operate in the EU, link the policy to your AI literacy training, since the EU AI Act expects deployers to take measures on staff AI literacy. This page is guidance, not legal advice, so have counsel review the final version.

How to enforce an AI usage policy without blocking work

Enforcement works best when the approved path is the easy path. Give people business accounts for good tools, single sign-on and clear guidance, and most personal-account use fades. Then add technical controls where the risk is real: data loss prevention rules in Microsoft Purview or a secure web gateway that flags sensitive data being pasted into unapproved AI sites, and admin settings that turn off training on your data in the approved tools.

Pair controls with habits. Include a short policy module in onboarding, ask managers to cover it in team meetings, and run a quarterly review of new tools people are requesting. Treat first mistakes as a training moment and repeated or deliberate data exposure as a disciplinary matter, the same as other security policies. Track requests and incidents so the policy changes as tools change, which in this area is every few months.

How it works

  1. 1

    Map current AI use

    We survey teams and review network and SaaS logs to see which AI tools are already in use and for what tasks.

  2. 2

    Draft the policy and data table

    We write a two to three page policy with a data table built from your own examples, plus a one-page summary for staff.

  3. 3

    Set up approved tools and controls

    We configure business accounts, single sign-on, retention and data loss prevention rules so the approved path is also the easiest.

  4. 4

    Train and launch

    Short team sessions walk through real scenarios, and the policy goes live with a named owner and a clear route for questions.

  5. 5

    Review with approvals built in

    Any AI agent or workflow that sends external messages, makes payments or deletes data is set to wait for a person to approve, and the policy is reviewed quarterly.

Before and after

TaskBy handWith agents
AI tools in use10 to 30 unsanctioned tools and extensions2 to 5 approved tools with business accounts
Answer to 'can I use this?'Days, or nobody asksMinutes, from the approved list and data table
Sensitive data in public AI toolsUnknown and unmonitoredFlagged by data loss prevention rules
Policy review cycleWritten once, rarely updatedReviewed quarterly against tool requests

Typical ranges from comparable deployments. Your baseline is measured before anything is built.

Tools it works with

  • ChatGPT Enterprise
  • Claude
  • Microsoft 365 Copilot
  • Google Gemini
  • Microsoft Purview
  • Netskope
  • Okta
  • Microsoft Entra ID
  • Slack

Questions people ask

01

What should an AI acceptable use policy include?

It should list approved AI tools, define what data can and cannot be entered, require a person to review AI output before it goes external, set disclosure rules and name an owner. Concrete examples from your own work make it usable. Keep it short enough to read in ten minutes.

02

Do companies need an AI policy?

Yes, in practice almost every company does, because staff are already using AI tools whether or not there is a policy. Without one, sensitive data ends up in personal accounts and nobody knows who is responsible for AI-assisted work. Even a one-page policy with an approved tools list reduces that risk quickly.

03

Can employees use ChatGPT at work?

They can if the company allows it, ideally through a business plan such as ChatGPT Enterprise or Team where data is not used for training by default and admins control access. Many companies allow approved AI tools for drafting and research while banning customer personal data or confidential information in them. The policy should say which account types are allowed.

04

How do you enforce an AI usage policy?

Make approved tools easy to access, then add technical controls such as single sign-on, data loss prevention rules and admin settings in the approved tools. Cover the policy in onboarding and team meetings. Handle breaches the same way as other security policy breaches, with training first and escalation for repeated or deliberate cases.

05

Who should own the AI policy in a company?

Ownership usually sits with IT or security, with legal and compliance as co-authors and a business lead who keeps it practical. In smaller companies the COO or head of operations often owns it. What matters most is one named person who approves new tools and keeps the policy current.

Start with one workflow.

Thirty minutes. One real process. A practical next step.