Artificial Intelligence Acceptable Use Policy
- Document ID
- PDC-AIU-SAMPLE
- Document version
- 1.0
- Template version
- v1.0.0
- Effective date
- September 27, 2026
- Next review
- March 27, 2027
1. Purpose
This policy sets the rules every [Company Name] employee must follow when using artificial intelligence (AI) tools for work. AI tools such as chatbots, writing assistants and code assistants can save time. They can also leak company or customer information, make up facts, and be used by criminals to trick you.
The goal is simple: use approved AI tools to do good work faster, keep sensitive information out of the wrong tools, check everything AI produces, and speak up quickly when something goes wrong. Following this policy supports the company in meeting its legal, contract and customer obligations.
If you are not sure whether something is allowed, stop and ask the IT Manager before you act.
2. Scope
Who it covers. This policy applies to all employees of [Company Name], and to temporary workers, interns, contractors and anyone else who uses company systems or handles company or customer information.
What it covers. It covers any AI tool used for company work, on any device, including personal phones and home computers. That includes chatbots, AI features built into other software such as email, documents, design, CRM and accounting programs, browser extensions, meeting note-takers, image, voice and video generators, and AI agents that can take actions for you.
Other policies. This policy works alongside the company's other IT, security, confidentiality and HR policies. When two rules conflict, follow the stricter rule.
Your rights. Nothing in this policy limits your right to discuss wages, hours or other working conditions with coworkers, or to report a possible violation of law to a government agency.
3. Key Terms
- AI tool
- Software that writes text, creates images, audio, video or code, answers questions, summarizes, or takes actions based on what you type or say.
- Generative AI
- AI that produces new content, such as ChatGPT, Microsoft Copilot, Google Gemini or Claude.
- Approved AI tool
- An AI tool the company has reviewed, licensed and listed as approved, used through a company-managed account.
- Personal or free account
- Any AI account the company did not create and does not manage, including free versions and paid plans you bought yourself.
- Prompt
- Anything you type, say, paste or upload into an AI tool, including files, photos and screenshots.
- Output
- Anything an AI tool produces in response to a prompt.
- Confidential information
- Nonpublic information about the company, its customers, suppliers or employees, including anything marked confidential or covered by an agreement.
- Shadow AI
- Using an AI tool for work without company approval.
- Hallucination
- When an AI tool states something false as if it were true, such as made-up facts, numbers, quotes or sources.
- Deepfake
- A fake but realistic image, video or voice recording of a real person, made or changed with AI.
- Prompt injection
- Hidden or planted instructions in a document, email or web page that trick an AI tool into doing something you did not ask for.
- AI agent
- An AI tool that can take actions on its own, such as sending email, changing files or making purchases.
4. Approved AI Tools
You may use only the AI tools listed below for company work, and only while signed in with your company account. Using the same product with a personal login is not approved.
- Microsoft 365 Copilot and Copilot Chat
- Other AI tools the company licenses and lists as approved
The current list. The IT Manager keeps the current list of approved AI tools, including which features are turned on, and will share it on request. A tool that is not on the list is not approved, even if a coworker, customer or vendor uses it.
Personal and free accounts. You must not use personal, free or self-paid AI accounts for company work of any kind. The company cannot control what those accounts keep, who can see it, or how it is used, and it cannot get that information back when you leave.
Browser extensions, plug-ins and apps. You must not install AI browser extensions, plug-ins, desktop apps or phone apps on any device used for company work, or connect an AI tool to company email, files or calendars, unless the IT Manager has approved it in writing. Some of these can read every web page and email you open.
AI help with code and scripts. You may use approved AI tools to help write or fix code, scripts, formulas and macros. You must review and test everything before it runs on company systems or goes to a customer, never paste passwords, keys or connection strings into a prompt, and follow the company's normal review and change process. You are responsible for any code you submit, whether you or an AI wrote it.
Training. You must complete the company's AI training before you use any AI tool for company work, and repeat it every year.
5. Getting a New Tool Approved
To request a new AI tool, or a new AI feature in a tool you already use, contact the IT Manager before you use it with any company information. Free tools and free trials need approval too. Include:
- The name of the tool and its web address
- What you want to use it for, and what information it would see
- Who else would use it
- Whether it costs money or needs to connect to email, files or other company systems
The company checks how the vendor stores, uses and protects data, whether it uses your data to train its AI, who at the vendor can see it, whether it supports company sign-in and multi-factor authentication, and what the contract says. Approval may be limited to certain people, uses or types of information.
A tool is approved only when you receive approval in writing. Until then, do not use it for company work.
6. What You May Use AI For
Using an approved tool, and following the data rules in this policy, you may use AI to:
- Draft emails, letters, reports, proposals and job aids, then edit them yourself
- Summarize long documents, meeting notes or your own notes
- Brainstorm ideas, outlines, headlines and questions to ask
- Rewrite text to be clearer, shorter, friendlier or easier to read
- Translate text, and have a fluent speaker check anything important before it is sent
- Build spreadsheet formulas and learn how software features work
- Research general topics, then confirm the facts with a trusted source
- Get help writing or fixing code and scripts, following the code rules in this policy
Everyday examples. Here are a few ways AI can help in our kind of work:
- Draft answers to common customer questions using public information
- Turn meeting notes into a list of action items
- Rewrite a procedure so it is easier to follow
You own the result. Anything you send, publish or act on is your work, whether or not AI helped create it.
7. What You Must Never Do
You must never:
- Use an AI tool that is not approved for company work, or use an approved tool through a personal or free account
- Enter information into an AI tool that this policy says must stay out of it
- Use AI to harass, threaten, bully, discriminate against or demean anyone, or to create sexual, violent or hateful content
- Use AI to pretend to be someone else, or to create fake messages, images, video or voice meant to deceive anyone
- Create realistic AI images, video or voice of a real person, including coworkers and customers, without that person's written consent and your manager's approval
- Use AI to make or drive decisions about people, such as hiring, firing, pay, promotion, discipline or credit, unless that use is approved in writing and a person makes and documents the final decision
- Use AI to get around security controls, break into systems, write malicious code, crack passwords, or bypass a tool's safety settings
- Let an AI agent send messages, change records, delete files, make purchases or take any other action for the company unless that specific use is approved in writing
- Present AI output as a checked fact, a professional opinion or a signed certification without checking it yourself
- Use AI to copy other people's work, logos or trademarks, or upload material the company does not have the right to share
- Turn on public share links or features that publish your chats unless they are approved
- Use AI for anything illegal or anything that breaks a customer or supplier contract
8. Protecting Company and Customer Data
Before you type, paste or upload anything, ask three questions: Is this tool approved? Is this information allowed in it? Am I sharing only what the task needs?
| Type of information | Approved company AI tools | Personal or free AI accounts |
|---|---|---|
| Public information, such as the company website or published specifications | Allowed | Not allowed |
| Internal business information, such as drafts, procedures and plans | Allowed, share only what the task needs | Not allowed |
| Customer company names and business details | Allowed, share only what the task needs | Not allowed |
| Personal information, such as names and contact details of individuals | Only the minimum the task needs | Not allowed |
| Employee records, such as pay, performance, discipline, medical or background check information | Not allowed | Not allowed |
| Legal matters, such as lawsuits, claims, investigations and advice from lawyers | Not allowed | Not allowed |
| Security details, such as network diagrams, system settings, security reports and vulnerability findings | Not allowed | Not allowed |
| Bulk data exports, such as full customer lists and database or ERP exports | Not allowed | Not allowed |
| Passwords, access codes, keys and full ID or account numbers | Not allowed | Not allowed |
Never, in any AI tool. Passwords, PINs, one-time codes, access keys and full Social Security, driver's license, passport, bank account or card numbers must never go into any AI tool, including approved ones. Neither may anything marked "Not allowed" for approved tools in the table above.
Share the minimum. Remove names, numbers and details the task does not need. Use placeholders such as Customer A or Employee 1 where you can.
Customer information. You may use customer names and business details in approved tools when the task needs them. Some customer contracts forbid sharing their information with AI tools or outside services. If you know or suspect a contract limits this, ask first.
Personal information. Personal information about employees, customers or anyone else may go into an approved AI tool only when the task truly needs it, and only the minimum needed. It must never go into a personal or free AI account.
Files, photos and screenshots. Uploading a file, photo, screenshot or recording counts as entering everything in it. Check for hidden sheets, comments, tracked changes and background details before you upload.
9. Checking AI Output
AI tools often sound confident when they are wrong. You are responsible for anything you use, send or publish, whether or not AI helped create it.
When review is required. Before AI output is sent outside the company, published, used to make a decision or relied on as fact, a person who understands the subject must review it. Check routine internal drafts yourself before you share them.
What to check. Make sure that:
- Facts, names, dates, quotes and sources are real and correct. Open every link and source the AI gives you.
- Numbers, math, measurements, part numbers, prices and units are right.
- It answers the actual request, leaves out nothing important, and does not conflict with company policy, contracts or safety rules.
- It is fair and does not stereotype or treat people differently because of race, sex, age, disability, religion, national origin or any other protected trait.
- It does not copy someone else's work word for word, and images do not include other companies' logos, characters or trademarks.
- It does not include confidential information the reader should not see.
High-stakes work. Never rely on AI output alone for safety procedures, engineering calculations, legal, tax, medical or financial advice, or government filings. A qualified person must verify it.
Labeling AI content. You must always label AI-generated or AI-altered images, video and audio that look or sound real. You must also disclose AI use when a customer, contract or law requires it, and answer honestly if anyone asks whether AI was used. Routine writing that you reviewed and edited yourself does not need a label.
Ownership. Content created mostly by AI may not be protected by copyright. Check with the IT Manager before using AI to create logos, product designs or anything else the company needs to own.
10. Meetings, Recordings and Note-Taking Bots
You may use only the note-taking, recording, transcription and summary features of approved AI tools, and only when:
- You tell everyone at the start of the meeting that AI note-taking or recording is on, and say so in the invitation when you can
- Everyone agrees. If anyone objects, turn it off.
- The meeting is not about legal advice, HR or discipline, health information, or anything the host has called confidential
Consent. Some states require everyone on a call to agree before it is recorded, which is why this rule applies to every meeting, including calls with people in other states.
Summaries and recordings. Check AI summaries and action items for accuracy before you share them. Keep recordings and transcripts only in approved company locations, and delete them when company record rules say to.
Outside note-takers. Do not admit unknown bots or attendees to company meetings. If an outside party's AI note-taker joins, the host may ask for it to be removed, and must remove it from confidential meetings. Do not sign up for note-taker services with your work email or give them access to your calendar without approval, because some join every meeting on your calendar automatically.
Personal devices. Do not use personal phone apps to record or transcribe work conversations.
11. Security Rules
Criminals use AI to write convincing phishing emails, build fake websites, and clone voices and faces. Treat urgency combined with an unusual request as a warning sign, no matter how real it looks or sounds.
- Before you change bank or payment details, send money, buy gift cards, or send sensitive files because someone asked, confirm the request by calling that person at a phone number from company records, not one given in the message. Do this even when the request comes by phone or video from someone you know.
- Do not treat a familiar voice or face on a call as proof of who someone is. Hang up and call back using a known number.
- Never share your password or one-time codes with anyone, including someone who says they are from IT, and never approve a sign-in or multi-factor prompt you did not start.
- Treat instructions inside documents, emails or web pages you give to an AI tool as untrusted. If an AI tool starts doing something you did not ask, such as sending, deleting or asking for passwords, stop and report it.
- Do not connect AI tools to company email, files or systems, or give them your login, unless that connection is approved.
- Download AI apps only from sources the company approves. Fake AI apps and look-alike websites are used to spread malware.
- Sign in to approved AI tools only with your company account and multi-factor authentication.
- Never turn off or get around security tools to make an AI tool work.
12. Reporting Mistakes and Incidents
Report right away, and no later than 24 hours after you notice, if:
- You entered information into an AI tool that this policy says must stay out of it, or used the wrong tool or account
- AI output with a serious error was sent to a customer, published or used in a decision
- You get a suspicious request that may use a cloned voice, fake video or AI-written phishing
- An AI tool behaves strangely, such as following hidden instructions, showing someone else's information or taking actions you did not request
- You see AI being used in a way that breaks this policy
How to report. Contact the IT Manager. Say what happened, which tool and account were involved, what information was shared, and when. Do not delete the chat, file or message unless you are told to, because the company may need it to limit the damage.
No blame for early reports. The company wants to hear about mistakes early, when they are easiest to fix. You will never be disciplined for reporting a mistake in good faith, and a prompt, honest report counts strongly in your favor when the company decides how to respond to the mistake itself. Hiding a mistake, or delaying a report on purpose, is a violation of this policy.
No retaliation. The company does not allow retaliation against anyone who reports a concern in good faith.
13. Consequences of Violations
Breaking this policy may lead to discipline, up to and including termination of employment or of a contract, consistent with company policy and applicable law. The company may also remove access to AI tools, and may report illegal activity to the authorities.
Monitoring. Company AI tools, accounts and devices belong to the company. As the law allows, the company may monitor, log and review how they are used, including prompts, uploaded files and outputs, so do not expect privacy in anything you enter into a company AI tool. This policy is your notice of that monitoring.
Keeping this policy current. The IT Manager is responsible for this policy and will review it by March 27, 2027, or sooner when AI tools, laws or risks change. The company will tell you when the rules change.
14. Employee Acknowledgment
I have received and read the [Company Name] Artificial Intelligence Acceptable Use Policy, effective September 27, 2026. I understand it, I have had the chance to ask questions, and I agree to follow it. I understand that breaking it may lead to discipline, up to and including termination, and that the company may monitor my use of company AI tools as the policy describes. I understand that the company may update this policy, and that this acknowledgment is not a contract of employment.
Employee name (printed)
Employee signature
Date
15. Document Control and Revision History
| Field | Value |
|---|---|
| Document | Artificial Intelligence Acceptable Use Policy |
| Organization | [Company Name] |
| Document ID | PDC-AIU-SAMPLE |
| Document version | 1.0 |
| Effective date | September 27, 2026 |
| Next scheduled review | March 27, 2027 |
| Policy owner | IT Manager |
| Approved by | Chief Executive Officer |
| Source template | Preferred Data Corporation AI Acceptable Use Policy template v1.0.0 |
Revision history. Record every change to this policy below. Increase the document version and obtain approval again each time the policy is revised.
| Version | Date | Description of change | Approved by |
|---|---|---|---|
| 1.0 | September 27, 2026 | Initial adoption, generated from template v1.0.0. | Chief Executive Officer |
| Blank | Blank | Blank | Blank |
| Blank | Blank | Blank | Blank |
16. Template Notice and Legal Disclaimer
This document was generated from a starter template provided by Preferred Data Corporation. It is general information only. It is not legal advice and it is not a substitute for advice from a licensed attorney.
Preferred Data Corporation is not a law firm. It makes no representation that this document is complete, current, or suitable for any particular organization, industry, jurisdiction, or regulatory requirement, and it is not responsible or liable for any use of this template or of any policy created from it. You are solely responsible for how you adapt, adopt, and enforce it.
Laws, regulations, insurance requirements, and contracts that apply to your organization may require different or additional terms. Before you adopt, publish, or rely on this policy, and in every case where you have a legal, regulatory, or contractual obligation, have it reviewed by qualified legal counsel.