Free artificial intelligence policy template

Free AI Acceptable Use Policy Template for Employees

An AI acceptable use policy is a short set of rules that tells employees which AI tools they may use for work, what information they must never enter, and how to check AI output before relying on it. Each employee reads and signs it, which gives the company one clear standard to train on and enforce and reduces the risk of shadow AI exposing company or customer data.

An AI acceptable use policy is a signed, employee-facing document that sets which artificial intelligence tools staff may use for work, what information they may enter, and how they must review, disclose and report their use of AI.

Template version
v1.0.0
Last reviewed
September 27, 2026
Sections
16
Guided phases
5
Time to complete
About 5 minutes
Price
Free

Why does this policy matter now?

What is inside the AI Acceptable Use Policy template?

16 sections, ending with the document control table and the legal notice every template carries. Select any section to jump to it in the sample below.

  1. 1. PurposeWhy the company has AI rules and what they protect.
  2. 2. ScopeWho and which AI tools the policy covers.
  3. 3. Key TermsPlain-language definitions of the AI terms used in the policy.
  4. 4. Approved AI ToolsThe approved tools, the personal-account rule, extensions and code.
  5. 5. Getting a New Tool ApprovedHow to request a new AI tool or feature before using it.
  6. 6. What You May Use AI ForEveryday tasks employees may use approved AI tools for, with examples.
  7. 7. What You Must Never DoProhibited uses, from shadow AI and deepfakes to decisions about people.
  8. 8. Protecting Company and Customer DataWhich information may go into which AI tools, with rules for regulated data.
  9. 9. Checking AI OutputHuman review, hallucinations, bias, copyright and labeling AI content.
  10. 10. Meetings, Recordings and Note-Taking BotsWhen AI note-takers and recording are allowed, and outside bots.
  11. 11. Security RulesPrompt injection, AI-written phishing, cloned voices and payment changes.
  12. 12. Reporting Mistakes and IncidentsWhat to report, how fast, and the no-blame promise for early reports.
  13. 13. Consequences of ViolationsDiscipline, monitoring notice and how the policy is kept current.
  14. 14. Employee AcknowledgmentThe statement each employee signs and dates.
  15. 15. Document Control and Revision HistoryDocument ID, version, effective date, next review, owner and approver, plus a revision history table.
  16. 16. Template Notice and Legal DisclaimerThe starter-template disclaimer and the reminder to have qualified counsel review the policy.
Template changelog
  • v1.0.0, September 27, 2026

    • Initial release: approved tools, data rules, output review, meeting bots, AI-enabled fraud, incident reporting and employee acknowledgment.

Read the full sample AI Acceptable Use Policy

This sample uses the recommended answer to every question and a placeholder company name. Build your own version to put in your organization's name, owners and choices.

Sections in this policy
Sample[Company Name]

Artificial Intelligence Acceptable Use Policy

Document ID
PDC-AIU-SAMPLE
Document version
1.0
Template version
v1.0.0
Effective date
September 27, 2026
Next review
March 27, 2027

1. Purpose

This policy sets the rules every [Company Name] employee must follow when using artificial intelligence (AI) tools for work. AI tools such as chatbots, writing assistants and code assistants can save time. They can also leak company or customer information, make up facts, and be used by criminals to trick you.

The goal is simple: use approved AI tools to do good work faster, keep sensitive information out of the wrong tools, check everything AI produces, and speak up quickly when something goes wrong. Following this policy supports the company in meeting its legal, contract and customer obligations.

If you are not sure whether something is allowed, stop and ask the IT Manager before you act.

2. Scope

Who it covers. This policy applies to all employees of [Company Name], and to temporary workers, interns, contractors and anyone else who uses company systems or handles company or customer information.

What it covers. It covers any AI tool used for company work, on any device, including personal phones and home computers. That includes chatbots, AI features built into other software such as email, documents, design, CRM and accounting programs, browser extensions, meeting note-takers, image, voice and video generators, and AI agents that can take actions for you.

Other policies. This policy works alongside the company's other IT, security, confidentiality and HR policies. When two rules conflict, follow the stricter rule.

Your rights. Nothing in this policy limits your right to discuss wages, hours or other working conditions with coworkers, or to report a possible violation of law to a government agency.

3. Key Terms

AI tool
Software that writes text, creates images, audio, video or code, answers questions, summarizes, or takes actions based on what you type or say.
Generative AI
AI that produces new content, such as ChatGPT, Microsoft Copilot, Google Gemini or Claude.
Approved AI tool
An AI tool the company has reviewed, licensed and listed as approved, used through a company-managed account.
Personal or free account
Any AI account the company did not create and does not manage, including free versions and paid plans you bought yourself.
Prompt
Anything you type, say, paste or upload into an AI tool, including files, photos and screenshots.
Output
Anything an AI tool produces in response to a prompt.
Confidential information
Nonpublic information about the company, its customers, suppliers or employees, including anything marked confidential or covered by an agreement.
Shadow AI
Using an AI tool for work without company approval.
Hallucination
When an AI tool states something false as if it were true, such as made-up facts, numbers, quotes or sources.
Deepfake
A fake but realistic image, video or voice recording of a real person, made or changed with AI.
Prompt injection
Hidden or planted instructions in a document, email or web page that trick an AI tool into doing something you did not ask for.
AI agent
An AI tool that can take actions on its own, such as sending email, changing files or making purchases.

4. Approved AI Tools

You may use only the AI tools listed below for company work, and only while signed in with your company account. Using the same product with a personal login is not approved.

  • Microsoft 365 Copilot and Copilot Chat
  • Other AI tools the company licenses and lists as approved

The current list. The IT Manager keeps the current list of approved AI tools, including which features are turned on, and will share it on request. A tool that is not on the list is not approved, even if a coworker, customer or vendor uses it.

Personal and free accounts. You must not use personal, free or self-paid AI accounts for company work of any kind. The company cannot control what those accounts keep, who can see it, or how it is used, and it cannot get that information back when you leave.

Browser extensions, plug-ins and apps. You must not install AI browser extensions, plug-ins, desktop apps or phone apps on any device used for company work, or connect an AI tool to company email, files or calendars, unless the IT Manager has approved it in writing. Some of these can read every web page and email you open.

AI help with code and scripts. You may use approved AI tools to help write or fix code, scripts, formulas and macros. You must review and test everything before it runs on company systems or goes to a customer, never paste passwords, keys or connection strings into a prompt, and follow the company's normal review and change process. You are responsible for any code you submit, whether you or an AI wrote it.

Training. You must complete the company's AI training before you use any AI tool for company work, and repeat it every year.

5. Getting a New Tool Approved

To request a new AI tool, or a new AI feature in a tool you already use, contact the IT Manager before you use it with any company information. Free tools and free trials need approval too. Include:

  • The name of the tool and its web address
  • What you want to use it for, and what information it would see
  • Who else would use it
  • Whether it costs money or needs to connect to email, files or other company systems

The company checks how the vendor stores, uses and protects data, whether it uses your data to train its AI, who at the vendor can see it, whether it supports company sign-in and multi-factor authentication, and what the contract says. Approval may be limited to certain people, uses or types of information.

A tool is approved only when you receive approval in writing. Until then, do not use it for company work.

6. What You May Use AI For

Using an approved tool, and following the data rules in this policy, you may use AI to:

  • Draft emails, letters, reports, proposals and job aids, then edit them yourself
  • Summarize long documents, meeting notes or your own notes
  • Brainstorm ideas, outlines, headlines and questions to ask
  • Rewrite text to be clearer, shorter, friendlier or easier to read
  • Translate text, and have a fluent speaker check anything important before it is sent
  • Build spreadsheet formulas and learn how software features work
  • Research general topics, then confirm the facts with a trusted source
  • Get help writing or fixing code and scripts, following the code rules in this policy

Everyday examples. Here are a few ways AI can help in our kind of work:

  • Draft answers to common customer questions using public information
  • Turn meeting notes into a list of action items
  • Rewrite a procedure so it is easier to follow

You own the result. Anything you send, publish or act on is your work, whether or not AI helped create it.

7. What You Must Never Do

You must never:

  • Use an AI tool that is not approved for company work, or use an approved tool through a personal or free account
  • Enter information into an AI tool that this policy says must stay out of it
  • Use AI to harass, threaten, bully, discriminate against or demean anyone, or to create sexual, violent or hateful content
  • Use AI to pretend to be someone else, or to create fake messages, images, video or voice meant to deceive anyone
  • Create realistic AI images, video or voice of a real person, including coworkers and customers, without that person's written consent and your manager's approval
  • Use AI to make or drive decisions about people, such as hiring, firing, pay, promotion, discipline or credit, unless that use is approved in writing and a person makes and documents the final decision
  • Use AI to get around security controls, break into systems, write malicious code, crack passwords, or bypass a tool's safety settings
  • Let an AI agent send messages, change records, delete files, make purchases or take any other action for the company unless that specific use is approved in writing
  • Present AI output as a checked fact, a professional opinion or a signed certification without checking it yourself
  • Use AI to copy other people's work, logos or trademarks, or upload material the company does not have the right to share
  • Turn on public share links or features that publish your chats unless they are approved
  • Use AI for anything illegal or anything that breaks a customer or supplier contract

8. Protecting Company and Customer Data

Before you type, paste or upload anything, ask three questions: Is this tool approved? Is this information allowed in it? Am I sharing only what the task needs?

Type of informationApproved company AI toolsPersonal or free AI accounts
Public information, such as the company website or published specificationsAllowedNot allowed
Internal business information, such as drafts, procedures and plansAllowed, share only what the task needsNot allowed
Customer company names and business detailsAllowed, share only what the task needsNot allowed
Personal information, such as names and contact details of individualsOnly the minimum the task needsNot allowed
Employee records, such as pay, performance, discipline, medical or background check informationNot allowedNot allowed
Legal matters, such as lawsuits, claims, investigations and advice from lawyersNot allowedNot allowed
Security details, such as network diagrams, system settings, security reports and vulnerability findingsNot allowedNot allowed
Bulk data exports, such as full customer lists and database or ERP exportsNot allowedNot allowed
Passwords, access codes, keys and full ID or account numbersNot allowedNot allowed

Never, in any AI tool. Passwords, PINs, one-time codes, access keys and full Social Security, driver's license, passport, bank account or card numbers must never go into any AI tool, including approved ones. Neither may anything marked "Not allowed" for approved tools in the table above.

Share the minimum. Remove names, numbers and details the task does not need. Use placeholders such as Customer A or Employee 1 where you can.

Customer information. You may use customer names and business details in approved tools when the task needs them. Some customer contracts forbid sharing their information with AI tools or outside services. If you know or suspect a contract limits this, ask first.

Personal information. Personal information about employees, customers or anyone else may go into an approved AI tool only when the task truly needs it, and only the minimum needed. It must never go into a personal or free AI account.

Files, photos and screenshots. Uploading a file, photo, screenshot or recording counts as entering everything in it. Check for hidden sheets, comments, tracked changes and background details before you upload.

9. Checking AI Output

AI tools often sound confident when they are wrong. You are responsible for anything you use, send or publish, whether or not AI helped create it.

When review is required. Before AI output is sent outside the company, published, used to make a decision or relied on as fact, a person who understands the subject must review it. Check routine internal drafts yourself before you share them.

What to check. Make sure that:

  • Facts, names, dates, quotes and sources are real and correct. Open every link and source the AI gives you.
  • Numbers, math, measurements, part numbers, prices and units are right.
  • It answers the actual request, leaves out nothing important, and does not conflict with company policy, contracts or safety rules.
  • It is fair and does not stereotype or treat people differently because of race, sex, age, disability, religion, national origin or any other protected trait.
  • It does not copy someone else's work word for word, and images do not include other companies' logos, characters or trademarks.
  • It does not include confidential information the reader should not see.

High-stakes work. Never rely on AI output alone for safety procedures, engineering calculations, legal, tax, medical or financial advice, or government filings. A qualified person must verify it.

Labeling AI content. You must always label AI-generated or AI-altered images, video and audio that look or sound real. You must also disclose AI use when a customer, contract or law requires it, and answer honestly if anyone asks whether AI was used. Routine writing that you reviewed and edited yourself does not need a label.

Ownership. Content created mostly by AI may not be protected by copyright. Check with the IT Manager before using AI to create logos, product designs or anything else the company needs to own.

10. Meetings, Recordings and Note-Taking Bots

You may use only the note-taking, recording, transcription and summary features of approved AI tools, and only when:

  • You tell everyone at the start of the meeting that AI note-taking or recording is on, and say so in the invitation when you can
  • Everyone agrees. If anyone objects, turn it off.
  • The meeting is not about legal advice, HR or discipline, health information, or anything the host has called confidential

Consent. Some states require everyone on a call to agree before it is recorded, which is why this rule applies to every meeting, including calls with people in other states.

Summaries and recordings. Check AI summaries and action items for accuracy before you share them. Keep recordings and transcripts only in approved company locations, and delete them when company record rules say to.

Outside note-takers. Do not admit unknown bots or attendees to company meetings. If an outside party's AI note-taker joins, the host may ask for it to be removed, and must remove it from confidential meetings. Do not sign up for note-taker services with your work email or give them access to your calendar without approval, because some join every meeting on your calendar automatically.

Personal devices. Do not use personal phone apps to record or transcribe work conversations.

11. Security Rules

Criminals use AI to write convincing phishing emails, build fake websites, and clone voices and faces. Treat urgency combined with an unusual request as a warning sign, no matter how real it looks or sounds.

  • Before you change bank or payment details, send money, buy gift cards, or send sensitive files because someone asked, confirm the request by calling that person at a phone number from company records, not one given in the message. Do this even when the request comes by phone or video from someone you know.
  • Do not treat a familiar voice or face on a call as proof of who someone is. Hang up and call back using a known number.
  • Never share your password or one-time codes with anyone, including someone who says they are from IT, and never approve a sign-in or multi-factor prompt you did not start.
  • Treat instructions inside documents, emails or web pages you give to an AI tool as untrusted. If an AI tool starts doing something you did not ask, such as sending, deleting or asking for passwords, stop and report it.
  • Do not connect AI tools to company email, files or systems, or give them your login, unless that connection is approved.
  • Download AI apps only from sources the company approves. Fake AI apps and look-alike websites are used to spread malware.
  • Sign in to approved AI tools only with your company account and multi-factor authentication.
  • Never turn off or get around security tools to make an AI tool work.

12. Reporting Mistakes and Incidents

Report right away, and no later than 24 hours after you notice, if:

  • You entered information into an AI tool that this policy says must stay out of it, or used the wrong tool or account
  • AI output with a serious error was sent to a customer, published or used in a decision
  • You get a suspicious request that may use a cloned voice, fake video or AI-written phishing
  • An AI tool behaves strangely, such as following hidden instructions, showing someone else's information or taking actions you did not request
  • You see AI being used in a way that breaks this policy

How to report. Contact the IT Manager. Say what happened, which tool and account were involved, what information was shared, and when. Do not delete the chat, file or message unless you are told to, because the company may need it to limit the damage.

No blame for early reports. The company wants to hear about mistakes early, when they are easiest to fix. You will never be disciplined for reporting a mistake in good faith, and a prompt, honest report counts strongly in your favor when the company decides how to respond to the mistake itself. Hiding a mistake, or delaying a report on purpose, is a violation of this policy.

No retaliation. The company does not allow retaliation against anyone who reports a concern in good faith.

13. Consequences of Violations

Breaking this policy may lead to discipline, up to and including termination of employment or of a contract, consistent with company policy and applicable law. The company may also remove access to AI tools, and may report illegal activity to the authorities.

Monitoring. Company AI tools, accounts and devices belong to the company. As the law allows, the company may monitor, log and review how they are used, including prompts, uploaded files and outputs, so do not expect privacy in anything you enter into a company AI tool. This policy is your notice of that monitoring.

Keeping this policy current. The IT Manager is responsible for this policy and will review it by March 27, 2027, or sooner when AI tools, laws or risks change. The company will tell you when the rules change.

14. Employee Acknowledgment

I have received and read the [Company Name] Artificial Intelligence Acceptable Use Policy, effective September 27, 2026. I understand it, I have had the chance to ask questions, and I agree to follow it. I understand that breaking it may lead to discipline, up to and including termination, and that the company may monitor my use of company AI tools as the policy describes. I understand that the company may update this policy, and that this acknowledgment is not a contract of employment.

Employee name (printed)

Employee signature

Date

15. Document Control and Revision History

FieldValue
DocumentArtificial Intelligence Acceptable Use Policy
Organization[Company Name]
Document IDPDC-AIU-SAMPLE
Document version1.0
Effective dateSeptember 27, 2026
Next scheduled reviewMarch 27, 2027
Policy ownerIT Manager
Approved byChief Executive Officer
Source templatePreferred Data Corporation AI Acceptable Use Policy template v1.0.0

Revision history. Record every change to this policy below. Increase the document version and obtain approval again each time the policy is revised.

VersionDateDescription of changeApproved by
1.0September 27, 2026Initial adoption, generated from template v1.0.0.Chief Executive Officer
BlankBlankBlankBlank
BlankBlankBlankBlank

16. Template Notice and Legal Disclaimer

This document was generated from a starter template provided by Preferred Data Corporation. It is general information only. It is not legal advice and it is not a substitute for advice from a licensed attorney.

Preferred Data Corporation is not a law firm. It makes no representation that this document is complete, current, or suitable for any particular organization, industry, jurisdiction, or regulatory requirement, and it is not responsible or liable for any use of this template or of any policy created from it. You are solely responsible for how you adapt, adopt, and enforce it.

Laws, regulations, insurance requirements, and contracts that apply to your organization may require different or additional terms. Before you adopt, publish, or rely on this policy, and in every case where you have a legal, regulatory, or contractual obligation, have it reviewed by qualified legal counsel.

How does the AI Acceptable Use Policy generator work?

5 short phases, about 5 minutes in total. Every question is pre-filled with a best-practice answer and the reason we recommend it.

  1. Your organization

    The basics that shape who the policy covers and which obligations it has to respect.

  2. Approved AI tools

    Which AI tools employees may use for work, and on what kind of account.

  3. Data rules

    What information may go into AI tools, and what must always stay out.

  4. Output and conduct

    How AI output is checked and labeled, and how quickly problems are reported.

  5. Ownership and review

    Who owns the policy, who approves it, and how it stays current.

  6. Review and download

    Preview your policy, unlock the full document and download it as a PDF with a document ID and review date.

Start the generator

Who should adopt this policy?

  • Small and mid-sized businesses whose staff already use ChatGPT, Copilot or Gemini, with or without permission
  • Manufacturers, contractors and distributors protecting drawings, bids, pricing and customer data
  • Companies rolling out Microsoft 365 Copilot or another business AI tool that need signed employee rules first
  • HR and IT leaders who need a plain-language policy employees will read and sign during onboarding
  • Defense suppliers and regulated businesses that must keep CUI, health or payment data out of AI tools

Which frameworks does this template align with?

The template was written against these public frameworks, laws and standards. Alignment is not certification, and your obligations depend on your industry and location.

Framework or lawWhy it matters for this policy
NIST AI Risk Management Framework (AI RMF 1.0)(opens in a new tab)The voluntary U.S. framework for managing AI risk that this policy turns into everyday employee rules.
NIST AI 600-1, Generative AI Profile(opens in a new tab)Names the generative AI risks the policy addresses, including confabulated output, data privacy and information security.
OWASP Top 10 for Large Language Model Applications (2025)(opens in a new tab)Lists prompt injection and sensitive information disclosure as the top two risks, which shape the security and data rules.
FBI Public Service Announcement: Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud(opens in a new tab)Describes AI voice cloning and fake media used in fraud, and recommends hanging up and calling back a known number.

AI Acceptable Use Policy questions, answered

Can employees use ChatGPT at work?

Yes, when the company has approved it and the employee signs in with a company-managed business account rather than a personal or free one. A personal account is controlled by the employee, so the company cannot set how long data is kept, see what was shared, or recover it when the employee leaves. An AI acceptable use policy lists the approved tools and the information that must never go into any of them.

What should an AI acceptable use policy include?

At minimum: the list of approved AI tools and how to request new ones, a clear rule against personal and free accounts, the types of data that must never be entered, a requirement to review AI output before it is sent or relied on, and prohibited uses such as deepfakes, harassment and decisions about people. It should also cover meeting note-taker bots, AI-enabled phishing and voice cloning, how to report mistakes quickly, consequences, and a signed employee acknowledgment.

Should employees sign an AI acceptable use policy?

Yes. A signed acknowledgment records that each employee received the rules, had a chance to ask questions and agreed to follow them, which supports consistent training and enforcement. Collect a new signature whenever the policy changes significantly, and keep it with other policy acknowledgments.

Can I put customer data into ChatGPT or Copilot?

Never into a personal or free account. In a company-approved business account, share only what the task needs, use placeholders such as Customer A where you can, and check whether the customer contract limits sharing. Regulated data such as payment card numbers, health information without a Business Associate Agreement, and Controlled Unclassified Information outside authorized systems must stay out of AI tools entirely.

What is shadow AI?

Shadow AI is the use of AI tools for work without the company knowing about or approving them, usually through personal or free accounts. IBM reported in its 2025 Cost of a Data Breach research that a high level of shadow AI added USD 670,000 to the global average breach cost. A signed acceptable use policy plus an easy way to request new tools is the most direct way to bring that use into the open.

What is the difference between an AI acceptable use policy and an AI governance policy?

An AI governance policy is written for leadership and sets how the organization approves, oversees, risk-rates and audits AI. An AI acceptable use policy is written for every employee and turns those decisions into short do and do not rules that each person signs. Most organizations need both, with the acceptable use policy kept short enough that people actually read it.

Are AI meeting note-takers allowed at work?

Only if the company approves them. A good policy limits note-taking to approved tools, requires telling every participant at the start, turns the tool off if anyone objects, and keeps it out of legal, HR and confidential meetings. Some states require every participant to agree before a conversation is recorded, so notice and agreement is the safe default.

How often should an AI acceptable use policy be updated?

Review it at least every six months, because AI products, features and vendor terms change quickly. Also update it right away when you approve a new AI tool, after an AI-related incident, or when a new law or customer contract changes what is allowed.

Related policy templates

Services that put this policy into practice

Want help rolling out your AI Acceptable Use Policy?

A policy works when the tools, training and controls behind it do. Preferred Data Corporation helps North Carolina businesses put policies like this one into practice, from High Point since 1987.