Artificial Intelligence Governance Policy
- Document ID
- PDC-AIG-SAMPLE
- Document version
- 1.0
- Template version
- v1.0.0
- Effective date
- September 27, 2026
- Next review
- March 27, 2027
1. Purpose
This policy sets the rules for how [Company Name] (the "company") selects, approves, uses, oversees, and retires artificial intelligence (AI). Its goal is to let the company benefit from AI while protecting its information, its customers, its employees, and its reputation.
Our stance. [Company Name] supports the use of approved AI tools for everyday work, under clear rules for data, human review, and accountability.
The policy is designed to align with the NIST AI Risk Management Framework (AI RMF 1.0) and to support the company in meeting its legal, regulatory, and contractual obligations. It does not replace those obligations. Where a law, regulation, or contract sets a stricter requirement, the stricter requirement applies.
2. Scope
People. This policy applies to all employees, officers, temporary workers, interns, contractors, consultants, and anyone else who uses AI on behalf of [Company Name] or with company information ("personnel").
Technology and activities. It covers any use of AI for company business, on any device and from any location, including:
- Stand-alone AI tools, such as chat assistants, image and video generators, and transcription services.
- AI features built into software the company already uses, such as office suites, email, CRM, ERP, accounting, design, and security tools.
- AI coding assistants, browser extensions, and mobile apps with AI features.
- AI agents and automations that can take actions in company systems.
- AI that the company builds, customizes, or offers to customers as part of its products or services.
- AI used by vendors and service providers to process company or customer information.
Out of scope. Personal use of AI on personal devices that involves no company, customer, or employee information, and software with no AI or machine learning capability.
3. Definitions
- AI system
- An engineered or machine-based system that can, for a given set of objectives, generate outputs such as predictions, recommendations, content, or decisions that influence real or virtual environments.
- Generative AI
- AI that creates new text, images, audio, video, or code in response to a prompt. Chat assistants and image generators are examples.
- Agentic AI (AI agent)
- AI that can plan and take actions toward a goal with limited human direction, such as sending messages, changing records, running code, or making purchases.
- AI output
- Anything an AI system produces, including text, summaries, code, images, recordings, scores, recommendations, and actions.
- Approved AI tool
- An AI tool, feature, or service that the AI Governance Lead has approved for company use under this policy, together with the classes of information it may process.
- Shadow AI
- Any AI tool, account, feature, or browser extension used for company work without approval under this policy.
- Confidential information
- Nonpublic information about the company, its customers, suppliers, or personnel, including pricing, financial data, contracts, designs, plans, and anything covered by a confidentiality agreement.
- Consequential decision
- A decision that has a material effect on a person, such as employment, pay, credit, insurance, housing, access to services, or safety, or that commits the company legally or financially.
- Human in the loop
- A qualified person who reviews AI output, understands its limits, and has the authority and the time to change or reject it before it takes effect.
- Hallucination
- AI output that is false, invented, or unsupported but presented as fact, such as a made-up citation, figure, or quote. NIST calls this confabulation.
- Prompt injection
- An attack in which instructions hidden in content that an AI system reads, such as a web page, email, or document, cause it to ignore its intended instructions.
- AI inventory
- The register of approved AI tools, AI features, and AI use cases maintained under this policy.
4. Guiding Principles
[Company Name] uses AI in line with the characteristics of trustworthy AI described in the NIST AI Risk Management Framework. Every decision under this policy should be tested against these principles.
| Principle | What it means in practice |
|---|---|
| Valid and reliable | AI output is checked for accuracy before it is relied on. A tool that proves unreliable for a task is not used for that task. |
| Safe | AI is never allowed to put people, property, or operations at risk. People stay in control of physical and safety-related processes. |
| Secure and resilient | AI tools are secured like any other system, with approved accounts, strong authentication, least-privilege access, and logging. |
| Accountable and transparent | A named person is accountable for every AI tool and every piece of AI output that is used. People are told when AI is used in ways that affect them. |
| Explainable and interpretable | Anyone relying on AI output should be able to explain what it is based on and why it is appropriate for the purpose. |
| Privacy-enhanced | Only the minimum information needed is shared with AI, and only in tools approved for that information. |
| Fair, with harmful bias managed | AI that affects people is checked for unfair or discriminatory results, and a person makes the final call on consequential decisions. |
5. Roles and Responsibilities
| Role | Responsibilities |
|---|---|
| Executive sponsor (Chief Executive Officer) | Approves this policy and the company risk appetite for AI, provides resources, decides high-risk uses and escalated exceptions, and holds leaders accountable for compliance. |
| AI Governance Lead | Appointed by the Chief Executive Officer. Approves AI tools and use cases, owns the AI risk process, reviews incidents and exceptions, keeps this policy current, and reports on AI risk to the Chief Executive Officer at least quarterly. |
| IT and security | Configures and secures approved AI tools, manages accounts and access, enforces technical controls, keeps logs, detects unapproved AI, and leads the technical response to AI incidents. |
| Tool owner | The business owner named for each approved AI tool. Ensures the tool is used only for its approved purposes and data, tracks vendor changes, and requests reassessment when the use changes. |
| Legal counsel | Internal or external counsel reviews AI vendor contracts, high-risk uses, disclosure obligations, and incidents that may require notification. |
| Managers | Make sure their teams complete training, use only approved AI tools, and apply human review. Escalate new AI needs instead of allowing workarounds. |
| All personnel | Follow this policy, protect company information, review AI output before relying on it, and report incidents, mistakes, and concerns promptly. |
Accountability. Using AI does not transfer responsibility. The person who uses AI output, and the manager who approves the work, are accountable for it as if they had produced it themselves.
6. AI Tool Approval, Inventory and Vendors
Approval required. Only approved AI tools may be used for company work. The AI Governance Lead approves each tool, records the classes of information it may process and its approved uses, and names a tool owner. New AI features that a vendor adds to software the company already uses must also be reviewed before they are turned on for company data.
Personal accounts. Personal, free, or consumer AI accounts must not be used for company work, even for tasks that seem harmless. Their terms often allow the provider to retain what is entered or use it to train models, and the company cannot see, control, or delete that information.
Risk assessment. Before approval, the AI Governance Lead documents a risk assessment that confirms at least the following. The assessment is repeated when the tool, its terms, or its use changes materially, and at least once a year.
- The business purpose, the intended users, and the classes of information the tool will process.
- The vendor contract prohibits using company data to train or improve models, limits retention, and allows deletion on request.
- Where data is stored and processed, which subprocessors are used, and whether the vendor holds independent security attestations such as SOC 2 Type II or ISO/IEC 27001.
- Single sign-on, multi-factor authentication, administrator controls, and audit logging are available.
- Known limitations, accuracy on the intended task, and the potential for biased or unsafe output.
- What the AI can access and do, especially for AI agents and AI features that search company files or mailboxes.
- The vendor terms on output ownership, intellectual property indemnity, and liability.
- How the tool will be retired and company data returned or deleted.
Vendor contracts. AI vendors that process any company information other than public information must commit in writing not to use it to train or improve their models, must protect it with appropriate security, and must notify the company of security incidents affecting it. Business or enterprise agreements are required. Click-through consumer terms are not sufficient.
AI used by our vendors. Suppliers and service providers that use AI to process company or customer information must disclose that use on request, follow data protection terms at least as strict as this policy, and obtain approval before using AI in ways their contract does not already cover.
AI inventory. The AI Governance Lead maintains an AI inventory and reviews it at least quarterly. Each entry records:
- The tool or feature, vendor, version or plan, and tool owner.
- Approved use cases and the classes of information it may process.
- The risk rating, the date of the last assessment, and any conditions of approval.
- Whether it is customer-facing, makes or supports consequential decisions, or can take actions as an agent.
- Integrations and the systems and data it can access.
- The date approved, the date of next review, and the retirement date when it is removed.
Requests and retirement. Personnel request a new AI tool or use case through the AI Governance Lead. When a tool is retired, accounts and integrations are disabled and the vendor is asked to return or delete company data.
7. Acceptable Uses
Approved AI tools may be used for everyday work that follows this policy. Common examples include:
- Drafting, editing, and summarizing emails, reports, procedures, and proposals.
- Researching general topics and brainstorming ideas.
- Summarizing long documents that the tool is approved to process.
- Analyzing data and creating charts from information the tool is approved to process.
- Creating first drafts of training material, job aids, and marketing content for human review.
- Translating internal content, with review by a fluent speaker before external use.
Every use must follow the data rules, human review rules, and prohibitions in this policy.
AI coding assistants. Approved AI coding assistants may be used for software, scripts, automations, and spreadsheet formulas. AI-generated code must be reviewed by a qualified person, tested, and scanned like any other code before it reaches production. Passwords, keys, tokens, and customer credentials must never be placed in prompts or code, and suggestions that reproduce third-party code must be checked for license terms.
AI meeting assistants. Only approved AI note-takers and transcription tools may be used. The meeting organizer must tell all participants at the start that AI is recording or transcribing, and must obtain consent wherever the law requires it. AI meeting assistants must not be used in meetings about legal advice, personnel matters, or security incidents unless the meeting owner approves, and third-party note-taker bots that join company meetings uninvited must be removed.
Customer-facing AI. Chatbots, automated replies, AI voice agents, and other AI that interacts directly with customers, suppliers, or the public may be deployed only after approval by the AI Governance Lead. Each must be tested before launch, limited to approved topics and information, clearly identified as AI, and give people an easy way to reach a person. The company is responsible for what its AI tells customers.
AI agents. AI agents may read information and prepare actions within approved workflows, but a person must approve each consequential action before it happens, including sending external communications, moving money, changing or deleting records, changing access rights or security settings, and making purchases or commitments.
8. Prohibited Uses
The following uses of AI are prohibited for all personnel:
- Any use that violates a law, regulation, contract, or company policy.
- Using an AI tool that is not approved, or using an approved tool with information it is not approved to process.
- Entering passwords, access keys, tokens, or other secrets into any AI tool.
- Creating content that harasses, discriminates, defames, or is sexually explicit.
- Deceiving customers, regulators, or anyone else, including fabricating records, reviews, test results, evidence, or citations.
- Bypassing security controls, generating malicious code, or probing systems for weaknesses without written authorization from IT and security.
- Using AI to reproduce copyrighted material, trademarks, or confidential information belonging to others without permission.
- Presenting AI output as verified fact, or as the independent work of a person, where that would mislead the recipient.
High-risk uses. Because of their potential for serious harm to people, [Company Name] also prohibits:
- Using AI to make hiring, firing, promotion, pay, scheduling, or discipline decisions without meaningful review by a qualified person.
- Using AI to decide credit, lending, insurance, tenancy, or individual pricing for a person without meaningful review by a qualified person.
- Giving legal, medical, tax, or financial advice to anyone based on AI output that a qualified professional has not reviewed.
- Using AI to identify or categorize people from their face, voice, fingerprints, or other biometric data, including facial recognition.
- Using AI to infer the emotions, personality, or trustworthiness of employees, applicants, or customers.
- Using AI to covertly monitor, record, or profile employees, customers, or members of the public.
- Creating synthetic images, audio, or video of a real person, or imitating a real person in writing, without that person's documented consent.
- Allowing AI to directly control machinery, vehicles, safety systems, or operational technology without a person in control who can override it.
9. Data Protection and Privacy
Basic rule. Only enter information into an AI tool that the tool is approved to process, and only the minimum needed for the task. When in doubt, remove names and identifying details, or ask before you enter anything.
| Class of information | Where it may be used |
|---|---|
| Public information | Any approved AI tool. |
| Internal information | Approved AI tools used through company-managed accounts. |
| Confidential information | Only approved AI tools that are specifically approved for confidential information under a business agreement. |
| Passwords, keys, and other secrets | Never permitted in any AI tool. |
Restricted information. The following information may be used with AI only after the AI Governance Lead gives specific written approval for the tool and the purpose, even if the tool is otherwise approved: sensitive personal information, customer-owned data and files, personnel records, and privileged legal communications.
Customer and third-party information. Information that belongs to customers, suppliers, or other third parties may be used with AI only where the contract or confidentiality agreement covering it allows that use. Many customer contracts now limit or prohibit AI processing, so check before you use it.
Personal information. Personal information about employees, applicants, customers, or others must be handled in line with applicable privacy and data breach notification laws, including those of North Carolina and of every state where the affected individuals live. Do not use AI to combine personal information in ways people would not reasonably expect, and honor any request to access or delete personal information that the law requires.
Retention and logging. Company-managed AI tools must keep audit logs of use, including agent actions where the tool supports it, for at least 12 months, or longer where a contract, regulation, or legal hold requires. Prompts and outputs are company records and follow the company record retention requirements. Vendor retention of company data must be limited to what the contract allows.
10. Human Oversight, Accuracy and Transparency
Human review. A qualified person must review AI output before it is: sent or published outside the company; used to make or support a consequential decision about a person; used in safety, financial, legal, contractual, or regulatory work; or deployed as code, configuration, or automation in a production system. Internal drafts and brainstorming do not need formal review, but the person using them remains responsible for them.
Checking accuracy. AI can produce confident, well-written output that is wrong. Reviewers must check facts, figures, names, quotes, citations, legal and regulatory references, and calculations against reliable sources, and must not assume that output is correct because it looks professional. "The AI said so" is never an acceptable basis for a decision.
Decisions about people. Where AI supports a consequential decision about a person, a qualified person must make the final decision, must be able to override the AI, and must consider information the AI may have missed. AI used this way must be tested for unfair or discriminatory results before use and periodically after, and the company must follow any notice, explanation, or appeal requirements that apply by law.
Transparency and disclosure. [Company Name] tells people when they are interacting with AI rather than a person, labels AI-generated or AI-altered images, audio, and video that could be mistaken for real, and discloses AI use to customers where a law, contract, or professional standard requires it, or where they would reasonably expect to know.
In every case, AI must never be used to mislead anyone about whether they are dealing with a person, or to misrepresent AI-generated content as real events or statements.
11. Security of AI Systems
AI tools are information systems and must meet the same security standards as any other system, plus the following controls for risks specific to AI:
- AI tools must be used through company-managed accounts protected by multi-factor authentication, with single sign-on wherever the tool supports it.
- Before an AI assistant is allowed to search company files, email, or chat, IT and security must review file-sharing permissions. These assistants can surface anything a user can technically access, including files that were overshared by mistake.
- Content that AI reads from outside sources, such as web pages, emails, and uploaded documents, must be treated as untrusted. It can carry hidden instructions (prompt injection).
- AI output must not be executed, run as a command, or passed into another system automatically unless that workflow has been approved and the output is validated first.
- AI browser extensions, plug-ins, and connectors must be approved before installation, because they can read everything a user sees.
- API keys and service accounts used by AI integrations must be stored in an approved secrets manager, limited to the access they need, and rotated.
- AI tools and integrations must be kept up to date and included in vulnerability management and security monitoring.
- Each AI agent must run under its own identity with least-privilege access, never a person's credentials, with limits on spending, volume, and scope, full logging of its actions, and a tested way to stop it immediately.
Deepfake and impersonation fraud. AI can convincingly imitate the voice, face, and writing of executives, customers, and suppliers. Any request received by phone, video, email, or message to send money, change payment or banking details, share credentials, or bypass a normal process must be verified through a separate, known contact method before anyone acts on it.
12. Intellectual Property and Output Ownership
Company ownership. AI output created by personnel for company work, using company tools or information, belongs to [Company Name] to the extent the law allows, on the same terms as any other work product.
Copyright limits. Under current U.S. Copyright Office guidance, material generated by AI is protected by copyright only where a human author determined sufficient expressive elements. Prompts alone are not enough. Where ownership matters, such as product designs, software, and marketing assets, keep a record of the human creative contribution and do not rely on AI output alone.
Rights of others. Do not prompt AI to copy or imitate a specific copyrighted work, a living artist, or a competitor brand, and do not upload material the company does not have the right to use. Check AI-generated names, logos, and slogans for conflicts before using them publicly.
Confidential inputs. Entering confidential or patentable information into an AI tool that is not approved for it may be treated as a disclosure. Consult counsel before using AI on inventions that may be patented.
13. Training and Awareness
All personnel must complete AI training before they are given access to approved AI tools, and again at least once a year. Training covers:
- This policy, the approved tool list, and how to request a new tool.
- Which information may go into which tools, with practical examples.
- How AI can be wrong or biased, and how to check its output.
- Prompt injection, deepfakes, and AI-assisted phishing and fraud.
- How and when to report an AI incident or mistake.
Role-based training. People who approve AI tools, build automations or AI agents, write code with AI, or use AI in consequential decisions receive additional training suited to their role. The AI Governance Lead sends short updates when tools, rules, or risks change, and training completion is recorded.
14. Incident Reporting and Response
Report promptly. Personnel must report a suspected AI incident to the AI Governance Lead immediately, and no later than 24 hours after discovering it. Report even if you are unsure, and even if you caused it. Good-faith reports are welcome and no one will face retaliation for making one. AI incidents include:
- Confidential, personal, regulated, or customer information entered into an unapproved tool or one not approved for it.
- AI output that caused, or could cause, harm to a customer, an employee, the public, or the company.
- An AI agent or automation acting outside its approved limits.
- Suspected prompt injection, compromise of an AI account, or unusual AI activity.
- Discriminatory, unsafe, or offensive output from a company AI system.
- A deepfake or AI-assisted impersonation attempt against the company or its people.
Response. Do not delete the conversation, output, or account involved unless told to. The AI Governance Lead and IT and security contain the incident, which may include disabling access or an agent, requesting deletion from the vendor, and correcting any output that was relied on. Incidents are handled under the company incident response procedures, assessed by legal counsel for notification obligations under breach notification laws and contracts, and recorded with lessons learned and changes to controls.
15. Monitoring, Audit, Enforcement and Exceptions
Monitoring. IT and security use available controls, such as web filtering, cloud application discovery, identity logs, data loss prevention, and browser extension management, to detect and block unapproved AI tools and to confirm that approved tools are used as intended. Monitoring is performed for security and compliance purposes and in line with applicable law, including any employee notice requirements.
Audit. The AI Governance Lead audits compliance with this policy at least once a year, covering the accuracy of the AI inventory, user access and account reviews, vendor terms, a sample of AI-assisted work, training completion, incidents, and open exceptions. Results and corrective actions are reported to the Chief Executive Officer.
Enforcement. Violations of this policy may result in loss of access to AI tools and disciplinary action, up to and including termination of employment or of a contractor agreement, consistent with applicable law. Prompt self-reporting of a mistake is taken into account.
Exceptions. Requests for an exception must be made in writing to the AI Governance Lead, explaining the business need, the risk, and the controls that will reduce it. The AI Governance Lead may approve low-risk exceptions. Exceptions that involve regulated data, consequential decisions, or customer-facing AI also require approval by the Chief Executive Officer. Every exception is recorded, limited to no more than 12 months, and reviewed before renewal. No exception can permit a use that breaks the law or a contract.
Policy review. The AI Governance Lead reviews this policy no later than March 27, 2027, and sooner after a significant AI incident, a new AI law or contract requirement that applies to the company, or the adoption of a new category of AI such as agents or customer-facing AI.
17. Acknowledgment
I have read and understand the [Company Name] Artificial Intelligence Governance Policy. I agree to use only approved AI tools, to protect company and customer information, to review AI output before relying on it, and to report AI incidents promptly. I understand that violations may result in disciplinary action.
Name
Job title
Signature
Date
18. Document Control and Revision History
| Field | Value |
|---|---|
| Document | Artificial Intelligence Governance Policy |
| Organization | [Company Name] |
| Document ID | PDC-AIG-SAMPLE |
| Document version | 1.0 |
| Effective date | September 27, 2026 |
| Next scheduled review | March 27, 2027 |
| Policy owner | AI Governance Lead |
| Approved by | Chief Executive Officer |
| Source template | Preferred Data Corporation AI Governance Policy template v1.0.0 |
Revision history. Record every change to this policy below. Increase the document version and obtain approval again each time the policy is revised.
| Version | Date | Description of change | Approved by |
|---|---|---|---|
| 1.0 | September 27, 2026 | Initial adoption, generated from template v1.0.0. | Chief Executive Officer |
| Blank | Blank | Blank | Blank |
| Blank | Blank | Blank | Blank |
19. Template Notice and Legal Disclaimer
This document was generated from a starter template provided by Preferred Data Corporation. It is general information only. It is not legal advice and it is not a substitute for advice from a licensed attorney.
Preferred Data Corporation is not a law firm. It makes no representation that this document is complete, current, or suitable for any particular organization, industry, jurisdiction, or regulatory requirement, and it is not responsible or liable for any use of this template or of any policy created from it. You are solely responsible for how you adapt, adopt, and enforce it.
Laws, regulations, insurance requirements, and contracts that apply to your organization may require different or additional terms. Before you adopt, publish, or rely on this policy, and in every case where you have a legal, regulatory, or contractual obligation, have it reviewed by qualified legal counsel.