Free artificial intelligence policy template

Free AI Governance Policy Template and Generator

An AI governance policy is the written rulebook for how a business approves, uses, oversees and audits artificial intelligence, from chat assistants to AI features built into everyday software and AI agents that take actions. A business needs one because employees are already using AI, often through personal accounts: IBM found that 63% of breached organizations had no AI governance policy or were still developing one, and that high levels of shadow AI added an average of $670,000 to breach costs. This free generator builds a policy aligned to the NIST AI Risk Management Framework in a few minutes.

An AI governance policy is a formal, executive-approved document that defines which AI tools an organization may use, what data they may process, who is accountable for them, and how AI output is reviewed, monitored and corrected.

Template version
v1.0.0
Last reviewed
September 27, 2026
Sections
19
Guided phases
6
Time to complete
About 6 minutes
Price
Free

Why does this policy matter now?

What is inside the AI Governance Policy template?

19 sections, ending with the document control table and the legal notice every template carries. Select any section to jump to it in the sample below.

  1. 1. PurposeWhy the policy exists and the stance it takes on artificial intelligence.
  2. 2. ScopeWho and what the policy covers, including AI built into existing software.
  3. 3. DefinitionsPlain-language definitions of AI system, generative AI, agentic AI, shadow AI and more.
  4. 4. Guiding PrinciplesThe seven NIST trustworthy AI characteristics, translated into everyday rules.
  5. 5. Roles and ResponsibilitiesWho sponsors, governs, secures, supervises and follows the policy.
  6. 6. AI Tool Approval, Inventory and VendorsHow AI tools and vendors are assessed, approved, recorded and retired.
  7. 7. Acceptable UsesEveryday work AI can help with, plus rules for coding, meetings, customer-facing AI and agents.
  8. 8. Prohibited UsesUses that are never allowed, plus the high-risk uses your organization bans outright.
  9. 9. Data Protection and PrivacyWhat information may go into which AI tools, with added rules for regulated data.
  10. 10. Human Oversight, Accuracy and TransparencyWhen a person must review AI output, how to check it, and when to disclose AI use.
  11. 11. Security of AI SystemsAccounts, access, prompt injection, output handling, agent limits and deepfake fraud.
  12. 12. Intellectual Property and Output OwnershipWho owns AI output, copyright limits, and respecting the rights of others.
  13. 13. Training and AwarenessAI training at onboarding and on a regular schedule, plus role-based training.
  14. 14. Incident Reporting and ResponseWhat counts as an AI incident, the reporting deadline, and how the company responds.
  15. 15. Monitoring, Audit, Enforcement and ExceptionsShadow AI detection, regular audits, consequences for violations, and how exceptions work.
  16. 16. Related Standards and ReferencesThe frameworks, standards and laws this policy is designed to align with.
  17. 17. AcknowledgmentA signature block confirming each person has read and will follow the policy.
  18. 18. Document Control and Revision HistoryDocument ID, version, effective date, next review, owner and approver, plus a revision history table.
  19. 19. Template Notice and Legal DisclaimerThe starter-template disclaimer and the reminder to have qualified counsel review the policy.
Template changelog
  • v1.0.0, September 27, 2026

    • Initial release aligned to NIST AI RMF 1.0, the NIST Generative AI Profile (NIST AI 600-1), ISO/IEC 42001:2023 and the OWASP Top 10 for LLM Applications (2025).

Read the full sample AI Governance Policy

This sample uses the recommended answer to every question and a placeholder company name. Build your own version to put in your organization's name, owners and choices.

Sections in this policy
Sample[Company Name]

Artificial Intelligence Governance Policy

Document ID
PDC-AIG-SAMPLE
Document version
1.0
Template version
v1.0.0
Effective date
September 27, 2026
Next review
March 27, 2027

1. Purpose

This policy sets the rules for how [Company Name] (the "company") selects, approves, uses, oversees, and retires artificial intelligence (AI). Its goal is to let the company benefit from AI while protecting its information, its customers, its employees, and its reputation.

Our stance. [Company Name] supports the use of approved AI tools for everyday work, under clear rules for data, human review, and accountability.

The policy is designed to align with the NIST AI Risk Management Framework (AI RMF 1.0) and to support the company in meeting its legal, regulatory, and contractual obligations. It does not replace those obligations. Where a law, regulation, or contract sets a stricter requirement, the stricter requirement applies.

2. Scope

People. This policy applies to all employees, officers, temporary workers, interns, contractors, consultants, and anyone else who uses AI on behalf of [Company Name] or with company information ("personnel").

Technology and activities. It covers any use of AI for company business, on any device and from any location, including:

  • Stand-alone AI tools, such as chat assistants, image and video generators, and transcription services.
  • AI features built into software the company already uses, such as office suites, email, CRM, ERP, accounting, design, and security tools.
  • AI coding assistants, browser extensions, and mobile apps with AI features.
  • AI agents and automations that can take actions in company systems.
  • AI that the company builds, customizes, or offers to customers as part of its products or services.
  • AI used by vendors and service providers to process company or customer information.

Out of scope. Personal use of AI on personal devices that involves no company, customer, or employee information, and software with no AI or machine learning capability.

3. Definitions

AI system
An engineered or machine-based system that can, for a given set of objectives, generate outputs such as predictions, recommendations, content, or decisions that influence real or virtual environments.
Generative AI
AI that creates new text, images, audio, video, or code in response to a prompt. Chat assistants and image generators are examples.
Agentic AI (AI agent)
AI that can plan and take actions toward a goal with limited human direction, such as sending messages, changing records, running code, or making purchases.
AI output
Anything an AI system produces, including text, summaries, code, images, recordings, scores, recommendations, and actions.
Approved AI tool
An AI tool, feature, or service that the AI Governance Lead has approved for company use under this policy, together with the classes of information it may process.
Shadow AI
Any AI tool, account, feature, or browser extension used for company work without approval under this policy.
Confidential information
Nonpublic information about the company, its customers, suppliers, or personnel, including pricing, financial data, contracts, designs, plans, and anything covered by a confidentiality agreement.
Consequential decision
A decision that has a material effect on a person, such as employment, pay, credit, insurance, housing, access to services, or safety, or that commits the company legally or financially.
Human in the loop
A qualified person who reviews AI output, understands its limits, and has the authority and the time to change or reject it before it takes effect.
Hallucination
AI output that is false, invented, or unsupported but presented as fact, such as a made-up citation, figure, or quote. NIST calls this confabulation.
Prompt injection
An attack in which instructions hidden in content that an AI system reads, such as a web page, email, or document, cause it to ignore its intended instructions.
AI inventory
The register of approved AI tools, AI features, and AI use cases maintained under this policy.

4. Guiding Principles

[Company Name] uses AI in line with the characteristics of trustworthy AI described in the NIST AI Risk Management Framework. Every decision under this policy should be tested against these principles.

PrincipleWhat it means in practice
Valid and reliableAI output is checked for accuracy before it is relied on. A tool that proves unreliable for a task is not used for that task.
SafeAI is never allowed to put people, property, or operations at risk. People stay in control of physical and safety-related processes.
Secure and resilientAI tools are secured like any other system, with approved accounts, strong authentication, least-privilege access, and logging.
Accountable and transparentA named person is accountable for every AI tool and every piece of AI output that is used. People are told when AI is used in ways that affect them.
Explainable and interpretableAnyone relying on AI output should be able to explain what it is based on and why it is appropriate for the purpose.
Privacy-enhancedOnly the minimum information needed is shared with AI, and only in tools approved for that information.
Fair, with harmful bias managedAI that affects people is checked for unfair or discriminatory results, and a person makes the final call on consequential decisions.

5. Roles and Responsibilities

RoleResponsibilities
Executive sponsor (Chief Executive Officer)Approves this policy and the company risk appetite for AI, provides resources, decides high-risk uses and escalated exceptions, and holds leaders accountable for compliance.
AI Governance LeadAppointed by the Chief Executive Officer. Approves AI tools and use cases, owns the AI risk process, reviews incidents and exceptions, keeps this policy current, and reports on AI risk to the Chief Executive Officer at least quarterly.
IT and securityConfigures and secures approved AI tools, manages accounts and access, enforces technical controls, keeps logs, detects unapproved AI, and leads the technical response to AI incidents.
Tool ownerThe business owner named for each approved AI tool. Ensures the tool is used only for its approved purposes and data, tracks vendor changes, and requests reassessment when the use changes.
Legal counselInternal or external counsel reviews AI vendor contracts, high-risk uses, disclosure obligations, and incidents that may require notification.
ManagersMake sure their teams complete training, use only approved AI tools, and apply human review. Escalate new AI needs instead of allowing workarounds.
All personnelFollow this policy, protect company information, review AI output before relying on it, and report incidents, mistakes, and concerns promptly.

Accountability. Using AI does not transfer responsibility. The person who uses AI output, and the manager who approves the work, are accountable for it as if they had produced it themselves.

6. AI Tool Approval, Inventory and Vendors

Approval required. Only approved AI tools may be used for company work. The AI Governance Lead approves each tool, records the classes of information it may process and its approved uses, and names a tool owner. New AI features that a vendor adds to software the company already uses must also be reviewed before they are turned on for company data.

Personal accounts. Personal, free, or consumer AI accounts must not be used for company work, even for tasks that seem harmless. Their terms often allow the provider to retain what is entered or use it to train models, and the company cannot see, control, or delete that information.

Risk assessment. Before approval, the AI Governance Lead documents a risk assessment that confirms at least the following. The assessment is repeated when the tool, its terms, or its use changes materially, and at least once a year.

  • The business purpose, the intended users, and the classes of information the tool will process.
  • The vendor contract prohibits using company data to train or improve models, limits retention, and allows deletion on request.
  • Where data is stored and processed, which subprocessors are used, and whether the vendor holds independent security attestations such as SOC 2 Type II or ISO/IEC 27001.
  • Single sign-on, multi-factor authentication, administrator controls, and audit logging are available.
  • Known limitations, accuracy on the intended task, and the potential for biased or unsafe output.
  • What the AI can access and do, especially for AI agents and AI features that search company files or mailboxes.
  • The vendor terms on output ownership, intellectual property indemnity, and liability.
  • How the tool will be retired and company data returned or deleted.

Vendor contracts. AI vendors that process any company information other than public information must commit in writing not to use it to train or improve their models, must protect it with appropriate security, and must notify the company of security incidents affecting it. Business or enterprise agreements are required. Click-through consumer terms are not sufficient.

AI used by our vendors. Suppliers and service providers that use AI to process company or customer information must disclose that use on request, follow data protection terms at least as strict as this policy, and obtain approval before using AI in ways their contract does not already cover.

AI inventory. The AI Governance Lead maintains an AI inventory and reviews it at least quarterly. Each entry records:

  • The tool or feature, vendor, version or plan, and tool owner.
  • Approved use cases and the classes of information it may process.
  • The risk rating, the date of the last assessment, and any conditions of approval.
  • Whether it is customer-facing, makes or supports consequential decisions, or can take actions as an agent.
  • Integrations and the systems and data it can access.
  • The date approved, the date of next review, and the retirement date when it is removed.

Requests and retirement. Personnel request a new AI tool or use case through the AI Governance Lead. When a tool is retired, accounts and integrations are disabled and the vendor is asked to return or delete company data.

7. Acceptable Uses

Approved AI tools may be used for everyday work that follows this policy. Common examples include:

  • Drafting, editing, and summarizing emails, reports, procedures, and proposals.
  • Researching general topics and brainstorming ideas.
  • Summarizing long documents that the tool is approved to process.
  • Analyzing data and creating charts from information the tool is approved to process.
  • Creating first drafts of training material, job aids, and marketing content for human review.
  • Translating internal content, with review by a fluent speaker before external use.

Every use must follow the data rules, human review rules, and prohibitions in this policy.

AI coding assistants. Approved AI coding assistants may be used for software, scripts, automations, and spreadsheet formulas. AI-generated code must be reviewed by a qualified person, tested, and scanned like any other code before it reaches production. Passwords, keys, tokens, and customer credentials must never be placed in prompts or code, and suggestions that reproduce third-party code must be checked for license terms.

AI meeting assistants. Only approved AI note-takers and transcription tools may be used. The meeting organizer must tell all participants at the start that AI is recording or transcribing, and must obtain consent wherever the law requires it. AI meeting assistants must not be used in meetings about legal advice, personnel matters, or security incidents unless the meeting owner approves, and third-party note-taker bots that join company meetings uninvited must be removed.

Customer-facing AI. Chatbots, automated replies, AI voice agents, and other AI that interacts directly with customers, suppliers, or the public may be deployed only after approval by the AI Governance Lead. Each must be tested before launch, limited to approved topics and information, clearly identified as AI, and give people an easy way to reach a person. The company is responsible for what its AI tells customers.

AI agents. AI agents may read information and prepare actions within approved workflows, but a person must approve each consequential action before it happens, including sending external communications, moving money, changing or deleting records, changing access rights or security settings, and making purchases or commitments.

8. Prohibited Uses

The following uses of AI are prohibited for all personnel:

  • Any use that violates a law, regulation, contract, or company policy.
  • Using an AI tool that is not approved, or using an approved tool with information it is not approved to process.
  • Entering passwords, access keys, tokens, or other secrets into any AI tool.
  • Creating content that harasses, discriminates, defames, or is sexually explicit.
  • Deceiving customers, regulators, or anyone else, including fabricating records, reviews, test results, evidence, or citations.
  • Bypassing security controls, generating malicious code, or probing systems for weaknesses without written authorization from IT and security.
  • Using AI to reproduce copyrighted material, trademarks, or confidential information belonging to others without permission.
  • Presenting AI output as verified fact, or as the independent work of a person, where that would mislead the recipient.

High-risk uses. Because of their potential for serious harm to people, [Company Name] also prohibits:

  • Using AI to make hiring, firing, promotion, pay, scheduling, or discipline decisions without meaningful review by a qualified person.
  • Using AI to decide credit, lending, insurance, tenancy, or individual pricing for a person without meaningful review by a qualified person.
  • Giving legal, medical, tax, or financial advice to anyone based on AI output that a qualified professional has not reviewed.
  • Using AI to identify or categorize people from their face, voice, fingerprints, or other biometric data, including facial recognition.
  • Using AI to infer the emotions, personality, or trustworthiness of employees, applicants, or customers.
  • Using AI to covertly monitor, record, or profile employees, customers, or members of the public.
  • Creating synthetic images, audio, or video of a real person, or imitating a real person in writing, without that person's documented consent.
  • Allowing AI to directly control machinery, vehicles, safety systems, or operational technology without a person in control who can override it.

9. Data Protection and Privacy

Basic rule. Only enter information into an AI tool that the tool is approved to process, and only the minimum needed for the task. When in doubt, remove names and identifying details, or ask before you enter anything.

Class of informationWhere it may be used
Public informationAny approved AI tool.
Internal informationApproved AI tools used through company-managed accounts.
Confidential informationOnly approved AI tools that are specifically approved for confidential information under a business agreement.
Passwords, keys, and other secretsNever permitted in any AI tool.

Restricted information. The following information may be used with AI only after the AI Governance Lead gives specific written approval for the tool and the purpose, even if the tool is otherwise approved: sensitive personal information, customer-owned data and files, personnel records, and privileged legal communications.

Customer and third-party information. Information that belongs to customers, suppliers, or other third parties may be used with AI only where the contract or confidentiality agreement covering it allows that use. Many customer contracts now limit or prohibit AI processing, so check before you use it.

Personal information. Personal information about employees, applicants, customers, or others must be handled in line with applicable privacy and data breach notification laws, including those of North Carolina and of every state where the affected individuals live. Do not use AI to combine personal information in ways people would not reasonably expect, and honor any request to access or delete personal information that the law requires.

Retention and logging. Company-managed AI tools must keep audit logs of use, including agent actions where the tool supports it, for at least 12 months, or longer where a contract, regulation, or legal hold requires. Prompts and outputs are company records and follow the company record retention requirements. Vendor retention of company data must be limited to what the contract allows.

10. Human Oversight, Accuracy and Transparency

Human review. A qualified person must review AI output before it is: sent or published outside the company; used to make or support a consequential decision about a person; used in safety, financial, legal, contractual, or regulatory work; or deployed as code, configuration, or automation in a production system. Internal drafts and brainstorming do not need formal review, but the person using them remains responsible for them.

Checking accuracy. AI can produce confident, well-written output that is wrong. Reviewers must check facts, figures, names, quotes, citations, legal and regulatory references, and calculations against reliable sources, and must not assume that output is correct because it looks professional. "The AI said so" is never an acceptable basis for a decision.

Decisions about people. Where AI supports a consequential decision about a person, a qualified person must make the final decision, must be able to override the AI, and must consider information the AI may have missed. AI used this way must be tested for unfair or discriminatory results before use and periodically after, and the company must follow any notice, explanation, or appeal requirements that apply by law.

Transparency and disclosure. [Company Name] tells people when they are interacting with AI rather than a person, labels AI-generated or AI-altered images, audio, and video that could be mistaken for real, and discloses AI use to customers where a law, contract, or professional standard requires it, or where they would reasonably expect to know.

In every case, AI must never be used to mislead anyone about whether they are dealing with a person, or to misrepresent AI-generated content as real events or statements.

11. Security of AI Systems

AI tools are information systems and must meet the same security standards as any other system, plus the following controls for risks specific to AI:

  • AI tools must be used through company-managed accounts protected by multi-factor authentication, with single sign-on wherever the tool supports it.
  • Before an AI assistant is allowed to search company files, email, or chat, IT and security must review file-sharing permissions. These assistants can surface anything a user can technically access, including files that were overshared by mistake.
  • Content that AI reads from outside sources, such as web pages, emails, and uploaded documents, must be treated as untrusted. It can carry hidden instructions (prompt injection).
  • AI output must not be executed, run as a command, or passed into another system automatically unless that workflow has been approved and the output is validated first.
  • AI browser extensions, plug-ins, and connectors must be approved before installation, because they can read everything a user sees.
  • API keys and service accounts used by AI integrations must be stored in an approved secrets manager, limited to the access they need, and rotated.
  • AI tools and integrations must be kept up to date and included in vulnerability management and security monitoring.
  • Each AI agent must run under its own identity with least-privilege access, never a person's credentials, with limits on spending, volume, and scope, full logging of its actions, and a tested way to stop it immediately.

Deepfake and impersonation fraud. AI can convincingly imitate the voice, face, and writing of executives, customers, and suppliers. Any request received by phone, video, email, or message to send money, change payment or banking details, share credentials, or bypass a normal process must be verified through a separate, known contact method before anyone acts on it.

12. Intellectual Property and Output Ownership

Company ownership. AI output created by personnel for company work, using company tools or information, belongs to [Company Name] to the extent the law allows, on the same terms as any other work product.

Copyright limits. Under current U.S. Copyright Office guidance, material generated by AI is protected by copyright only where a human author determined sufficient expressive elements. Prompts alone are not enough. Where ownership matters, such as product designs, software, and marketing assets, keep a record of the human creative contribution and do not rely on AI output alone.

Rights of others. Do not prompt AI to copy or imitate a specific copyrighted work, a living artist, or a competitor brand, and do not upload material the company does not have the right to use. Check AI-generated names, logos, and slogans for conflicts before using them publicly.

Confidential inputs. Entering confidential or patentable information into an AI tool that is not approved for it may be treated as a disclosure. Consult counsel before using AI on inventions that may be patented.

13. Training and Awareness

All personnel must complete AI training before they are given access to approved AI tools, and again at least once a year. Training covers:

  • This policy, the approved tool list, and how to request a new tool.
  • Which information may go into which tools, with practical examples.
  • How AI can be wrong or biased, and how to check its output.
  • Prompt injection, deepfakes, and AI-assisted phishing and fraud.
  • How and when to report an AI incident or mistake.

Role-based training. People who approve AI tools, build automations or AI agents, write code with AI, or use AI in consequential decisions receive additional training suited to their role. The AI Governance Lead sends short updates when tools, rules, or risks change, and training completion is recorded.

14. Incident Reporting and Response

Report promptly. Personnel must report a suspected AI incident to the AI Governance Lead immediately, and no later than 24 hours after discovering it. Report even if you are unsure, and even if you caused it. Good-faith reports are welcome and no one will face retaliation for making one. AI incidents include:

  • Confidential, personal, regulated, or customer information entered into an unapproved tool or one not approved for it.
  • AI output that caused, or could cause, harm to a customer, an employee, the public, or the company.
  • An AI agent or automation acting outside its approved limits.
  • Suspected prompt injection, compromise of an AI account, or unusual AI activity.
  • Discriminatory, unsafe, or offensive output from a company AI system.
  • A deepfake or AI-assisted impersonation attempt against the company or its people.

Response. Do not delete the conversation, output, or account involved unless told to. The AI Governance Lead and IT and security contain the incident, which may include disabling access or an agent, requesting deletion from the vendor, and correcting any output that was relied on. Incidents are handled under the company incident response procedures, assessed by legal counsel for notification obligations under breach notification laws and contracts, and recorded with lessons learned and changes to controls.

15. Monitoring, Audit, Enforcement and Exceptions

Monitoring. IT and security use available controls, such as web filtering, cloud application discovery, identity logs, data loss prevention, and browser extension management, to detect and block unapproved AI tools and to confirm that approved tools are used as intended. Monitoring is performed for security and compliance purposes and in line with applicable law, including any employee notice requirements.

Audit. The AI Governance Lead audits compliance with this policy at least once a year, covering the accuracy of the AI inventory, user access and account reviews, vendor terms, a sample of AI-assisted work, training completion, incidents, and open exceptions. Results and corrective actions are reported to the Chief Executive Officer.

Enforcement. Violations of this policy may result in loss of access to AI tools and disciplinary action, up to and including termination of employment or of a contractor agreement, consistent with applicable law. Prompt self-reporting of a mistake is taken into account.

Exceptions. Requests for an exception must be made in writing to the AI Governance Lead, explaining the business need, the risk, and the controls that will reduce it. The AI Governance Lead may approve low-risk exceptions. Exceptions that involve regulated data, consequential decisions, or customer-facing AI also require approval by the Chief Executive Officer. Every exception is recorded, limited to no more than 12 months, and reviewed before renewal. No exception can permit a use that breaks the law or a contract.

Policy review. The AI Governance Lead reviews this policy no later than March 27, 2027, and sooner after a significant AI incident, a new AI law or contract requirement that applies to the company, or the adoption of a new category of AI such as agents or customer-facing AI.

17. Acknowledgment

I have read and understand the [Company Name] Artificial Intelligence Governance Policy. I agree to use only approved AI tools, to protect company and customer information, to review AI output before relying on it, and to report AI incidents promptly. I understand that violations may result in disciplinary action.

Name

Job title

Signature

Date

18. Document Control and Revision History

FieldValue
DocumentArtificial Intelligence Governance Policy
Organization[Company Name]
Document IDPDC-AIG-SAMPLE
Document version1.0
Effective dateSeptember 27, 2026
Next scheduled reviewMarch 27, 2027
Policy ownerAI Governance Lead
Approved byChief Executive Officer
Source templatePreferred Data Corporation AI Governance Policy template v1.0.0

Revision history. Record every change to this policy below. Increase the document version and obtain approval again each time the policy is revised.

VersionDateDescription of changeApproved by
1.0September 27, 2026Initial adoption, generated from template v1.0.0.Chief Executive Officer
BlankBlankBlankBlank
BlankBlankBlankBlank

19. Template Notice and Legal Disclaimer

This document was generated from a starter template provided by Preferred Data Corporation. It is general information only. It is not legal advice and it is not a substitute for advice from a licensed attorney.

Preferred Data Corporation is not a law firm. It makes no representation that this document is complete, current, or suitable for any particular organization, industry, jurisdiction, or regulatory requirement, and it is not responsible or liable for any use of this template or of any policy created from it. You are solely responsible for how you adapt, adopt, and enforce it.

Laws, regulations, insurance requirements, and contracts that apply to your organization may require different or additional terms. Before you adopt, publish, or rely on this policy, and in every case where you have a legal, regulatory, or contractual obligation, have it reviewed by qualified legal counsel.

How does the AI Governance Policy generator work?

6 short phases, about 6 minutes in total. Every question is pre-filled with a best-practice answer and the reason we recommend it.

  1. Your organization

    The basics that shape who the policy covers and which obligations it has to respect.

  2. How your organization uses AI

    Your overall stance on AI and which kinds of AI use are allowed at all.

  3. Data protection

    What information may go into AI tools, and what vendors may do with it.

  4. Oversight and risk

    Who is accountable for AI, what needs human review, and which uses are off limits.

  5. Training, incidents and audit

    How staff learn the rules, how problems get reported, and how compliance is checked.

  6. Ownership and review

    Who owns the policy, who approves it, and how it stays current.

  7. Review and download

    Preview your policy, unlock the full document and download it as a PDF with a document ID and review date.

Start the generator

Who should adopt this policy?

  • Owners and executives of small and mid-sized businesses whose staff already use ChatGPT, Copilot, Gemini or other AI tools.
  • IT managers who are asked about AI controls in security questionnaires, audits, or customer contract reviews.
  • Manufacturers, contractors, distributors and professional services firms that handle customer designs, bids and confidential data.
  • Defense contractors protecting CUI, and healthcare or financial organizations handling regulated data.
  • Organizations piloting AI agents or customer-facing chatbots that need guardrails before they scale.

Which frameworks does this template align with?

The template was written against these public frameworks, laws and standards. Alignment is not certification, and your obligations depend on your industry and location.

Framework or lawWhy it matters for this policy
NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1)(opens in a new tab)The policy structure, roles and guiding principles map to the AI RMF Govern, Map, Measure and Manage functions and its seven trustworthiness characteristics.
NIST AI 600-1, Generative Artificial Intelligence Profile(opens in a new tab)Informs the rules on confabulation (hallucination), data privacy, information security and content provenance for generative AI tools.
ISO/IEC 42001:2023, AI management systems(opens in a new tab)The international management system standard for AI; the inventory, risk assessment, audit and review cycle in this policy follow its structure.
OWASP Top 10 for LLM Applications (2025)(opens in a new tab)The security section addresses its leading risks, including prompt injection, sensitive information disclosure, improper output handling and excessive agency.
European Commission, AI Act regulatory framework(opens in a new tab)Official application timeline for the EU AI Act, including prohibited practices, AI literacy and transparency duties that can reach U.S. companies.
U.S. Copyright Office, Copyright and Artificial Intelligence(opens in a new tab)Basis for the intellectual property section: AI output is protected by copyright only where a human author determined sufficient expressive elements.

AI Governance Policy questions, answered

Does a small business need an AI policy?

Yes, if anyone in the business uses AI for work, and most already do. Microsoft found that 78% of AI users bring their own AI tools to work, rising to 80% at small and medium-sized companies. Without a written policy, company and customer data can end up in consumer tools whose terms may allow the provider to keep it or train on it. A short, enforced policy with a list of approved tools closes most of that gap.

What should an AI governance policy include?

At minimum: scope, definitions, roles and accountability, how AI tools are approved and inventoried, acceptable and prohibited uses, which data may and may not be entered, human review of AI output, transparency to customers, security controls for AI and AI agents, training, incident reporting, and audit. It should name an accountable owner and be approved by an executive so it is enforceable.

Is an AI policy legally required?

No federal law requires most private U.S. businesses to adopt a written AI policy, but specific AI laws can apply. The EU AI Act prohibitions and AI literacy provisions have applied since February 2, 2025 to organizations in its scope, including some U.S. companies whose AI output is used in the EU. Colorado SB 26-189, signed May 14, 2026, regulates automated decision-making technology used in consequential decisions such as employment, lending and housing from January 1, 2027. Existing privacy, anti-discrimination, consumer protection and contract obligations already apply to AI use, so have counsel confirm what applies to you.

How often should an AI policy be reviewed?

Review an AI policy at least every six months, which is more often than most IT policies, because AI tools, vendor terms and AI laws change quickly. Also review it after an AI incident, before adopting a new category of AI such as agents or customer-facing chatbots, and when a new law or customer contract requirement applies. Record every revision and re-approval.

What is the NIST AI RMF?

The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) is a free, voluntary framework released by the U.S. National Institute of Standards and Technology on January 26, 2023. It organizes AI risk work into four functions: Govern, Map, Measure and Manage. NIST added a Generative AI Profile, NIST AI 600-1, on July 26, 2024 to address risks specific to generative AI.

What is the difference between AI governance and an AI acceptable use policy?

An AI governance policy sets how the organization as a whole decides about AI: who approves tools, how risk is assessed, what is inventoried, audited and reported. An AI acceptable use policy is the employee-facing subset: what staff may and may not do with AI day to day. Most small businesses benefit from one governance policy that contains the acceptable use rules, plus a short acknowledgment each employee signs.

How do you stop employees from using unapproved AI tools?

Give them an approved alternative first, because blocking without one pushes use onto personal phones. Then license business-grade AI tools with data protection terms, block or monitor unapproved AI services with web filtering and cloud app discovery, and train staff on why the rules exist. IBM found that one in five organizations reported a breach due to shadow AI, and only 37% had policies to manage AI or detect shadow AI.

Can employees use ChatGPT or other AI chatbots at work?

They can when the company approves the tool and licenses a business or enterprise plan whose terms exclude company data from model training and give administrators control over accounts and retention. Consumer and free plans often allow the provider to use conversations to improve its models unless a user opts out. The policy should say which tools are approved, what data each may process, and that output must be reviewed before it is relied on.

Related policy templates

Services that put this policy into practice

Want help rolling out your AI Governance Policy?

A policy works when the tools, training and controls behind it do. Preferred Data Corporation helps North Carolina businesses put policies like this one into practice, from High Point since 1987.