FREE TEMPLATE
AI Acceptable Use Policy
Which AI tools your people can use, what they can put into them, and who checks what comes out. Written for a business with no IT department, with a signature block at the end.
[COMPANY NAME]
Effective date: [DATE] · Owner: [NAME, TITLE] · Review: every six months, or when an approved tool changes its terms
Purpose
This policy sets out which AI tools may be used for [COMPANY NAME] work, what information may be put into them, and who is responsible for what comes out. It exists so that nobody has to guess, and so that client and company information does not end up somewhere the company never agreed to send it.
Scope
This policy applies to every employee, contractor, temporary worker, intern and vendor who does work for [COMPANY NAME], on company devices and on personal devices used for company work.
It covers any tool that uses AI to write, summarize, translate, analyze, record or act: chat assistants; AI features built into software the company already uses, such as email, the office suite, accounting software and the browser; meeting recorders and note takers; browser extensions; and AI agents or automations that take actions in company systems.
Approved tools
Only the tools listed here may be used for company work, and only through the account shown.
| Tool | Account or plan | Approved for | Owner |
|---|---|---|---|
| [TOOL] | [COMPANY ACCOUNT OR PLAN] | [PUBLIC, INTERNAL OR RESTRICTED] | [NAME] |
| [TOOL] | [COMPANY ACCOUNT OR PLAN] | [PUBLIC, INTERNAL OR RESTRICTED] | [NAME] |
| [TOOL] | [COMPANY ACCOUNT OR PLAN] | [PUBLIC, INTERNAL OR RESTRICTED] | [NAME] |
Sign in with your company account. Personal accounts and free plans are not approved for company work, even for a tool that is on the list. Many consumer plans allow the provider to use what you type to train its models, and the company has no way to see, keep or delete what was entered there.
An AI feature that appears inside software the company already uses is still a new tool. It needs to be on the list before you use it with company information.
To request a new tool, ask [POLICY OWNER OR IT PROVIDER]. Before a tool is approved, they confirm in writing whether the provider trains on what is entered, how long it is kept, who at the provider can see it, whether it can be deleted, and whether sign-in supports multi-factor authentication.
What may go into an AI tool
Information falls into three groups.
Public. Anything the company has already published or that is freely available. It may be used in any approved tool.
Internal. Day-to-day business information that is neither public nor restricted: drafts, internal procedures, meeting agendas, general correspondence. It may be used in approved tools on a company account.
Restricted. It may be entered only in a tool the table above approves for restricted information, and nowhere else:
- Client or customer personal information: Social Security numbers, dates of birth, tax returns, financial account numbers, health information
- Employee records: payroll, medical, disciplinary
- Anything covered by a contract, NDA or professional rule that limits who may see it
- [OTHER RESTRICTED INFORMATION]
Never, in any tool. Passwords, access codes, recovery keys, API keys and payment card numbers do not go into an AI tool, approved or not.
Removing a name does not make information anonymous. If the details could identify a person or a client, it is still restricted.
If you are not sure which group something belongs in, treat it as restricted and ask.
Checking what comes out
AI tools produce text that reads well and can still be wrong. They invent facts, figures, citations and quotes, and they state them with confidence.
If you use it, you own it. Work produced with an AI tool is your work, and you are responsible for it exactly as if you had written every word.
Before anything produced with AI leaves the company, a person checks every fact, number, date, name and citation against its source. That applies to client letters, proposals, reports, filings, invoices and anything sent to a regulator, court or insurer.
AI output may inform a decision about hiring, discipline, pay, credit or a client’s eligibility for a service. It may not be the decision. A named person makes it and can explain it.
Meeting recorders and note takers
Use only the approved recorder, and tell everyone on the call that it is running before it starts. Some states require every participant’s consent to be recorded. If anyone objects, turn it off.
Do not let a personal note-taking tool join a company or client meeting.
Recordings, transcripts and summaries are company records. They are stored in [APPROVED LOCATION], kept according to the Data Retention and Disposal Policy, and not forwarded outside the company without the approval of the person who ran the meeting.
Turn the recorder off for conversations involving legal advice, personnel matters or anything a client has asked to keep off the record.
AI that takes actions
Some AI tools do more than answer questions. They can send email, change records, move files or act in other systems on their own. These need more control, not less.
An AI tool or automation that takes actions in company systems must:
- Be approved in writing by [POLICY OWNER] before it is connected to anything
- Run under its own account, never a person’s login, with access to only what its job needs
- Have a named person who is responsible for it
- Keep a record of what it did
- Wait for a person’s approval before [ACTIONS THAT REQUIRE APPROVAL], for example sending email outside the company, paying an invoice, changing payment details or deleting data
Do not connect an AI tool to company email, files, calendars or client systems through a plug-in, connector or browser extension without approval from [POLICY OWNER OR IT PROVIDER].
Client and contract limits
Some client contracts, insurance policies and professional rules restrict the use of AI on their work, or require that it be disclosed. [POLICY OWNER] keeps the list of clients and engagements where limits apply in [LOCATION OF LIST]. Where a client has said no, the answer is no, whatever this policy otherwise allows.
Do not enter another party’s copyrighted or licensed material into an AI tool beyond what the license allows.
Accounts and history
AI accounts follow the Password and Authentication Policy: company sign-in, multi-factor authentication, no shared logins.
Prompts, uploads and chat history in a company AI account are company data. They may be reviewed, retained and produced like any other company record. When someone leaves, their AI accounts are closed or reassigned along with the rest of their access.
When something goes wrong
Tell [POLICY OWNER OR IT PROVIDER] right away if restricted information was entered into a tool that is not approved for it, if AI-produced work containing an error went to a client, or if an AI tool did something it was not supposed to do.
Reporting quickly is never the violation. Hiding it is. Some of these events are security incidents and are handled under the Incident Response Plan.
Responsibilities
Everyone is responsible for reading this policy, following it, checking their own AI-assisted work, and reporting anything that looks wrong.
Managers are responsible for making sure their people have read it, and that the tools their team uses are on the approved list.
[POLICY OWNER OR IT PROVIDER] is responsible for keeping the approved list current, reviewing each approved tool’s terms every [NUMBER] months, and removing AI accounts when someone leaves.
Exceptions
Exceptions must be requested in writing from [POLICY OWNER] and, if granted, documented with a business reason, a scope and an expiration date. An undocumented exception is a violation.
Enforcement
Violations may result in loss of access and disciplinary action up to and including termination. Violations that involve illegal activity may be referred to law enforcement.
Review
This policy and the approved tool list are reviewed every six months by [POLICY OWNER], and whenever an approved tool changes its terms, its features or the plan the company is on. AI tools change faster than most software. A list that was right in the spring may not be right in the fall.
Acknowledgment
I have read and understood the [COMPANY NAME] AI Acceptable Use Policy, and I agree to follow it.
Name: ______________________________
Signature: __________________________
Date: ______________________________
Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your state’s employment law. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.
EDITABLE VERSION
Want the Word version you can edit?
The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the signature block ready for your team to sign. Tell us where to send it.
Free. About 20 seconds.
Where should we send it?
THE REST OF THE SET
The rest of the set, and someone to run them.
This is one of our free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.
A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.
