Abstract outshined.io banner

How to Write an AI Acceptable Use Policy (Free Template)

Your employees are almost certainly using AI at work already, whether or not you’ve approved it. Someone is pasting a client email into a free chatbot to “make it sound better.” Someone else installed an AI browser extension that can read every page they open. None of it is malicious, but without clear rules, your company’s data is going places you can’t see.

An AI acceptable use policy fixes that. It doesn’t have to be long or legalistic. A good one fits on three pages and answers three questions: which tools people can use, what information they can put into them, and who is responsible for the output.

Key takeaways

  • Banning AI rarely works. People use it anyway, just out of sight. A clear policy is safer.
  • The core of any policy is a simple data classification: what’s OK to share with AI, what’s limited, and what’s never allowed.
  • Approve specific tools on business plans, with company-owned accounts.
  • People stay responsible for anything AI helps them produce.
  • Free download: editable Word template, ready to customize.

Why “just don’t use it” doesn’t work

Some businesses respond to AI risk with a blanket ban. In practice, that pushes usage underground. Employees use personal accounts on their phones, where you have no visibility, no control over data retention, and no way to help when something goes wrong. IT teams call this shadow AI, and it’s the same problem as shadow IT a decade ago: the risk doesn’t disappear, it just becomes invisible.

A policy that says “yes, with these tools, for this kind of information” gives people a safe path. That’s the path most of them will take.

The heart of the policy: a traffic-light rule for data

Employees won’t memorize a long list of rules, but they will remember three colors. Sort your information into three tiers and tell people which tier each approved tool can handle.

Green: public

OK in any approved tool

Published marketing copy, public web content, general research questions, your own writing with no client or personal details.

Yellow: internal

Business-plan tools only

Internal procedures, non-confidential project notes, anonymized examples, draft documents without client identifiers.

Red: restricted

Never, unless approved in writing

Client confidential data, personal information, ID numbers, passwords and keys, financial accounts, health information, anything under NDA.

Try it yourself. Pick a type of information and see where it lands under a typical policy:

Interactive

Can I paste this into AI?

Choose an example above.

What to include: the 10 sections

The free template below includes every one of these, ready to edit. Here’s what each section does and why it matters.

SectionWhat it covers
1. PurposeSets the tone: you encourage AI use, safely. A positive framing gets better adoption than a list of prohibitions.
2. ScopeWho it applies to (staff, contractors) and what counts as an AI tool, including AI features hidden inside other software and browser extensions.
3. Approved toolsA short table of approved tools, what they may be used for, and which data tier each can handle. Plus how to request a new tool.
4. Information rulesThe green / yellow / red classification above, with concrete examples from your business.
5. Using outputPeople are responsible for what they publish. Verify facts, review before sending to clients, and no fully automated decisions about people.
6. SecurityCompany accounts with multi-factor authentication, no unapproved extensions or integrations, and awareness of AI-powered scams.
7. ReportingHow to report a mistake, like pasting the wrong file, with a no-blame promise so people actually report.
8. TrainingWhat people must complete before using approved tools.
9. ViolationsConsequences, consistent with your other policies.
10. ReviewAI changes fast. Commit to reviewing the policy at least twice a year.

Free download

AI Acceptable Use Policy Template (Word)

All 10 sections, an approved-tools table, the traffic-light data rules and an employee acknowledgment form. Fill in the [brackets] and you’re most of the way there.

Download the template
Not legal advice.This template is a practical starting point. If you work in a regulated industry, such as healthcare, finance or legal, or handle data from the EU or certain U.S. states, have your attorney or compliance advisor review the final version.

The security section most policies forget

Most AI policies focus on what employees put into AI. From an IT and security perspective, three other risks deserve a line in your policy:

  • Browser extensions and “AI helpers.” Many request permission to read everything on every page you visit, including your email and banking. Require approval before installing any of them.
  • Integrations and agents. Connecting an AI tool to your email, file storage or CRM gives it broad access. That decision belongs to whoever manages your IT, not to an individual user.
  • AI-powered scams. Phishing emails no longer have tell-tale spelling mistakes, and voices can be cloned from a short clip. Your policy should require verifying any unusual request for money, credentials or data through a separate, known channel, like calling back on a number you already have.

Is your policy complete?

Checklist

Policy readiness check

0 of 10 complete

How to roll it out in two weeks

  1. Find out what’s already in use. Ask your team, anonymously if needed, which AI tools they use and for what. You’ll learn what to approve, and what to replace.
  2. Pick one or two approved tools on business plans that fit your existing systems. Fewer tools are easier to secure and support.
  3. Customize the template with your tools, your data examples and your contacts. Keep it short.
  4. Hold a 30-minute session to walk through the traffic-light rule with real examples from your business.
  5. Collect signed acknowledgments and set the review date.
  6. Make the safe path easy. Give people logins to the approved tools on day one. If the approved option is harder than a free chatbot, people will use the chatbot.

Frequently asked questions

Do small businesses really need an AI policy?

Yes, and arguably more than large ones. Small teams rarely have a security department watching data flows, so a clear written rule is often the only control in place. It doesn’t need to be long. Three pages is plenty.

Is ChatGPT (or Claude, or Gemini) safe for business use?

It depends on the plan, not just the product. Business and enterprise plans generally offer stronger data protections, admin controls and contractual commitments than free consumer plans. Read the current data terms for the specific plan before approving it, because they change.

What should happen if someone pastes sensitive data by mistake?

They should report it right away, without fear of punishment. Then delete the conversation if the tool allows it, change any exposed passwords or keys, and assess whether clients need to be notified under your contracts or applicable law.

How often should we update the policy?

At least every six months, and whenever you approve a new tool. AI products change their features and data terms frequently.

Next step

Policy done? Put it to work.

With guardrails in place, you’re ready to test AI on a real workflow. Our step-by-step pilot guide shows how to prove it’s worth it in six weeks.

Read the pilot guide