What should an AI acceptable use policy include?
An AI acceptable-use policy is the short, employee-facing rulebook for AI at work. It names the approved AI tools and requires company-managed accounts, lists data that must never go into AI, says when a human must review AI output, explains how to request a new tool and how to report mistakes. Keep it to about two pages, backed by your broader AI governance policy.
How it differs from an AI governance policy
Your AI governance policy is the internal standard leadership and IT own: accountability, vendor review, risk management and controls. The acceptable-use policy is the part every employee reads and signs. It should be plain enough to follow without training and short enough that people actually finish it.
NIST's AI Risk Management Framework, which is voluntary, places policies like this under its Govern function. NIST says the framework is being revised, so tie your policy to its four functions, Govern, Map, Measure and Manage, rather than to one version's wording.
A short outline you can adapt
- 1. Purpose and scope: employees, contractors, and AI features inside software you already license.
- 2. Approved tools: a named list, used only through company-managed accounts with single sign-on. Personal AI accounts are not used for company work.
- 3. Data rules: what may go into each approved tool by classification level, and what never goes into any AI tool, such as regulated health data, CUI, export-controlled data, credentials and unpublished inventions, unless a specific environment is approved for it.
- 4. Human review: AI output must be checked by a person before it reaches customers, contracts, regulators, code in production or regulated records.
- 5. Transparency: when to disclose that content was AI-assisted.
- 6. New tools: how to request one, and that nothing is used before approval.
- 7. Reporting: who to tell, and how fast, if data goes to the wrong tool or an output causes harm.
- 8. Consequences and review date: how violations are handled, and when the policy is next reviewed.
- 9. Acknowledgment: signed at onboarding and after material changes.
Why the approved-account rule comes first
The biggest practical risk is company data in personal AI accounts. OpenAI's help center, for example, says it may use content from its services for individuals to train models unless the user opts out, while by default it does not train on ChatGPT Business, Enterprise, Edu or API data. A company account also gives you an admin console and the ability to remove access.
Make it enforceable
Back each rule with a control where you can: single sign-on for approved tools, sensitivity labels on confidential data, and data loss prevention. Microsoft states that onboarded Windows devices can warn or block users sharing sensitive information with third-party generative AI sites. Review the approved-tool list quarterly and the policy at least annually.
Common follow-up questions
Should an AI acceptable use policy ban ChatGPT?
Usually not outright. Bans tend to push use onto personal phones and accounts you cannot see. A better approach is to approve a company-managed AI tool, prohibit personal accounts for work, and state which data may never be entered into any AI tool.
Who should sign the AI acceptable use policy?
Every employee and contractor who uses company systems, at onboarding and again after significant changes. Keep a simple record of acknowledgments. The policy itself should be approved by the senior leader accountable for AI governance, with IT and legal review.
How is this different from our AI governance policy?
The governance policy sets ownership, vendor review, risk management and controls for leadership and IT. The acceptable-use policy translates that into a short set of rules every employee follows day to day. You need both, and they must not contradict each other.
LAN Service Group drafts AI acceptable-use policies for small and mid-size businesses and implements the single sign-on, labeling and data loss prevention controls that make them enforceable.
Talk to LAN Service Group (888) 281-7243