AI policy template for employees and enterprise teams
An AI policy tells people which tools they may use, what data they may share and when a person must review the work. Paul Okhrem's editable template covers staff use and agent workflows. It is a starting document for your own approval process, not legal advice or proof of compliance. Read it below or download it without giving your email.
Before you adopt this template
Choose the accountable executive, policy owner, incident channel and approval process. Add your actual tool register, data classifications and review date. Have security, privacy, HR and qualified legal advisers review the text against your business and contracts.
Do not label an unapproved draft as company policy. A useful policy needs a working approval route and people who can answer questions.
Editable AI acceptable-use policy
1. Purpose and scope
This policy sets the rules for using AI in company work. It applies to employees, contractors and suppliers who handle company information. It covers approved AI tools, embedded AI features and automated agent workflows.
2. Approved tools and uses
Use only tools and use cases approved in the company's AI register. The system owner records the purpose, permitted users, data categories and operating limits. Request approval before enabling a new AI feature or connecting a new data source.
3. Data handling
Use public or approved internal data only within the tool's permitted data classification. Do not enter passwords, secrets, restricted personal information or confidential client material unless the approved configuration and contracts expressly allow that use. Minimize the data needed for the task.
4. Human review
The person using an AI output remains responsible for the work they submit. Check important facts, calculations, sources and instructions. A qualified person must approve consequential decisions and externally published work under the relevant review process.
5. Disclosure
Tell the recipient when law, contract or company policy requires disclosure of AI use. Do not present generated evidence, invented sources or synthetic identities as genuine. Follow the company's approved rules for customer-facing AI and synthetic content.
6. Prohibited uses
Do not bypass access controls, impersonate people, create deceptive material or use AI for unlawful discrimination. Do not let an agent make unapproved payments, delete records or take other actions outside its documented permissions. Stop any use that conflicts with law or contract.
7. Intellectual property
Use material that the company is entitled to process. Check licensing and customer restrictions before uploading documents or publishing output. Escalate uncertainty about ownership, reuse or infringement to the designated legal reviewer.
8. Security and agents
Use approved accounts and access controls. Do not connect personal credentials or unapproved plugins. Agent owners must define allowed tools, data boundaries, approval gates, spending limits, logs and a tested stop procedure.
9. Training and support
Complete role-appropriate training before using an approved system. Know the tool's limits, the review process and how to report a problem. Managers provide an alternative process when AI is unavailable or unsuitable.
10. Incidents and escalation
Stop the affected workflow when safe to do so and report suspected data exposure, unauthorized actions or harmful output through the internal incident channel immediately. The proposed internal reporting target is within 24 hours; separate legal or contractual deadlines may be shorter. Preserve relevant evidence without spreading sensitive data.
11. Ownership and review
The accountable executive approves the policy. The AI governance owner maintains it with security, privacy, legal and business teams. Review it at least every six months and after material incidents, tool changes or changes in applicable rules.
12. Acknowledgment and exceptions
Record acknowledgment through the company's normal policy process. Document exceptions with a named approver, reason, controls and expiry date. An exception cannot waive a legal obligation or a customer contract.
How to roll out the policy
- Find the real use cases. Include embedded AI and personal tools currently used for work.
- Offer a usable approved route. Give staff tools and examples that meet their actual tasks.
- Train by role. A support agent, engineer and finance approver need different examples.
- Keep an exception register. Time-limit each exception and review its evidence.
- Measure behavior. Review recurring incidents, unapproved-tool requests and whether staff understand escalation.
The AI governance framework defines who makes these decisions. The agentic AI governance guide adds controls for systems that can take actions.
Policy, legal duties and evidence
Workplace policy is not the same as legal compliance. Confirm the organization's role, system purpose and applicable law. The European Commission's July 2026 AI Omnibus notice describes changes to AI-literacy provisions, so do not rely on older blanket statements about mandatory training.
Use the EU AI Act compliance checklist to organize questions for legal review. Keep training that staff need to use systems responsibly, even where the precise legal duty differs.
When to ask Paul Okhrem for help
Paul Okhrem's AI governance consulting connects the policy to inventory, approvals, risk reviews and evidence. Executive AI training helps leaders make decisions about permitted use and ownership.
This template and its original wording are available under CC BY 4.0. Attribute Paul Okhrem and identify your changes. Linked third-party sources retain their own rights.
Questions about ai policy template for employees and enterprise teams
Can we edit the AI policy template for our business?
Yes. Add your actual tools, owners, data rules and reporting process, then obtain internal and legal approval. Attribute the original template and identify changes.
Does downloading the template enroll me in marketing?
No. The files are ungated downloads. No email address or enquiry is needed.
Is this an EU AI Act compliance certificate?
No. A policy is one operating document. It does not determine legal classification, complete a conformity assessment or certify compliance.
Change log
- : Reviewed copy, source boundaries and supporting resources.
Send a private brief to Paul Okhrem

Paul Okhrem reads every brief personally and replies within two business days. Start with the decision, its owner and the deadline. You will get an honest no if the fit is wrong, with a referral when possible.
Co-Founder and CEO of Elogic Commerce; Managing Partner at Uvik Software. Company experience is not a guarantee of a consulting result. Read the background and published terms.