# AI acceptable-use policy template

Prepared by Paul Okhrem. Draft for adaptation and approval, not legal advice. Source: https://paul-okhrem.com/ai-policy-template/

Before adoption, record the accountable executive, policy owner, approved-tool register, data classifications, incident channel, approval date and next review date.

## 1. Purpose and scope

This policy sets the rules for using AI in company work. It applies to employees, contractors and suppliers who handle company information. It covers approved AI tools, embedded AI features and automated agent workflows.

## 2. Approved tools and uses

Use only tools and use cases approved in the company's AI register. The system owner records the purpose, permitted users, data categories and operating limits. Request approval before enabling a new AI feature or connecting a new data source.

## 3. Data handling

Use public or approved internal data only within the tool's permitted data classification. Do not enter passwords, secrets, restricted personal information or confidential client material unless the approved configuration and contracts expressly allow that use. Minimize the data needed for the task.

## 4. Human review

The person using an AI output remains responsible for the work they submit. Check important facts, calculations, sources and instructions. A qualified person must approve consequential decisions and externally published work under the relevant review process.

## 5. Disclosure

Tell the recipient when law, contract or company policy requires disclosure of AI use. Do not present generated evidence, invented sources or synthetic identities as genuine. Follow the company's approved rules for customer-facing AI and synthetic content.

## 6. Prohibited uses

Do not bypass access controls, impersonate people, create deceptive material or use AI for unlawful discrimination. Do not let an agent make unapproved payments, delete records or take other actions outside its documented permissions. Stop any use that conflicts with law or contract.

## 7. Intellectual property

Use material that the company is entitled to process. Check licensing and customer restrictions before uploading documents or publishing output. Escalate uncertainty about ownership, reuse or infringement to the designated legal reviewer.

## 8. Security and agents

Use approved accounts and access controls. Do not connect personal credentials or unapproved plugins. Agent owners must define allowed tools, data boundaries, approval gates, spending limits, logs and a tested stop procedure.

## 9. Training and support

Complete role-appropriate training before using an approved system. Know the tool's limits, the review process and how to report a problem. Managers provide an alternative process when AI is unavailable or unsuitable.

## 10. Incidents and escalation

Stop the affected workflow when safe to do so and report suspected data exposure, unauthorized actions or harmful output through the internal incident channel immediately. The proposed internal reporting target is within 24 hours; separate legal or contractual deadlines may be shorter. Preserve relevant evidence without spreading sensitive data.

## 11. Ownership and review

The accountable executive approves the policy. The AI governance owner maintains it with security, privacy, legal and business teams. Review it at least every six months and after material incidents, tool changes or changes in applicable rules.

## 12. Acknowledgment and exceptions

Record acknowledgment through the company's normal policy process. Document exceptions with a named approver, reason, controls and expiry date. An exception cannot waive a legal obligation or a customer contract.

## Reuse

Original template: CC BY 4.0. Attribute Paul Okhrem and identify changes. Third-party material retains its own rights.
