AI acceptable use policy examples are most useful when they show what an employee can do after reading the rule. “Use AI responsibly” sounds sensible, but it gives very little help to someone deciding whether they can paste a customer document into an AI tool.
A workable generative AI acceptable use policy connects each rule to an outcome. The employee can proceed, proceed with safeguards, request approval from a named role, choose another method, or provide more information.
The examples below are written as starting points. The wording, information categories, approved tools, reviewers, and prohibited uses should reflect your organisation’s contracts, systems, jurisdictions, and professional advice.
Example 1: approved tools and company-managed accounts
Policy wording
Employees may use an AI service for company work only when the service has been approved for that purpose. Where the company provides a managed account, company work must use that account. Ask the security team when the tool or account status is unclear.
Employee request
An employee wants to summarise internal meeting notes using a personal ChatGPT account. The company has approved the enterprise workspace for internal material.
Useful outcome
Use the approved company-managed account. The proposed use can continue after the employee moves the work to that account and confirms that the information category is permitted there.
This example separates the product from the account. The same AI service can have different contractual terms, administrative controls, retention settings, and approved uses across account types.
Our guide to personal AI accounts at work covers the questions a policy owner should resolve before permitting them.
Example 2: confidential and customer information
Policy wording
Do not enter confidential company information, customer information, personal data, credentials, security details, or unreleased source code into an AI service unless the company has explicitly approved that information category for the selected tool and account. Remove protected information where the task can be completed without it.
Employee request
A salesperson wants an AI assistant to improve a proposal. The draft contains the customer’s pricing, contact details, and planned launch date.
Useful outcome
The employee must either remove the protected details or use an approved service and account whose permitted information categories cover them. If neither route applies, the checker should stop the proposed use and explain who can review an exception.
A rule like this needs company-specific definitions. Employees should see examples of what the organisation considers confidential, restricted, or safe for approved AI tools. The confidential-information guide explains why deleting a person’s name may still leave sensitive context behind.
Example 3: drafts and human review
Policy wording
AI-generated drafts must be reviewed by a person who understands the subject and can correct, reject, or replace the output before it is relied upon. The reviewer remains responsible for the final work.
Employee request
An employee uses AI to draft an internal training outline and plans to check every section before sharing it with colleagues.
Useful outcome
Proceed with complete human review. The result should remind the employee to check factual claims, confidential information, sources, and any company-specific requirements before use.
“Human in the loop” is too vague for an operational policy. The company should define whether review means reading the complete output, checking selected parts, or merely being able to intervene. Those states can produce different policy answers.
Example 4: material sent outside the company
Policy wording
AI-assisted material intended for customers, applicants, regulators, the public, or another external audience requires review under the same standards as material created without AI. High-impact, legally significant, safety-related, or contractual communications require approval from the responsible role before release.
Employee request
A support employee wants AI to draft a reply about an ordinary product setting. A second employee wants it to draft a response promising a customer compensation under a contract.
Useful outcomes
The ordinary support draft may proceed after the required review. The contractual commitment should go to the authorised reviewer before it is sent.
The policy should distinguish assistance from authority. An AI tool can help prepare text, while the company decides who can make a promise, publish a statement, or communicate a regulated conclusion.
Example 5: employment and other important decisions
Policy wording
Employees must obtain approval before using AI to rank, recommend, screen, or materially influence decisions about recruitment, employment, access to services, credit, insurance, health, legal rights, safety, or another significant interest. The approval must identify the permitted purpose, information, reviewer, safeguards, and period of use.
Employee request
A hiring manager wants an AI tool to rank applicants from their CVs. The company has approved AI for drafting job descriptions but has no approved hiring-decision use.
Useful outcome
Approval required. The request should reach the company’s named HR, legal, privacy, or governance owner with the proposed tool, data, purpose, and review arrangement already attached.
A policy checker should avoid inventing a legal conclusion here. It can apply the company’s approved boundary, route the request, and preserve what was decided under the current policy version.
Example 6: training or improving an external model
Policy wording
Company information may not be used to train, fine-tune, evaluate, or otherwise improve an external AI model unless the company has approved the provider, information, purpose, access, retention, intellectual-property terms, and responsible owner.
Employee request
An engineering team wants to upload resolved customer tickets to improve a third-party support model.
Useful outcome
Approval required before the upload. The checker should name the team responsible for reviewing the provider and data use instead of returning a generic instruction to “contact the business.”
Training deserves its own policy route because it can involve a longer-lived use of company information than an ordinary one-time prompt.
Example 7: unlisted tools or unclear facts
Policy wording
When the selected tool, account, information category, region, or intended use is unclear or absent from this policy, pause the proposed use and ask the policy owner. Do not treat a missing rule as approval.
Employee request
An employee discovers a new browser-based AI service. They do not know whether the company has reviewed it or where submitted information is processed.
Useful outcome
More information needed. The employee should receive a short list of missing facts and a named contact rather than having to guess whether the service is allowed.
This route matters because no AI usage policy template can predict every product and use. A policy still needs a defined response when reality falls outside its current choices.
A compact AI acceptable use policy template
The following structure can be adapted into a first working policy:
Purpose
This policy explains how employees and contractors may use AI for company work, which safeguards apply, and when approval is required.
Scope
The policy applies to company work performed through public, personal, company-managed, embedded, or internally operated AI systems.
Approved tools and accounts
Company work may use the tools, account types, and purposes listed in the approved register. Company-managed accounts are required where specified. Unlisted tools require review before use.
Permitted information
The company defines which information categories each approved tool may receive. Public, internal, personal, confidential, highly sensitive, credential, and security information should have clear examples and explicit treatment.
Permitted purposes
List the activities employees may perform, such as brainstorming, drafting, summarising, translation, coding assistance, research, or analysis. State any safeguards or approval routes attached to each purpose.
Human review
Define what review must happen before an output is relied upon, shared, published, or used in a decision. Name the person or role responsible for higher-impact work.
Restricted and prohibited uses
Identify the uses that require approval and those the company will not permit. Include high-impact decisions, external commitments, sensitive information, automated actions, model training, and any company-specific boundaries that apply.
Questions and approvals
Name the team or individual who receives questions and approval requests. Explain what information the employee must provide and how the final decision will be recorded.
Version and review
Give every published policy an effective date and version. Preserve completed decisions under the version that produced them, then publish policy changes as new versions.
This template is intentionally compact. The workplace AI policy checklist covers the policy sections in more detail, while the AI-use request form guide explains which facts to collect from an employee.
Turn the wording into a usable employee decision
A document can contain excellent rules and still leave the employee searching for an answer. The operational layer should ask only the facts that can change the result:
- the proposed task and intended result;
- the AI tool and account;
- the most sensitive information involved;
- how the output will be used;
- what human review will happen; and
- which people or regions the work affects.
The company’s current policy can then return a direct outcome and preserve the completed check with its exact policy version. If approval is required, the same request can reach the named reviewer without starting again in email or chat.
Create a Can I Use AI? workspace to configure a workplace policy, turn it into an employee-facing check, and retain the decisions produced under each published version.
These examples provide general operational guidance. Your organisation should adapt the wording with the legal, privacy, security, employment, contractual, and sector-specific advice relevant to its work.