AI Governance

AI Acceptable Use Policy Template: A Company AI Policy You Can Copy (2026)

A company AI policy you can copy and adapt: model wording for approved and prohibited tools, data classification, human review, customer disclosure under EU AI Act Article 50, AI literacy under Article 4, confidentiality, incident reporting, exceptions and review, with a rollout plan and a one-page checklist.

An AI acceptable use policy is a company's rulebook for everyday AI use: which tools staff may use, what data may go into them, when a person must check the output, how AI use is disclosed to customers, what training staff receive, and how problems are reported. The template below gives model wording for each clause, ready to copy and adapt.

What a company AI policy needs to cover

Most organisations already use AI daily, approved or not: chat assistants, meeting summaries, coding tools and AI features switched on inside existing software. An acceptable use policy turns that into a bounded practice, and stays short so that staff remember it.

ClauseWhy it is thereRule it helps you meet
Purpose, scope and rolesSays who is bound and who decidesInternal accountability
Approved and prohibited toolsKeeps company data out of unvetted servicesGDPR Art. 28 processor terms
Data classificationMaps each class of information to the tools allowed to receive itGDPR Art. 5(1)(c) and Art. 9
Human reviewKeeps a person responsible for decisions and published workGDPR Art. 22
DisclosureTells people when they deal with AIEU AI Act Art. 50, applicable since 2 August 2026
AI literacyGives staff the knowledge to use AI safelyEU AI Act Art. 4, applicable since 2 February 2025
IP and confidentialityProtects trade secrets, client material and third-party rightsContracts and confidentiality duties
Incident reportingGets leaks and errors to the right team fastGDPR Art. 33 breach notification
Exceptions, enforcement, reviewKeeps the policy credible and currentInternal governance

The AI acceptable use policy template

Copy each block into your own policy format. Replace the bracketed placeholders, such as [Company] and [AI governance lead], and delete clauses that do not apply. This is a starting draft for your legal, privacy, security and HR teams to review, not legal advice.

1. Purpose, scope and roles

1. PURPOSE, SCOPE AND ROLES

1.1 Purpose. This policy sets the rules for using artificial
    intelligence (AI) tools at [Company], so that staff can use AI
    productively while protecting customers, colleagues, confidential
    information and personal data.

1.2 Scope. It applies to all employees, contractors, temporary staff
    and anyone else who uses AI tools for [Company] work, on any
    device, including AI features built into software we already
    license.

1.3 Definition. An "AI tool" is any system that generates text, code,
    images, audio, video, summaries or recommendations from a prompt
    or other input, including chat and coding assistants, meeting
    summary features and AI agents that act in other systems.

1.4 Roles.
    - Policy owner: [AI governance lead / CIO] maintains this policy
      and the Approved AI Tools Register.
    - AI review group: [members from IT security, privacy (the data
      protection officer), legal and the business] approves new
      tools, new uses and exceptions.
    - Managers make sure their teams know and follow this policy.
    - Users follow this policy, complete the required training and
      report concerns.

2. Approved and prohibited AI tools

2. APPROVED AND PROHIBITED AI TOOLS

2.1 Approved tools only. Use only the AI tools listed in the Approved
    AI Tools Register, with the accounts and settings stated there.
    Do not use personal AI accounts for [Company] work.

2.2 Approval. A new AI tool, or a new use of an approved tool, needs
    approval from the AI review group before use. The review covers
    security; data protection, including a data processing agreement
    and, where needed, a data protection impact assessment; where
    data is processed and stored; whether the vendor trains models on
    our data; retention; and contract terms.

2.3 Prohibited uses. Unless the register says otherwise, you must not:
    - use free or consumer versions of AI tools for [Company] work;
    - install AI browser extensions, plug-ins or agents that can read
      company data;
    - connect an AI tool to company email, files, code repositories
      or business systems without approval;
    - use AI to make decisions about a person's employment, credit,
      insurance, access to services or legal rights without the
      review in section 4;
    - use AI to impersonate a real person or to create misleading
      content about real people or organisations;
    - try to bypass the safety controls of an AI tool or our own
      security controls.

2.4 Embedded AI features. AI features that vendors add to software we
    already use count as new tools. They stay switched off until the
    AI review group has reviewed them.

For the review in clause 2.2, our 13-point GDPR check for AI tools lists the questions to send each vendor.

3. Data classification: what may go into which tool

Data classExamplesApproved external AI toolsInternal AI on [Company] infrastructure
PublicPublished marketing copy, public web contentAllowedAllowed
InternalInternal procedures, non-sensitive project notesOnly tools approved for Internal dataAllowed
ConfidentialCustomer records, contracts, financials, unreleased plans, source codeOnly tools approved for Confidential data, with training off and the agreed processing regionAllowed
RestrictedSpecial-category personal data, privileged material, credentials, security detailsNeverOnly systems approved for Restricted data
3. DATA RULES: WHAT MAY GO INTO WHICH TOOL

3.1 Classify before you paste. Before entering information into an
    AI tool, check its class under the [Information Classification
    Policy] and the table above. If unsure, treat it as Restricted.

3.2 Never into an external AI tool. The following must never be
    entered into an AI tool hosted outside [Company]'s infrastructure:
    - passwords, API keys, tokens or other credentials;
    - special categories of personal data (health, genetic or
      biometric data, racial or ethnic origin, political opinions,
      religious or philosophical beliefs, trade union membership,
      sex life or sexual orientation) and data about criminal
      convictions or offences;
    - legally privileged material, and client material that the
      client's contract does not allow us to process this way;
    - details of unpatched vulnerabilities or open security
      incidents;
    - data that a contract, licence or law requires us to keep in a
      specific location or system.

3.3 Minimise. Share only what the task needs. Remove names and other
    identifiers whenever the task can be done without them.

3.4 Personal data. Use personal data in AI tools only for purposes
    already covered by our records of processing and privacy
    notices, and only in tools covered by a data processing
    agreement. A new purpose needs the privacy team's approval first.

4. Human review of AI output

4. HUMAN REVIEW OF AI OUTPUT

4.1 You own the result. AI output is a draft. The person who uses it
    is responsible for checking facts, figures, sources, code and
    tone before relying on it or sharing it.

4.2 Mandatory review. A qualified person must review and approve AI
    output before it is:
    - sent to a customer, regulator, court or the public;
    - used in a contract, financial report or legal advice, or in a
      medical or safety-relevant context;
    - merged into production code or used to change production
      systems.

4.3 Decisions about people. AI must not be the sole basis for a
    decision with legal or similarly significant effects on a
    person, such as hiring, dismissal, credit or access to a service.
    A person with authority to change the outcome makes the decision
    and records the reasons.

4.4 AI agents. Agents may act (send messages, update records, start
    payments, change systems) only within approved permissions.
    Actions with financial, legal or customer impact need human
    approval before they run.

5. Disclosure to customers and the public

5. DISCLOSURE TO CUSTOMERS AND THE PUBLIC

5.1 AI interactions. Any AI system that talks or writes to customers
    or the public on [Company]'s behalf must tell people they are
    dealing with AI, clearly and at the latest at the first
    interaction, unless that is obvious from the context.

5.2 Synthetic media. AI-generated or AI-altered images, audio or
    video that show real people, places or events in a way that could
    pass as authentic must be labelled as AI-generated.

5.3 Published text. Text generated by AI and published to inform the
    public on matters of public interest must be labelled as such,
    unless a person has reviewed it and [Company] takes editorial
    responsibility for it.

5.4 Contracts first. Where a contract or client instruction requires
    us to disclose or limit AI use, that requirement applies in
    addition to this policy.

These clauses follow Article 50 of the EU AI Act, which has applied since 2 August 2026. The Commission published guidelines on it on 20 July 2026, and our Article 50 explainer covers who counts as the provider of an in-house assistant.

6. AI literacy and training

6. AI LITERACY AND TRAINING

6.1 Required training. Everyone in scope completes [Company]'s AI
    training before using approved AI tools for work, with a
    refresher every [12] months. Content differs by role: general
    users, people who build or configure AI tools, and people who
    review AI-assisted decisions.

6.2 Content. How the approved tools work and fail, including
    inaccurate or invented output; the data rules in section 3; the
    review rules in section 4; disclosure duties; and how to report
    incidents.

6.3 Records. The [learning team] keeps an internal record of who
    completed which training and when.

Article 4 of the EU AI Act has applied since 2 February 2025. As amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744, it asks providers and deployers to take measures that support the AI literacy of their staff, without guaranteeing a set level. The Commission’s Q&A says no certificate is needed and that an internal record of training can be kept.

7. Intellectual property and confidentiality

7. INTELLECTUAL PROPERTY AND CONFIDENTIALITY

7.1 Confidentiality applies. Duties of confidentiality in employment
    contracts, client contracts and non-disclosure agreements apply
    to AI tools exactly as they apply to any other third party.

7.2 Trade secrets. Source code, algorithms, formulas, pricing and
    strategy documents go only into tools approved for Confidential
    data.

7.3 Third-party rights. Do not use AI to reproduce copyrighted
    material, trademarks or a person's likeness without permission,
    and check generated code for licence obligations before use.

7.4 Ownership. Work created with AI tools for [Company] belongs to
    [Company] to the extent the law and the tool's terms allow.
    Record significant AI contributions to deliverables where a
    client or contract requires it.

8. Incident reporting

8. INCIDENT REPORTING

8.1 What to report. Report straight away if you:
    - entered data into an AI tool that this policy does not allow;
    - receive AI output that is harmful, discriminatory, defamatory
      or reveals someone else's data;
    - notice an AI agent acting outside its permissions;
    - find an unapproved AI tool in use with company data.

8.2 How. Report to [security contact or ticket queue] within
    [24 hours]. Do not delete evidence while trying to fix the
    problem.

8.3 Personal data breaches. The privacy team decides whether an
    incident is a personal data breach. Under Article 33 of the
    GDPR, a breach must be notified to the supervisory authority
    without undue delay and, where feasible, within 72 hours, unless
    it is unlikely to result in a risk to people's rights and
    freedoms.

9. Exceptions, enforcement and review

9. EXCEPTIONS, ENFORCEMENT AND REVIEW

9.1 Exceptions. Send exception requests to the AI review group in
    writing, with the business reason, the data involved and the
    safeguards proposed. Approved exceptions are time-limited,
    recorded in the register and reviewed when they expire.

9.2 Enforcement. Breaches of this policy are handled under
    [Company]'s disciplinary procedure and can lead to loss of access
    to AI tools. For contractors, contractual remedies apply.

9.3 Review. The policy owner reviews this policy at least every [12]
    months, and sooner when laws, regulator guidance, approved tools
    or our risk profile change.

9.4 Version control. Version [x.y], approved by [name, role] on
    [date]. Next review due: [date].

How to roll out the policy

  1. Find what is already in use. Survey teams and check network logs and expense claims; the result is your first register. An AI inventory and shadow AI discovery exercise gives this step structure.
  2. Approve a usable default first. Configure at least one tool for Internal and Confidential data (training off, retention set, region chosen, access by role) before publishing, so the policy offers a working route alongside its bans.
  3. Agree the data classes with privacy and security, and fill in the section 3 table with real tool names.
  4. Publish with a one-page summary, because most staff will read only that.
  5. Train by role, starting with heavy users and reviewers of AI-assisted decisions, and keep completion records.
  6. Make reporting easy by putting the section 8 channel where people already ask for IT help.
  7. Review after 90 days, using exception requests, incidents and tool requests to adjust the register and the policy.

One-page AI policy checklist

  • A named policy owner and an AI review group with security, privacy and legal members
  • An Approved AI Tools Register listing accounts, settings and permitted data classes
  • Personal and consumer AI accounts banned for company work
  • Four data classes mapped to tools, plus a never-share list for external AI
  • Data processing agreements, and DPIAs where needed, for tools that receive personal data
  • Human review before external, legal, financial, safety-relevant or production use
  • No solely automated decisions with legal or similarly significant effects
  • AI disclosure at the first interaction for customer-facing chatbots and agents
  • Labels for AI-generated images, audio and video of real people or events
  • Role-based AI training with completion records
  • Rules on confidentiality, client contracts, copyright and code licences
  • An incident route with a reporting deadline and a link to breach handling
  • A written exceptions process with expiry dates
  • An annual review date and triggers for an earlier review

Adapting the template for law firms, healthcare and small teams

  • Law firms and professional services. Engagement terms often decide which tools may see client material, so let client data go only into tools the engagement allows, and keep privileged material Restricted.
  • Healthcare and life sciences. Patient data is special-category data under Article 9 of the GDPR, so it stays Restricted.
  • Small businesses. A two-person review group and a shared-document register are enough, but keep the data table and the never-share list intact, since they carry most of the protection.

Draft it with your own details

The AI governance policy generator drafts AI use policies, RACI matrices, approval lifecycles and risk-appetite statements grounded in EU AI Act Article 26 and ISO/IEC 42001, on infrastructure you control. Once the policy sits beside your other policies, the policy review agent reads the set together and reports contradictions, gaps and overdue reviews.

For section 6, the AI compliance training agent delivers role-adaptive Article 4 training with scenario questions, and for section 5 the transparency notice generator drafts plain-language disclosure wording. The Academy lesson on building a governance framework and RACI covers the review group and approval flow behind the policy.

How VDF AI fits

A policy holds when the approved route is easier than the workaround. VDF AI gives staff assistants and agents that run on your own infrastructure, on-premises, in a private cloud or air-gapped, so Confidential and Restricted data can be used with AI without leaving it.

Role-based access control, included on every plan, decides which roles can use which agents, tools and workspaces. Consequential agent steps can wait at a human approval gate, and every prompt, tool call, retrieval and response is recorded with the user and time, which turns sections 2 to 4 of the policy into enforced settings rather than reminders.

Sources

Frequently asked questions

What should an AI acceptable use policy include?

At minimum: purpose, scope and named roles; the approved tools and the uses that are prohibited; data rules that say which classes of information may go into which tools; when a person must review AI output; disclosure to customers when they deal with AI; required training; confidentiality and intellectual property rules; how to report incidents; and an exceptions process, enforcement and a review date. A short summary for staff and a register of approved tools make it workable day to day.

Does the EU AI Act require companies to have an AI policy?

Not in those words. For most companies that use AI, the duties already in force are Article 4, which since February 2025 requires measures to support the AI literacy of staff, and Article 50, which since August 2026 requires AI disclosure in certain situations. The Commission's Q&A says no certificate or specific governance structure is required for AI literacy. A written policy, training records and a tool register are the practical way to show the measures exist. Deployers of high-risk systems take on more duties from December 2027.

Can employees use ChatGPT at work?

Only through an account type and settings the company has approved. OpenAI says it may use content from its services for individuals to train its models unless the user opts out, and that rating a response can bring the whole conversation into training even after opting out. Data from ChatGPT Business, Enterprise, Edu and the API is not used for training by default. A policy should name the approved workspace, ban personal accounts for company work and state which data classes may be entered.

Who should own a company AI policy?

One named owner, usually the CIO, a head of AI or an AI governance lead, supported by a small review group with information security, the data protection officer, legal and a business representative. The owner keeps the policy and the approved tools register current, and the group approves new tools, new uses and exceptions. The European Commission's AI literacy Q&A says no specific governance structure is mandated for Article 4, so size the group to the organisation.

How often should an AI policy be reviewed?

At least once a year, and sooner when something material changes: a new law or regulator guidance, a newly approved tool, a vendor changing its defaults or sub-processors, or a serious incident. Several fixed dates are worth planning around, including the end of the Article 50 marking grace period on 2 December 2026 for generative systems already on the market, and the start of the high-risk obligations for Annex III systems on 2 December 2027.

What is the difference between an AI acceptable use policy and an AI governance policy?

An acceptable use policy speaks to employees: what they may and may not do with AI tools in daily work. An AI governance policy speaks to the organisation: who approves AI systems, how risk is classified, which controls apply at each risk level, and how systems are monitored and retired. Most companies need both, with the acceptable use policy pointing to the governance process for approvals, exceptions and escalation.

Filed under
AI governanceAI policyEU AI ActAI compliancehuman oversightAI security
AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Keep reading