AI security
AI acceptable use policy template your staff can follow
An AI acceptable use policy template gives you a ready set of rules for how staff use AI tools at work: which tools are approved, what data they may enter and when a person must check the output. Copy the policy below, fill in the placeholders and have your legal counsel review it before you publish it.
By the KDS security engineering teamPublished 14 min read
Key takeaways
- The policy sets which AI tools staff may use, what data they may enter and who checks the output.
- In IBM's 2026 breach research, 43% of the organizations studied had security incidents involving shadow AI, up from 20% a year earlier.
- Under Article 4 of the EU AI Act, providers and deployers must support their staff's AI literacy.
- A policy works when staff get an approved alternative, a named owner and clear data classes.
- Review the policy every 6–12 months and after adding a major AI tool or AI agent.
On this page
What is an AI acceptable use policy?
An AI acceptable use policy is a short set of rules that tells staff which AI tools they may use for work, what information they may enter and how to check the output. It covers chat assistants, AI features inside other software and AI agents that act in your systems. Our post on writing an AI usage policy people follow explains how to keep it practical.
Why your company needs an AI policy
Staff often use AI tools before the company approves any. Without written rules, five risks grow:
- Unapproved AI use ("shadow AI"). Staff use AI tools nobody has reviewed. In IBM's 2026 breach research (opens in a new tab), 43% of the organizations studied had security incidents involving shadow AI, up from 20% a year earlier. Our guide to shadow AI shows how to find it.
- Data leaks. Free AI tools may keep what staff type and, depending on their terms, train on it. Customer records or source code pasted into them leave your control.
- Wrong answers. AI tools can invent facts and sources and state them with confidence.
- Intellectual property and confidentiality. A prompt can break an NDA, and your rights to AI output may be limited.
- Regulatory duties. Privacy, employment and AI laws apply to how staff use AI.
In the EU, Article 4 of the AI Act (opens in a new tab) has applied since February 2, 2025. The Digital Omnibus on AI (opens in a new tab), in force since July 27, 2026, rewrote it: companies that build AI systems (providers) and companies that use them at work (deployers) must take measures to support their staff's AI literacy, without guaranteeing a set level for each person.
The European Commission's AI literacy questions and answers (opens in a new tab) say supervision and enforcement apply from August 3, 2026. They add that staff who write or translate with generative AI should learn about risks such as hallucination (confident but made-up answers). A policy plus training records helps you show your measures. Our EU AI Act guide covers the other duties.
What this AI acceptable use policy template covers
The template has 18 sections and is neutral about country and industry. Its core parts are:
- Approved and prohibited tools, with a request process for new ones.
- A data table that shows which data may go into which tools.
- Prohibited uses, such as automated decisions about people without human review.
- Human review and disclosure rules for anything customers see.
- AI agent rules: least privilege, approval before high-impact actions and logging.
How to adapt and roll out the policy in 5 steps
- Inventory current AI use. List the AI tools and built-in AI features staff use today, what data they enter and why.
- Decide approved tools and data classes. Choose tools that meet your security and contract requirements, and map your data classes to the table in section 6.
- Fill in the placeholders. Name the policy owner and the approval contact. Delete clauses that don't fit your business.
- Get legal and HR review. Your counsel checks the policy against privacy, employment and sector laws in each country where you operate. Human resources (HR) aligns it with contracts and the disciplinary policy.
- Train staff and review regularly. Publish the policy with short training, keep acknowledgment records and review it every 6–12 months.
Common mistakes that make AI policies fail
- Banning all AI. AI use moves to personal devices and accounts, where you have no visibility.
- No approved alternative. If the policy only says no, staff keep the tools they already use.
- No owner. The approved tool list goes out of date and requests for new tools get no answer.
- No data classification. "Don't enter sensitive data" means different things to different people. A table with examples gives one clear answer.
Our AI security consulting team can find the AI tools your staff use today and adapt this policy to them.
Free download
Get the editable version (.docx)
Fill in your details and download the AI Acceptable Use Policy as an editable .docx file, ready for your logo, your tools and your legal review.
The template
AI Acceptable Use Policy
Replace every placeholder in [Square brackets] with your company's details and delete any clause that doesn't fit your business. Have your legal counsel and human resources (HR) team review the final text before you publish it to staff.
| Field | Details |
|---|---|
| Company | [Company name] |
| Policy owner | [Policy owner] |
| Approved by | [Approver name and job title] |
| Effective date | [Effective date] |
| Version | [Version number] |
1. Purpose
This policy sets the rules for using artificial intelligence (AI) tools at [Company name] (the Company). It helps staff use AI productively while protecting customers, colleagues, confidential information and Company systems.
This policy supports the Company's duties under the data protection, confidentiality, intellectual property and AI laws that apply to it, including [Applicable laws and regulations]. It works together with the [Information security policy], [Data protection policy] and [Data classification policy]. Where they conflict, the stricter rule applies.
2. Scope
This policy applies to:
- All employees, contractors, temporary workers and consultants of the Company (staff).
- All AI tools used for Company work, free or paid, on Company or personal devices.
- AI features built into other software, such as writing assistants in email, office, CRM or meeting tools.
- AI agents and automations that connect to Company systems or data.
Private use of AI tools outside work is not covered unless it involves Company data, accounts or systems.
3. Definitions
- AI tool: any software that uses AI to generate, analyze, summarize, translate or act on content, including AI features inside other software.
- Generative AI: AI that creates text, images, audio, video or code in response to a prompt (the instructions or content a user gives it).
- Approved AI tool: a tool listed in [List of approved AI tools], contracted and configured by the Company and used through a Company account.
- Public or unapproved AI tool: any AI tool not on the approved list, including free versions of approved tools and any tool used with a personal account.
- Confidential information: non-public information about the Company, its customers, partners or staff, such as [Examples: contracts, pricing, financial data, source code].
- Personal data: any information about an identified or identifiable person, such as a name, email address, phone number, account number or voice recording.
- Special category or regulated data: data the law protects more strictly, such as health, biometric and genetic data, government ID numbers, payment card data and [Other regulated data in your sector].
- Credentials and secrets: passwords, API keys, access tokens, private keys and any other data that grants access to a system.
- AI agent: an AI system that can take actions through connected tools, such as sending email, updating records or making payments.
- Prompt injection: an attack that hides instructions in content an AI reads, such as an email, file or web page, to change what the AI does.
4. Roles and responsibilities
- [Policy owner]: owns this policy, keeps [List of approved AI tools] current, answers questions and runs the reviews in section 18.
- [Approval contact]: receives requests for new AI tools and AI agents and coordinates their review with IT, security, legal and data protection.
- IT and security: configure approved tools, manage access, detect unapproved AI use as the law permits and handle AI incidents.
- Legal and data protection, [Legal or privacy contact]: review vendor contracts and data processing terms and advise on legal duties.
- Managers: make sure their teams know this policy and complete training.
- All staff: follow this policy, check AI output and report incidents.
5. Approved and prohibited AI tools
- Approved AI tools. Staff may use the tools in [List of approved AI tools] for Company work, through Company accounts only. The list states the data classes each tool may process. It is published at [Location of the approved tool list].
- Prohibited AI tools. Staff must not use [List of prohibited AI tools or categories] for Company work or on Company devices.
- Other public AI tools. Staff may use other public AI tools only with Public data (section 6), only for [Permitted low-risk tasks] and never with a Company account or a connection to Company systems.
Requesting a new AI tool or AI feature
- Send a request to [Approval contact] through [Request form or channel] with the purpose, the users, the data involved and any systems the tool will connect to.
- [Approval contact] coordinates a review of the vendor's security, data retention and storage location, whether it trains models on inputs and its contract terms.
- The request is approved, approved with conditions or rejected within [Number of business days]. The decision is recorded.
- Staff may use the tool only after it appears on [List of approved AI tools].
The same process applies to new AI features in software the Company already uses. Staff must not switch on AI features, plug-ins or browser extensions until they are approved.
6. Data rules
Before entering data into an AI tool, staff must identify its class under the [Data classification policy] and follow the table below. When unsure, treat the data as the stricter class and ask [Policy owner].
| Data class | Approved AI tools | Public or unapproved AI tools |
|---|---|---|
| Public (published web pages, press releases) | Allowed | Allowed, within section 5 |
| Internal (procedures, internal notes with no personal data) | Allowed | Not allowed |
| Confidential (contracts, pricing, financial data, source code) | Allowed only in tools approved for confidential data | Not allowed |
| Personal data (customer, staff or candidate details) | Allowed only in tools approved for personal data, for a defined purpose and with the minimum data needed | Not allowed |
| Special category or regulated data (health, government ID, payment card data) | Not allowed without written approval from [Policy owner] and [Legal or privacy contact] | Not allowed |
| Credentials and secrets (passwords, API keys, tokens) | Not allowed | Not allowed |
- Enter only the minimum data a task needs. Remove or mask names and other identifiers where possible.
- Do not upload whole databases, customer lists, mailboxes or shared folders unless that use is approved.
- Do not change the history, retention or model training settings that IT has configured.
- Customer and partner contracts may limit AI use further. Follow the stricter rule.
7. Acceptable uses
Within the data rules in section 6, staff may use approved AI tools to:
- Draft, edit, summarize and translate text.
- Brainstorm ideas, outlines and first drafts.
- Research topics, after checking the sources.
- Write and review code under the [Secure development policy].
- Analyze data the tool is approved to process.
- Transcribe and summarize meetings, with the notice or consent that local law or Company rules require.
- [Other approved uses for your business].
Each person remains responsible for work they produce with AI, as if they had produced it without AI.
8. Prohibited uses
Staff must not use any AI tool to:
- Enter passwords, API keys, tokens or other credentials and secrets.
- Upload customer, staff or candidate personal data to public or unapproved AI tools.
- Make decisions that significantly affect a person, such as hiring, dismissal, pay, credit or access to services, without meaningful review by a qualified person.
- Create deceptive content, such as fake reviews, misleading advertising or fabricated records.
- Impersonate a real person, including creating a synthetic voice, image or video of someone without their written consent and approval from [Approval contact].
- Bypass or disable security controls, content filters or monitoring, except in an authorized security test.
- Give legal, medical, financial or other professional advice based on AI output without review by a qualified person.
- Monitor or profile staff or customers without written approval from [Legal or privacy contact].
- Create unlawful, discriminatory, harassing or sexually explicit content.
- Infringe copyright, trademarks or other intellectual property rights.
9. Accuracy and human review
AI output can be wrong, incomplete, out of date or biased, and AI tools can invent facts, quotes and sources.
- Staff must review AI output before they use it, send it or rely on it.
- The review must match the impact: [Review levels, for example an expert review for legal, financial or security content].
- Staff must check facts, figures, quotes and sources against reliable sources.
- Code written with AI must pass the same review, testing and security scanning as other code.
- Staff should report harmful or seriously wrong output to [Policy owner].
10. Transparency and disclosure
- People who communicate with a Company AI system, such as a chat assistant or voice agent, must be told they are dealing with AI unless this is obvious. Use [Approved AI disclosure wording].
- Realistic images, audio or video of people, places or events created or changed with AI must be labeled as AI-generated before publication.
- Other AI-generated content is labeled as required by [Applicable laws and regulations] and the [Content disclosure guideline].
- Staff must follow customer contract rules on AI use and must not claim that content was made without AI when it was.
11. Intellectual property and confidentiality
- Confidentiality duties in employment contracts, NDAs and customer contracts apply in full to AI tools.
- The Company approves only AI tools whose terms meet [Contract requirements for AI vendors, for example no training on Company data].
- Staff must not enter third-party content, such as copyrighted text, images or code, unless the Company has the right to use it that way.
- The Company may not be able to protect content produced mainly by AI, and AI output can resemble existing works. Check important output before publishing it.
- Work that staff produce with AI tools for the Company belongs to the Company under [Employment or contractor agreement terms].
12. AI agents and automation
AI agents that read Company data or act in Company systems carry more risk than chat tools. These rules apply in addition to the rest of this policy.
- Only [Authorized roles] may connect an AI tool or AI agent to Company systems, accounts or data. Staff must not connect AI tools to Company systems through plug-ins or connectors without approval.
- Each AI agent must have a named owner and a documented purpose and be recorded in the [AI system inventory].
- Each AI agent must use its own credentials with least privilege: only the access its task needs.
- Actions with financial, legal, security or customer impact, such as payments, deleting data or bulk external messages, must wait for approval by an authorized person. See [List of actions that need human approval].
- AI agents must log their inputs, actions, outputs and approvals for [Log retention period].
- AI agents must be tested for prompt injection and data leaks before launch and after major changes.
- The owner must be able to pause an AI agent quickly and must do so if it behaves unexpectedly.
13. Security
- Use Company accounts with single sign-on and multi-factor authentication (MFA) where available. Never use personal accounts for Company work.
- Do not share AI tool accounts or API keys.
- Treat emails, web pages and files from outside the Company as untrusted, because they can contain prompt injection.
- Report suspected prompt injection, unexpected AI actions or an AI tool asking for credentials to [Security contact] at once.
- Verify unusual requests for payments, data or access through a second, known channel, because AI can clone voices and fake video calls.
14. Incident reporting
Report the following to [Security contact] through [Reporting channel] within [Reporting deadline, for example 24 hours]:
- Confidential information, personal data or credentials entered into a public or unapproved AI tool, even by mistake.
- AI output that exposed data to the wrong person.
- An AI agent that took an unapproved or unexpected action.
- Suspected prompt injection or misuse of AI tools by others.
Fast reporting helps the Company limit harm and meet any legal notification deadlines. A report made promptly and in good faith will not in itself lead to disciplinary action. Incidents are handled under the [Incident response plan].
15. Training and AI literacy
- All staff must complete [AI training course] before using approved AI tools and a refresher every [Refresher interval].
- Training covers how the approved tools work and fail, the data rules, checking output, prompt injection, AI-enabled fraud and each person's duties under this policy.
- Staff in higher-risk roles, such as [Roles, for example developers, AI agent owners and HR], receive additional training.
- [Policy owner] keeps records of completed training and of each person's acknowledgment of this policy.
This training supports the Company's measures to develop its staff's AI literacy, including under [Applicable AI laws, for example Article 4 of the EU AI Act].
16. Monitoring and enforcement
- The Company may monitor AI use on Company systems, networks and accounts to detect unapproved AI tools, data leaks and security incidents.
- Monitoring must be lawful and proportionate and follow the [Employee privacy notice] and local law, including any duty to inform or consult staff representatives.
- A breach of this policy may lead to removal of AI access and disciplinary action under the [Disciplinary policy], up to termination of employment or contract where local law allows.
17. Exceptions
- Request an exception in writing from [Policy owner], stating the reason, the data involved, the duration and the safeguards.
- Exceptions need approval from [Exception approver], last no longer than [Maximum exception period] and are recorded in the [Exceptions register].
- No exception may allow staff to enter credentials, secrets or special category or regulated data into a public or unapproved AI tool.
18. Review and version history
[Policy owner] reviews this policy at least every [Review interval, for example 12 months], after a significant AI incident and when the Company adopts a major AI tool or when relevant laws change. Questions go to [Policy owner] at [Contact email].
| Version | Date | Summary of changes | Approved by |
|---|---|---|---|
| 1.0 | [Effective date] | First version | [Approver name and job title] |
| [Version number] | [Date] | [Summary of changes] | [Approver name and job title] |
Sources
- 1.Cost of a Data Breach Report 2026, IBM, 2026-07-29 (opens in a new tab)
- 2.Every AI agent followed the rules. The data still leaked., IBM, 2026 (opens in a new tab)
- 3.Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text, EUR-Lex, Publications Office of the European Union, 2026-07-27 (opens in a new tab)
- 4.Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)
- 5.AI literacy: questions and answers, European Commission, 2026-07-27 (opens in a new tab)
- 6.AI Omnibus enters into force, European Commission, 2026-07-27 (opens in a new tab)