AI Automation

AI acceptable use policy template for small and mid-sized businesses

A free AI acceptable use policy template you can copy and adapt in an hour. Includes a one-page version for very small teams and a full policy covering approved tools, what data may go into AI, checking output, customer-facing AI, AI agents that take actions, meeting recorders, security and incident reporting.

— TL;DR

An AI acceptable use policy tells staff which AI tools are approved, what information must never go into them, and who is responsible for the output. This page has a one-page version and a full template, free to copy with no attribution. Pick your approved tools, sort your information into four classes, name an owner, and review it every six months.

An AI acceptable use policy is a short document that tells your staff which AI tools they may use, what information must never go into them, and who is responsible for what comes out. Below are two versions you can copy: a one-page policy for very small teams, and a full template for businesses that need more. Both are free to use and adapt, with no attribution.

You can also download the full template as a Word document.

This is a plain-language starting point, not legal advice. If you work in a regulated field, handle health, financial or children's data, or operate in several countries, have a qualified professional review your final version.

#Why bother

Your staff are already using AI, whether or not you have said anything about it. The realistic risks are ordinary ones:

  • Customer data, a contract or a password pasted into a personal AI account.
  • An AI-written email, quote or report sent out with a confident error in it.
  • A meeting recorded and transcribed by an AI note-taker without everyone's consent.
  • A new AI tool connected to the company inbox or file store by one enthusiastic person.

A policy does not stop people using AI. It tells them how to do it safely, which is what most of them want to know.

#How to adapt this in an hour

  1. List your approved tools. For each one, note what kind of account is required. Business plans from the major providers generally do not train on your data, and personal accounts often do.
  2. Sort your information into four classes. Public, internal, confidential and restricted. Two or three examples of each, from your own business, are worth more than a long definition.
  3. Name an owner. One person who answers questions, approves new tools and hears about problems.
  4. Replace everything in square brackets, and delete the sections that do not apply to you.
  5. Tell people. Ten minutes in a team meeting does more than a signature on a document nobody has read.

#The one-page version

For a team of up to about fifteen people, this is often enough.

#The full template

Copy from here down to the acknowledgment. Replace the text in square brackets.

#AI Acceptable Use Policy

[Company name] · Version [1.0] · Effective [date] · Owner: [name and role] · Next review: [date]

#1. Purpose

We want everyone at [Company name] to use artificial intelligence (AI) tools where they help us do better work. This policy sets out how to do that while protecting our customers, our staff and the business.

#2. Who and what this covers

This policy applies to all employees, contractors and temporary staff. It covers any AI tool used for company work, including chat assistants, writing and coding assistants, image and audio generators, meeting note-takers, AI features inside other software, and AI agents that take actions in our systems. It applies on company devices and on personal devices used for work.

#3. Approved tools

Use only the tools listed here, on company accounts. The current list is kept at [location].

ToolApproved forAccount requiredHighest class of information allowed
[Tool name][General drafting, research, summarizing][Company account with single sign-on][Confidential]
[Tool name][Software development][Company account][Internal]
[Tool name][Meeting notes][Company account][Internal, with consent of all participants]

Personal AI accounts must not be used for any work involving internal, confidential or restricted information.

#4. Rules for information

We sort information into four classes.

ClassExamplesMay it go into an AI tool?
PublicPublished web pages, marketing material, public price listsYes, any reputable tool
InternalInternal procedures, non-sensitive project notes, draftsApproved tools on company accounts only
ConfidentialCustomer information, contracts, financial results, unreleased plans, source code, employee recordsOnly tools approved for confidential information in section 3
RestrictedPasswords and access keys, payment card and bank details, health information, identity documents, information covered by a confidentiality agreement that forbids sharingNever

If you are not sure which class applies, treat the information as confidential and ask [owner].

Where possible, remove names and identifying details before using AI, even in approved tools.

#5. What you may use AI for

Examples of good uses: drafting and editing text, summarizing long documents, research and brainstorming, analyzing data that is permitted under section 4, writing and reviewing code, translating, preparing for meetings, and creating first drafts of images and presentations.

#6. What you must not do

  • Enter restricted information into any AI tool.
  • Use AI to make or substantially inform decisions about hiring, promotion, pay, discipline or dismissal without approval from [owner] and appropriate human review.
  • Use AI to create content that is unlawful, discriminatory, harassing or deceptive.
  • Use AI to imitate a real person's voice, image or writing without their written permission.
  • Present AI output as professional advice, for example legal, medical, tax or financial advice.
  • Create fake reviews, testimonials, customer quotes or case studies.
  • Attempt to get around the security settings or safeguards of an AI tool.
  • Connect an AI tool to company email, files, systems or customer data without approval under section 12.

#7. Check the output

AI tools make confident mistakes. They invent facts, figures, quotations, references and legal citations. You are responsible for anything you send, publish or act on, however it was produced.

Before using AI output, check facts and figures against a reliable source, check that names, dates and amounts are correct, and read it as if a new colleague had written it. Code produced with AI assistance goes through the same review and testing as any other code.

#8. Being open about AI

  • Customers must be told when they are communicating with an AI system and must be able to reach a person.
  • Do not claim that work was produced without AI if AI was used substantially, where a customer or contract requires disclosure.
  • Follow any rules that apply in your field or location about labeling AI-generated content.

#9. Customer-facing AI and AI agents

Any AI system that communicates with customers, or that takes actions in our systems on its own, needs approval from [owner] before it goes live. Such systems must:

  • Have only the access and permissions their job requires.
  • Require a person to approve sensitive actions, including refunds or payments above [amount], changes to customer records, and messages sent outside the company, unless [owner] has approved otherwise.
  • Keep a log of conversations and actions.
  • Be tested against real examples before launch and before significant changes.
  • Hand over to a person on request, and whenever a request is outside their authority.
  • Have a named person responsible for reviewing their performance at least [weekly or monthly].

#10. Intellectual property

  • Do not ask AI tools to reproduce copyrighted material, and do not publish output that closely copies someone else's work.
  • Be aware that in some countries, material produced entirely by AI may not be protected by copyright. For work where ownership matters, such as brand assets, make sure a person makes a substantial creative contribution, and ask [owner] if in doubt.
  • Follow the license terms of any AI tool regarding commercial use of its output.

#11. Security and accounts

  • Use company accounts with [single sign-on and] multi-factor authentication.
  • Do not install AI browser extensions, plugins or desktop applications that are not on the approved list. Many of them can read everything in your browser.
  • Do not give an AI tool your password, or let it log in as you, unless the tool is approved for that purpose.
  • Meeting recorders and note-takers: tell all participants and obtain their agreement before recording or transcribing a meeting. In some places the law requires the consent of everyone present. Do not record meetings about legal, disciplinary or health matters.

#12. Getting a new tool approved

Send [owner] the name of the tool, what you want to use it for, and what information it would handle. [Owner] will check the provider's terms on data use, training and retention, where data is stored, security features, and cost. Expect an answer within [five working days]. Trying a tool with public information only does not need approval.

#13. Reporting a problem

Tell [owner] immediately if restricted or confidential information has gone into an unapproved tool, if AI-generated material containing a serious error has been sent to a customer or published, or if an AI system has taken an action it should not have. Prompt reports are treated as a good thing. The aim is to fix the problem, not to blame.

#14. Training and questions

Everyone covered by this policy will be shown how it works when they join and when it changes significantly. Questions go to [owner, contact details].

#15. Review

[Owner] reviews this policy at least every six months, and whenever we adopt a significant new AI tool, begin using AI with customers, or the relevant law changes.

#16. Acknowledgment

I have read and understood this policy and agree to follow it.

Name: ____________________ Signature: ____________________ Date: ____________

#Adapting it to your size

Up to about fifteen people. Use the one-page version. Put the approved tools in the policy itself. The owner is usually the founder or the operations lead.

Fifteen to a few hundred. Use the full template. Keep the approved tools list as a separate, living document. Give section 12 a real process, because requests will come weekly. Add the policy to onboarding.

Regulated or larger organizations. Treat this as a first draft for your legal, security and compliance people. You will probably need to add your sector's rules, records of AI systems in use, supplier assessments and, if you operate in the EU, the obligations in the EU AI Act.

#Common mistakes

  • Banning everything. People keep using AI, on personal accounts, where you cannot see it. Approving a good tool is safer than a ban.
  • No approved tools list. A policy that says "use AI responsibly" tells nobody anything.
  • No owner. Questions go unanswered and the policy is quietly ignored.
  • Written once. The tools change every few months. An out-of-date policy is ignored.
  • Forgetting the quiet AI. Note-takers, browser extensions and AI features switched on inside software you already use are where most surprises come from.

#Where a policy fits

A policy covers how people use AI tools. It is one part of getting AI working properly in a business, along with choosing where AI will actually pay back and building it safely. If you would like help with that, our AI readiness checklist is a free place to begin, and the AI Opportunity Audit is a one-week, $1,500 review that ends with a ranked list of opportunities and what each would cost. Or book a free 20-minute call.

Common questions.

  • What should an AI acceptable use policy include?

    At a minimum: which AI tools are approved and on what kind of account, which types of information may and may not be entered into them, a rule that people check AI output and remain responsible for it, when customers must be told AI is involved, how a new tool gets approved, and how to report a mistake. If you use AI agents that take actions, add rules for permissions, approvals and logging.

  • Do small businesses need an AI policy?

    Yes, and it can be one page. The risk in a small business is the same as in a large one: someone pastes customer data, a contract or a password into a personal AI account, or sends out something an AI invented. A short written policy costs an hour and prevents the most likely problems. It is also increasingly asked for by larger customers and insurers.

  • Can employees use ChatGPT at work?

    That is for the business to decide, and the policy is where you decide it. A common approach is to allow approved AI tools on company accounts with business terms, which generally do not train on your data, and to prohibit personal accounts for any work involving customer, confidential or personal information. A flat ban tends to push use out of sight.

  • How often should an AI policy be updated?

    Review it every six months, and whenever you adopt a significant new tool, start using AI with customers, or a relevant law changes. AI tools change quickly, so a policy that names specific approved tools needs more frequent attention than most company policies. Keep a version number and date on it.

  • Is this template free to use?

    Yes. You may copy, adapt and use it inside your organization without asking and without attribution. It is a starting point written in plain language, not legal advice. If you work in a regulated field, handle health, financial or children's data, or operate in several countries, have a qualified professional review your final version.

— Want help with this?

AI automation that gives your team hours back

We find the repetitive work that costs your team the most time, then build the AI workflow automation that takes it over. One workflow at a time, each measured against the hours it saves.

— Keep reading