Search this site
Public information siteInstitutional framework and operating programs continue to evolve

Practical AI Governance · Published September 3, 2026

AI Acceptable Use Policy

A complete, adoptable policy for how the people in an organization use AI tools: which tools, what information, which uses, whose review, how to report, and how the policy stays current. Each of the twelve clauses is followed by the Institute’s reasoning.

What is an AI acceptable use policy?

The rules for people, not the rules for systems.

An AI acceptable use policy is the document that tells the people who work for an organization which AI tools they may use, what information they may share with those tools, what they may and may not use AI for, when a person must review AI output before it is relied on, how to report a problem, and what happens when the rules are broken.

It is written for the employee, contractor, or volunteer at their desk, not for the team deciding whether to build an AI system. That second question belongs to the organization’s governance process, which the Institute’s framework, charter, and checklist address. Most organizations already have a general IT acceptable use policy. That policy rarely says what a person may type into a model, whether the provider may train on it, or which decisions still need a person. This one does.

Four documents, four jobs

The usage rule sits on top of the governance stack.

The framework explains how to design AI around people. The charter gives a committee its authority. The checklist proves one use case is ready. This policy tells everyone else what they may do on a normal working day.

01

Framework

The human-centered AI framework explains how to design and govern an AI use case so that purpose, judgment, and correction stay with people.

02

Charter

The committee charter gives a named body the authority to approve tools, grant exceptions, and adopt policies like this one.

03

Checklist

The governance checklist is the evidence record for one AI use case before launch and through monitoring and retirement.

04

Acceptable use policy

This policy is the daily usage rule for people: which tools, what information, which uses, whose review, and what happens when something goes wrong.

Four decisions the organization makes

The policy is complete. These four inputs make it yours.

Every clause below is written in adoptable language and refers to the policy owner, the approved list, the four information tiers, and the consequential categories. Those four things are the only parts an organization has to decide for itself.

01

Name the owner

One accountable person maintains the approved list, answers questions, records exceptions, and brings the policy to the approval authority. Without a name, the list goes stale within a quarter.

02

Build the approved list from real use

Find out which AI tools people already use, including features inside licensed software, before writing the list. A list written from a wish list is violated on its first day.

03

Map the four information tiers

Public, internal, confidential, and restricted must line up with the classification your people already know. If your scheme uses different names, adopt the policy with your names.

04

List your consequential categories

Decide which decisions and outputs require recorded human review and who is qualified to review each. Clause 09 gives the default list; your organization may add to it.

Twelve clauses, each with the reasoning

Adopt the rule. Keep the reasoning for the people who ask why.

01

Purpose

This policy sets the rules for using artificial intelligence tools in the organization’s work so that people can use AI productively without exposing information, misleading anyone, or handing a consequential decision to a system.

Applies toEveryone covered by clause 02, and every leader who approves AI tools or relies on AI-assisted work.

Why this clause existsA policy that opens with prohibitions reads as a ban. Opening with purpose tells people that AI use is expected, that the rules exist to keep it safe, and that the organization, not the tool, remains accountable.

  • The organization permits the use of approved AI tools in the course of work, subject to this policy.

  • The organization remains accountable for every decision, document, communication, and product that AI helps produce.

  • This policy protects confidential information, personal information, intellectual property, the people affected by the organization’s decisions, and the organization’s obligations to customers, regulators, and the public.

  • This policy supplements, and does not replace, the organization’s information security, privacy, records, conduct, and general acceptable use policies. Where two policies conflict, the more protective rule applies.

02

Scope

This policy applies to every person who does work for the organization and to every AI capability they use in that work, whether it is a standalone product, a feature inside existing software, or an agent that acts on a person’s behalf.

Applies toEmployees, officers, contractors, interns, volunteers, and vendor personnel acting for the organization, on any device and through any account.

Why this clause existsMost AI use now arrives inside tools the organization already licenses. A scope limited to chat products misses the meeting assistant, the spreadsheet helper, the email drafter, and the coding agent.

  • Covered people: employees, officers, directors, contractors, interns, volunteers, and any vendor or partner personnel acting on the organization’s behalf.

  • Covered tools: generative AI products, AI assistants and copilots, AI features embedded in licensed software, AI agents that take actions, and internal systems built on AI models.

  • Covered devices and accounts: organization-managed devices, personal devices used for work, and any account, personal or organizational, through which work information reaches an AI tool.

  • Covered information: all information a person handles in the course of work, regardless of format or where it is stored.

  • This policy governs how people use AI tools. A decision to build, buy, or deploy an AI system for the organization’s own operations follows the organization’s governance process, not this policy alone.

03

Definitions

Terms in this policy have the meanings below. Where a term is not defined, its ordinary meaning applies, and the more protective reading applies whenever a person is unsure.

Applies toEveryone reading or applying the policy.

Why this clause existsMost policy disputes are definitional. People argue about whether a grammar checker is AI or whether a customer’s name is personal information. Short definitions settle those arguments before they start.

  • AI tool: any software that generates content, predictions, recommendations, summaries, translations, code, or actions using a machine learning or language model, including such features inside other software.

  • Approved AI tool: an AI tool that appears on the organization’s approved list, used through the organization’s account and under the organization’s agreement with the provider.

  • AI agent: an AI tool that can take actions, such as sending messages, changing records, running code, or making purchases, rather than only producing content for a person to review.

  • Restricted information: personal information about any individual; health, financial, and payment information; credentials, keys, and security details; source code, trade secrets, and unreleased plans; information received under a confidentiality obligation; and any information the organization classifies as confidential or restricted.

  • Consequential decision: a decision that materially affects a person’s employment, pay, access to services, credit, health, safety, legal rights, or education, or that commits the organization to a material financial, legal, or contractual obligation.

  • Output: anything an AI tool produces, including text, code, images, audio, video, data, summaries, and actions.

04

Approved tools

Work may be done only with approved AI tools, through the organization’s accounts. Any AI tool not on the approved list is not approved, and personal accounts on approved tools are not approved.

Applies toEveryone who uses AI tools, and the policy owner and security lead who maintain the approved list.

Why this clause existsThe approved list is the policy’s most operational clause. It has to reflect what people actually use, or it will be violated immediately. It also needs a fast, visible route for adding tools, or people will route around it.

  • The policy owner maintains a published, dated list of approved AI tools, the account through which each is used, and any use limits that apply to it.

  • A tool joins the list only after the organization has reviewed how the provider handles inputs and outputs, whether inputs are used to train the provider’s models, where information is stored, how long it is retained, how access is controlled, and whether the provider’s terms meet the organization’s obligations.

  • Any covered person may request a new tool by describing the tool, the intended use, and the information it would touch. The policy owner records a decision and its reasons within a stated service period and publishes approved additions.

  • AI features that appear inside already-licensed software are treated as new tools. They stay off until the same review is complete or the policy owner records that the existing agreement already covers them.

  • Personal accounts, free tiers, and trial accounts on any AI tool are not approved for work information, even where the same tool is approved through an organizational account.

  • The organization may remove a tool from the list at any time and will tell covered people what to do with work stored in that tool.

05

Information rules

What you may share with an AI tool depends on the information, not the tool. Public information may be used with any approved tool. Restricted information may not be entered into any AI tool unless the policy owner has approved that specific use in writing.

Applies toEveryone who enters information into an AI tool or connects an AI tool to a data source.

Why this clause existsThe most common AI incident is ordinary. A person pastes a customer record, a contract, or source code into a tool to save time. A four-tier rule that maps to the organization’s existing classification is easy to remember and easy to enforce.

  • Public information, already published by the organization or freely available, may be used with any approved AI tool.

  • Internal information, meant for people inside the organization, may be used only with approved AI tools operating under the organization’s account.

  • Confidential information, whose disclosure would harm the organization, a customer, or a partner, may be used only with approved tools the policy owner has designated for confidential information because the provider’s agreement prohibits training on inputs and provides adequate retention, access, and security terms.

  • Restricted information, as defined in clause 03, may not be entered into any AI tool, connected to any AI tool, or made available to any AI agent unless the policy owner has approved that specific use case in writing and recorded the conditions.

  • Where a person is unsure how information is classified, the person treats it as the more restrictive class or asks the policy owner before proceeding.

  • Remove or replace identifying details before using information with an AI tool wherever the task allows it. De-identification does not by itself move restricted information into a lower class.

  • Connecting an AI tool or agent to a mailbox, drive, database, code repository, or messaging system counts as sharing everything that connection can reach, and requires the same approval as sharing the most sensitive information in that source.

06

Permitted uses

Within the information rules, approved AI tools may be used to help with work, on the condition that a person checks the output before it is relied on, sent, published, or acted on.

Applies toEveryone who uses AI tools in the course of work.

Why this clause existsPeople need to see what good use looks like, not only what is forbidden. Naming permitted uses also signals which uses are expected to become routine, which shapes training and tool selection.

  • Drafting, editing, restructuring, and summarizing documents, messages, and presentations that a person then reviews and owns.

  • Researching a topic, generating options, and testing arguments, with every fact, figure, quotation, and citation verified against a primary source before it is used.

  • Writing, explaining, reviewing, and testing code, with the resulting code reviewed by a qualified person and tested before it reaches a shared or production system.

  • Transcribing and summarizing meetings the organization has permitted to be recorded, with participants told that an AI tool is present.

  • Translating and adapting content for a first draft, with human review before anything official, legal, or public relies on it.

  • Analyzing, cleaning, and visualizing information that the person is permitted to share under clause 05.

  • Automating routine steps through an AI agent, within the limits, monitoring, and stop controls the policy owner has approved for that agent.

07

Prohibited uses

The following uses are prohibited with any AI tool, approved or not, regardless of the information involved.

Applies toEveryone covered by this policy.

Why this clause existsProhibitions must be specific enough to act on and short enough to remember. Each item below describes a use that has already caused harm to real organizations, not a hypothetical.

  • Letting an AI tool make, or effectively make, a consequential decision about a person, or presenting AI output as the basis for such a decision, without the documented human review required by clause 09.

  • Entering restricted information into an AI tool, or connecting one to a source of restricted information, outside a written approval under clause 05.

  • Using an AI tool through a personal, free, or trial account for work information, or using a tool the organization has not approved.

  • Presenting AI output as a person’s own original work where authorship matters, or concealing AI involvement where clause 08 requires disclosure.

  • Generating content that impersonates a real person or organization, fabricates quotations, reviews, credentials, or evidence, or is designed to deceive.

  • Generating content that is harassing, discriminatory, defamatory, or otherwise contrary to the organization’s conduct standards, or that infringes another party’s intellectual property.

  • Using AI tools to find, exploit, or bypass security controls, access controls, or monitoring, other than authorized security testing.

  • Allowing an AI provider to train on the organization’s information, or accepting provider terms on the organization’s behalf, without the policy owner’s approval.

  • Giving an AI agent the authority to spend money, change records of account, send external communications, or alter access permissions beyond the limits approved for that agent.

08

Accountability, verification, and disclosure

The person who uses an AI tool is responsible for the output as if they had produced it themselves. Output is checked before it is relied on, and AI involvement is disclosed where the audience would reasonably expect to know.

Applies toEveryone who produces or relies on AI output, and managers who accept AI-assisted work.

Why this clause existsAccountability is the clause that makes the others enforceable. If a person can say the tool did it, no other rule holds. Verification and disclosure are the practical form of that accountability.

  • A person may not rely on, send, publish, commit, or act on AI output until they have checked it for accuracy, completeness, tone, bias, confidentiality, and intellectual property concerns to a standard appropriate for the task.

  • Facts, figures, quotations, legal or regulatory statements, and citations produced by an AI tool are treated as unverified until confirmed against a primary source.

  • Content that is wholly or substantially AI-generated and is published to the public, sent to a customer, regulator, court, or partner, or used in any formal record carries a clear statement that AI was used in its creation.

  • Where a person interacts with the organization through an AI system, that person is told they are dealing with an AI system.

  • A covered person answers honestly when the organization asks how AI was used in a piece of work.

  • Managers who accept AI-assisted work confirm that the review in this clause took place and may ask for the record of it.

09

Human review for consequential outputs

Before AI output is used in any of the categories below, a qualified person with the authority to reject it reviews it and records that the review took place.

Applies toAnyone using AI output in a consequential category, and the reviewers named for each category.

Why this clause existsA reviewer who lacks the information, time, or authority to disagree is ceremonial. This clause names the categories so nobody has to guess, and requires a record so the review can be evidenced later.

  • Employment decisions: hiring, evaluation, pay, discipline, and termination.

  • Decisions about a person’s access to services, benefits, credit, housing, education, or care, and any eligibility determination.

  • Legal, regulatory, tax, and compliance positions, contracts, and filings.

  • External communications to customers, regulators, courts, the press, or the public, and any public-facing published content.

  • Security and privacy decisions, including access grants, data sharing, and policy exceptions.

  • Financial commitments and payments above the threshold the organization sets for AI-assisted work, and all changes to financial records.

  • Code and configuration changes to production or shared systems, and any change to how an AI agent is permitted to act.

  • The reviewer records who reviewed the output, when, what was changed or rejected, and in which system the record lives.

10

Reporting, exceptions, monitoring, and consequences

People report AI incidents promptly and without fear, exceptions are granted only in writing, AI use may be monitored within the law and the organization’s privacy commitments, and violations carry consequences proportionate to their seriousness.

Applies toEveryone covered, and the policy owner, security lead, and people lead who operate these processes.

Why this clause existsThe policy will be broken. What matters is whether the organization hears about it in time. Protected reporting, a written exceptions route, and stated consequences turn the policy from a document into an operating control.

  • A covered person reports, within one business day and through the route the organization publishes: restricted information entered into an AI tool; AI output that appears to contain another party’s confidential or personal information; suspected manipulation of an AI tool or agent; AI output or action that caused or could cause harm; and AI use by anyone that appears to breach this policy.

  • Good-faith reporting, including self-reporting, is protected. Failing to report a known incident is itself a violation.

  • Exceptions to this policy are requested in writing, granted only by the policy owner or the body that adopted the policy, limited to a stated use case and period, recorded, and reviewed on expiry.

  • The organization may log and review the use of approved AI tools and may detect unapproved tools on managed devices and networks, consistent with applicable law and the organization’s notices to its people.

  • Violations may lead to retraining, loss of tool access, disciplinary action up to and including termination of employment or engagement, and legal action where warranted. Deliberate misuse of restricted information or an attempt to conceal AI use is treated as a serious violation.

11

Training and acknowledgment

Every covered person is briefed on this policy before using AI tools for work, receives role-specific guidance where their work touches restricted information or consequential decisions, and acknowledges the policy on adoption and at each material change.

Applies toEveryone covered, and the people lead who runs onboarding and records acknowledgments.

Why this clause existsA policy nobody has read binds nobody in practice. Brief, role-specific, repeated guidance is what changes daily behavior, and the acknowledgment record is what shows the policy was communicated.

  • New covered people are briefed on this policy, the approved list, the information rules, and the reporting route before they use AI tools for work.

  • People whose roles involve restricted information, consequential decisions, code, or public communication receive guidance specific to those tasks.

  • Acknowledgment is recorded when the policy is adopted, when a person joins, and whenever a material change is published.

  • The organization keeps the current approved list, the reporting route, and the exceptions route where people will actually look for them.

12

Ownership, review, and change

This policy has a named owner, is reviewed at least once a year and whenever a defined trigger occurs, and is changed only through the approval authority that adopted it.

Applies toThe policy owner, the AI governance committee or other approval authority, and the legal, security, privacy, and people leads.

Why this clause existsAI tools change faster than annual review cycles. Naming the triggers that force an earlier review keeps the policy current without pretending the organization can rewrite it every month.

  • The policy owner is named in the adoption record, along with the approval authority and the effective date.

  • The policy is reviewed at least annually, and earlier when a tool is added to or removed from the approved list, a material AI incident occurs, the organization’s data classification changes, a provider changes its terms, a new legal or contractual obligation applies, or the organization begins to deploy AI agents or customer-facing AI systems.

  • Changes are drafted by the policy owner with security, privacy, legal, and people input, approved by the approval authority, dated, versioned, and communicated under clause 11.

  • The organization keeps each version and its adoption record so it can show what the policy said on any given date.

Six steps from draft to operating rule

Adopt it in the order that survives contact with real use.

The sequence matters. Organizations that write the approved list before inventorying real use, or brief people before the reporting route exists, spend the first quarter correcting the policy instead of running it.

  1. 01

    Inventory actual AI use

    Ask teams what they use, check browser and device records where the organization is permitted to, and list the AI features already switched on inside licensed software.

    Security and IT
  2. 02

    Decide the first approved list and account model

    Approve a short list under organizational accounts, decide what happens to work stored in tools that will not be approved, and publish the request route with a decision period.

    Policy owner with security
  3. 03

    Map information tiers and consequential categories

    Align the four tiers in clause 05 with the organization’s classification, and confirm the clause 09 categories and reviewers with the people who own those decisions.

    Privacy, legal, and business leads
  4. 04

    Adopt the policy through the approval authority

    Record the owner, the approving body, the effective date, and the version. The AI governance committee charter gives that body its mandate.

    Governance committee
  5. 05

    Brief people and record acknowledgment

    Run the briefing, publish the approved list and reporting route where people work, and record acknowledgment before AI use continues.

    People lead
  6. 06

    Run the first quarterly review

    Review incidents, requests, exceptions, and detected unapproved tools, then adjust the list and guidance. The first review is where the policy meets reality.

    Policy owner

Keep it current without rewriting it monthly

The approved list moves monthly. The clauses move on triggers.

WhenWhatWho
At adoption

Publish the policy, the approved list, the reporting route, and the exceptions route. Record the owner, the approval authority, and the effective date.

Policy owner

Monthly

Update the approved list, publish decisions on pending tool requests, and close or renew exceptions that expire.

Policy owner with security

Quarterly

Review incidents, exception use, tool requests, and any detected unapproved tools. Adjust guidance and briefings.

Policy owner reporting to the governance committee

Annually and on trigger

Review every clause against current tools, obligations, incidents, and the organization’s classification scheme. Re-acknowledge on any material change.

Approval authority

Why most AI acceptable use policies stop working

The document survives. The rule does not.

It names tools nobody uses

The approved list was written from a wish list. People keep using what they used before, and every working day becomes a violation nobody enforces.

Inventory real use first, then approve or replace. Rollout step one.

It bans without routing

Every clause says no and none says how to get to yes. People stop asking, and the organization loses sight of what is actually in use.

A request route with a stated decision period. Clause 04.

It has no owner and no evidence

Nobody updates the list, nobody records reviews, and nobody can show what the policy said on the day something went wrong.

A named owner, a versioned record, and the review cadence above. Clause 12.

Use established public guidance

A usage policy that fits inside recognized risk frameworks.

The clauses above are written so that an organization can map them to the governance, mapping, measurement, and management functions of broader AI risk programs.

NIST AI Risk Management Framework

The NIST framework organizes AI risk work through Govern, Map, Measure, and Manage. The ownership, approved-list, information, review, and reporting clauses on this page give those functions a daily-use form. NIST’s generative AI profile lists risks and suggested actions specific to generative AI that the information and verification clauses address.

Review the NIST AI RMF Review the NIST generative AI profile

OECD AI Principles

The OECD principles address human-centred values, transparency, robustness and safety, and accountability. The accountability, disclosure, and human review clauses are the parts of this policy that carry those principles into a person’s daily work.

Review the OECD AI Principles

References indicate source alignment only. They do not imply affiliation, endorsement, certification, or approval by NIST, OECD, or any other organization.

AI acceptable use policy FAQ

Clear answers before adoption.

What is an AI acceptable use policy?

An AI acceptable use policy is the document that tells the people who work for an organization which AI tools they may use, what information they may share with those tools, what they may and may not use AI for, when a person must review AI output before it is relied on, how to report problems, and what happens when the rules are broken. It governs daily use by people. It is not the same as a policy for deciding whether to build or deploy an AI system.

How is an AI acceptable use policy different from an IT acceptable use policy?

A general IT acceptable use policy covers devices, networks, email, and software. It usually says nothing about what a person may type into a model, whether the provider may train on it, how AI output must be checked, when AI involvement must be disclosed, or which decisions need recorded human review. An AI acceptable use policy answers those questions and is normally adopted alongside the IT policy rather than replacing it.

What are acceptable uses of AI at work?

Under this policy, acceptable uses include drafting and editing documents a person then reviews and owns, researching a topic with every fact verified against a primary source, writing and reviewing code that a qualified person tests before it reaches a shared system, summarizing meetings the organization has permitted to be recorded, first-draft translation with human review, analysis of information the person is permitted to share, and routine automation through an AI agent within approved limits. Each use is acceptable only within the information rules in clause 05 and the accountability rules in clause 08.

What is an unacceptable use of AI?

The clearest unacceptable uses are letting AI make a consequential decision about a person without documented human review, entering restricted information such as personal, health, financial, or credential data into an AI tool without written approval, using personal or unapproved tools for work information, presenting AI output as original work where authorship matters, generating content that impersonates or deceives, producing harassing or discriminatory content, using AI to bypass security controls, and giving an AI agent authority beyond its approved limits. Clause 07 lists them in full.

Is this a fill-in-the-blank template?

No. It is a complete policy written in adoptable language. An organization reads it, makes the four adoption decisions on this page, aligns the tier and category names with its own, and adopts it through its own approval authority. There are no placeholders to fill in, and nothing on this page creates obligations for any organization until that organization adopts it.

Is an AI acceptable use policy legally required?

This page does not determine what any law requires. Some sectors, jurisdictions, customer contracts, and audit frameworks expect documented rules for how people use AI and how information is protected, and an adopted policy is often the first thing an auditor, insurer, or customer asks to see. Whether a specific obligation applies to your organization is a question for your legal and compliance advisers.

Does the policy cover AI features inside software we already use, and AI agents?

Yes. Clause 02 covers AI features embedded in licensed software and AI agents that take actions, and clause 04 treats a newly switched-on feature as a new tool until it is reviewed. Clause 07 and clause 09 limit what an agent may be authorized to do and require that any change to an agent’s permissions receives recorded human review.

Who should own the policy, and how often should it be reviewed?

One named person owns it, usually a security, privacy, or technology leader, reporting to the AI governance committee or whichever body adopted the policy. It is reviewed at least annually and earlier whenever a defined trigger occurs, such as a new tool, a material incident, a change in data classification, a change in a provider’s terms, a new obligation, or the first deployment of AI agents or customer-facing AI.

Build the connected governance system

Give the usage rule a committee, an evidence record, and a framework.