How to Develop an AI Acceptable Use Policy

August 24, 2026Download

How to Develop an AI Acceptable Use Policy

An AI acceptable use policy is an internal policy document that sets out what AI tools staff, volunteers, and contractors may and may not use in their work, what data they may and may not enter into those tools, how those tools may or may not be used, and what the consequences are for misuse.

People in your organization are likely already using AI tools, whether for writing emails, summarizing documents, or generating content. Without a policy, they have no guidance on what is safe, what is not, and what the organization's expectations are. This type of policy protects data, reduces risk, and removes ambiguity.

How to Develop Your Own Acceptable Use Policy

  1. Identify what AI tools are already in use. Ask staff, check recent software purchases, and review any cloud-based tools.

  2. Review the tools using the guidance found in part 3 of this guidance.

  3. Decide which tools are approved and which are not. Create a short approved tools list. For anything not on the list, require staff to seek approval before using it for work purposes.

  4. Write a clear "what never goes in" list. Pull directly from your data classification framework. Make it specific, not vague.

  5. Define the review requirement. All AI-generated content must be reviewed by a human before it is sent, published, or acted on.

  6. Set disclosure expectations. If required by your organization’s policy, staff should include a disclosure statement when using AI in their work and follow the organization’s approved template.

  7. Name consequences for misuse. Connect policy breaches to your existing data breach and HR procedures. The policy needs teeth to be taken seriously.

Use this template to help build your own AI acceptable use policy.