How to Create an AI Acceptable Use Policy Employees Will Follow
Lou Morentin, VP, Compliance and Privacy

“Telling employees to “use AI responsibly” leaves too much open to interpretation. “
Key Takeaways
- An AI acceptable use policy should identify approved tools, permitted data, and situations that require additional review.
- Rules should reflect how employees already use AI rather than relying on broad prohibitions.
- Organizations need separate guidance for low-risk tasks and uses involving sensitive data, important decisions, or customer-facing work.
- Training, reporting procedures, and regular updates are as important as the written policy.
- Use corporate or client data only when the organization has approved both the tool and the data, and the provider contractually prohibits using it to train shared models.
Teams already use AI to draft emails, summarize meetings, analyze documents, write code, and complete other routine tasks. Telling employees to “use AI responsibly” leaves too much open to interpretation.
An effective AI acceptable use policy should answer four questions clearly:
- Does the company have specific AI tools to use, and are there any exclusions?
- Can I give it this information?
- What should I verify before using the response?
- Who should I ask when I am unsure?
The policy should identify approved tools and any exclusions, explain how to verify facts and links, and name the team responsible for questions or approval requests.
Without clear answers, people are left to decide for themselves what is allowed.
NIST’s AI Risk Management Framework Playbook suggests defining intended uses, connecting AI rules with existing data governance, assigning responsibilities, reviewing third-party systems, and preparing for incidents.
1. Start With Current AI Use
Find out how teams across the organization use AI.
Marketing teams may draft copy, developers may rely on coding assistants, and human resources may summarize employee feedback. Sales teams may research prospects or prepare follow-up emails. AI is also built into meeting platforms, browsers, document applications, and search tools.
These use cases help identify where the policy needs specific guidance. They may also uncover tools adopted without a formal review.
Base the policy on the work employees are already doing. Then decide which activities are allowed, which require safeguards, and which are prohibited.
2. Identify Approved AI Tools
The policy should identify approved AI tools or link to a current approved-tool list.
Free, paid, and enterprise accounts can provide different contractual, privacy, and administrative protections. A paid subscription does not automatically make a tool appropriate for company information.
Corporate or client data should be used only when the organization has approved both the AI tool and that type of data. The provider agreement should also contractually prohibit the use of prompts, uploads, and responses to train or improve its shared model.
Before approving any AI platform for company use, the organization should review:
- Which team or governance body must review and approve the platform, such as a change advisory board or security committee
- How long the provider retains prompts, files, and responses
- Who can access the data
- Whether the provider uses prompts, uploads, or responses to train its models
- Which administrative and security controls are available
- Where the provider stores and processes company data, and whether it remains within an approved environment or tenant
The organization should evaluate vendor terms. The policy should make clear which tools, account types, and uses the organization has approved.
3. Define Permitted and Restricted Data
The policy should spell out which data must stay out of AI tools.
Restricted data may include:
- Passwords, API keys, and authentication codes
- Customer and employee personal information
- Confidential business records
- Proprietary code and intellectual property
- Legal, human resources, and financial documents
- Vulnerability findings and other detailed security information
Avoid broad instructions such as “do not share confidential information” without examples. A meeting transcript, customer email, internal spreadsheet, or small section of source code may contain sensitive data even when it is not labeled confidential.
The policy should also explain when to use fictional, sample, or company-approved de-identified information.
4. Separate Routine Uses from Higher-Risk Decisions
The policy should state which AI uses the organization permits, requires approval for, or prohibits. The categories should be specific enough to apply without interpreting broad risk language each time.
Using an approved tool to improve the wording of a public social media post is different from using AI to evaluate job candidates, interpret a contract, recommend disciplinary action, make a financial decision, or respond to a security incident.
The policy should identify uses that require additional review. These may include AI use involving:
- Employment
- Customer eligibility or access
- Legal rights or obligations
- Financial reporting
- Health or safety
- Cybersecurity investigations
- Public statements or contractual commitments
Clearly separate prohibited uses from those that require approval. For uses that require approval, identify who can authorize the task and what review is needed.
5. Require Human Review
AI output may contain factual errors, outdated information, or conclusions that do not fit the situation. The person using the output remains responsible for the final work or decision.
The policy should require someone to review AI output before using it. Depending on the task, that may include:
- Checking facts, calculations, and cited sources
- Reviewing language for bias or unsupported conclusions
- Confirming that the response does not disclose confidential or personal information
- Verifying code before it enters a production environment
Having qualified personnel review legal, financial, human resources, or security content
6. Make Questions and Reporting Easy
Provide a clear place to ask whether the organization allows a tool or use case. Name the appropriate security, privacy, legal, compliance, or technology contact and explain how to submit a request.
Include instructions for anyone who accidentally enters sensitive information into an AI tool.
After a disclosure, stop using the tool for that task and report what happened promptly. The report should include the tool, account, approximate time, type of data, and actions already taken.
Prompt reporting helps the organization assess the situation and limit the exposure.
7. Provide Training and Keep the Policy Current
Use short, role-based examples. Show marketers how to remove customer details from a prompt, help developers recognize credentials embedded in code, and explain why employee records require approval and appropriate safeguards before they are uploaded for summarization. Managers should also know how to answer common questions and where to send requests they cannot resolve.
Assign an owner to maintain the policy and approved-tool list. Review both regularly as tools, account settings, business uses, and provider terms change, and communicate changes to approved tools or rules promptly. P addresses, software versions, and known weaknesses. Those details could help an attacker identify valuable systems or likely entry points.
Keep the Policy Practical
The policy should identify which tools the organization has approved, which tasks require additional review, and where people should ask questions or report mistakes.
CISO Global helps organizations assess AI-related risk, develop acceptable use policies, and define clear data-handling requirements. Talk with a CISO Global security and compliance expert about putting practical AI guidance in place for your organization.