How to Write an AI Acceptable Use Policy Staff Will Follow
ISO Cloud Consulting editorial team
To write an AI acceptable use policy staff will follow, keep it short, name the approved tools, give a simple Green, Amber and Red rule for data, make people responsible for checking output, and offer a safe way to report mistakes. Policies fail when they are vague, ban everything or never change.
Key facts
- Purpose: daily rules for employees using AI tools such as ChatGPT, Copilot, Gemini and AI features in existing software.
- ISO 42001 link: supports controls A.9.2 (processes for responsible use), A.9.3 (objectives for responsible use) and A.9.4 (intended use), under the top-level AI policy (clause 5.2).
- EU AI Act: Article 50 transparency obligations apply from 2 August 2026; the 2026 Digital Omnibus softened the AI literacy duty to supporting staff development. Check the current text.
- Typical length: a few pages plus a one-page summary.
Why do most AI policies get ignored?
Most AI policies get ignored because they are written to protect the company on paper rather than to help people do their jobs. Staff see a long document full of "must not" and no approved alternative, and they carry on using AI on their phones.
Three patterns cause most of the trouble. The first is the outright ban: it looks safe, but it pushes usage onto personal accounts where you have no visibility and no data protection. The second is vagueness: "use AI responsibly" gives nobody a decision rule at the moment they are about to paste a customer spreadsheet. The third is staleness: a tools list written once, while vendors change features and terms every few months. A good policy fixes all three.
What principles make an AI policy work?
An AI policy works when it gives a clear yes path, a decision rule people can apply in seconds, and an explanation of why each rule exists.
- Offer a yes. Approve at least one business-grade tool before you restrict anything. People follow rules that let them get their work done.
- Classify data, not tools alone. The question staff face is "can I paste this?", so answer it with data classes.
- Use examples from your own business. People remember "never paste the payroll export" far better than "do not enter personal data".
- Explain the why in one line. "Because the vendor may keep it" earns more compliance than a bare prohibition.
- Make reporting safe. A no-blame route for mistakes gets you early warning instead of silence.
- Keep it current. Name an owner and review the tools list every quarter.
What sections should an AI acceptable use policy have?
An effective AI acceptable use policy usually has eight sections: scope, approved tools, data rules, output checks, disclosure, prohibited uses, security and incident reporting, with training and consequences at the end.
| Section | What it answers | Example wording (adapt it) |
|---|---|---|
| Scope | Who and what is covered? | "This policy applies to all staff and contractors using any AI tool or AI feature for [Organization name] work." |
| Approved tools | Which tools can I use, for what data? | "Use only the tools in the approved list, signed in with your work account." |
| Data rules | Can I paste this? | "Green data: any approved tool. Amber: tools approved for Amber. Red: never, unless approved in writing." |
| Checking outputs | Who is responsible for mistakes? | "You own anything you use. Check facts, figures, code and sources before sharing." |
| Disclosure | When do I say AI helped? | "Tell the recipient when AI produced a material part of client deliverables." |
| Prohibited uses | What is never allowed? | "No decisions about people based only on AI output. No realistic imitations of real people." |
| Security | What about plugins and agents? | "Do not connect AI tools to company systems without IT approval." |
| Incidents | What if I get it wrong? | "Report it to [contact] the same day. Honest reports will not be punished." |
What should the approved AI tools list include?
The approved tools list should show, for each tool, what it may be used for, the highest data class it is cleared for, how to sign in and any special conditions. It is the part of the policy people consult most, so keep it in a table that is easy to scan and easy to update.
- Tool and edition: the business edition matters, because consumer and business versions of the same product often have different data terms.
- Approved purposes: for example drafting, summarizing, code completion or meeting notes.
- Data class cleared: Green or Amber; Red only with written approval.
- Data handling: whether the vendor may use inputs for training and how long chats are kept, taken from the vendor's current terms.
- Conditions: single sign-on only, history settings, who may request access.
Store the list somewhere that can change without re-approving the whole policy, and give the policy owner authority to update it. That one design choice keeps the policy alive.
How do you handle specific AI tools and use cases?
Handle higher-risk uses with short, targeted sections rather than lengthening the whole policy. Four cases come up in almost every company.
- Coding assistants. Allow them on company repositories only under a business plan, never paste secrets, and review generated code as you would a junior colleague's pull request, including license and security checks.
- AI meeting note-takers. Announce them at the start, get consent from external participants, keep them out of sensitive meetings such as HR or legal discussions, and set a deletion period for recordings.
- Office suite copilots. These can surface any file a user already has access to. Clean up over-shared folders before switching them on, or the assistant will helpfully summarize documents people were never meant to see.
- Decisions about people. Hiring, performance and customer eligibility decisions need a human who reviews the evidence and can overrule the AI. These uses also belong in your AI system impact assessments.
How do you get employees to actually follow it?
People follow an AI policy when the launch is short and practical, when leaders visibly use the approved tools, and when exceptions have a quick answer.
Launch with a 20-minute session built around real examples, not a read-through of the document. Collect an acknowledgement from every employee, which also gives you evidence of awareness for ISO 42001 clause 7.3. Publish a simple request form for new tools and promise an answer within a set number of days; slow approvals are what drive people back to shadow AI. After a month, repeat the anonymous usage survey you ran before launch. If usage of unapproved tools has not fallen, the approved tools probably do not meet people's needs.
What does a good AI acceptable use policy look like?
A good policy passes a simple test: a new employee can read it before lunch and, that afternoon, correctly decide whether they may paste a given document into a given tool. Beyond that, look for a named owner and review date, a tools list updated within the last quarter, examples drawn from your own work, a clear line between the staff rules and the leadership AI policy, and records showing every employee acknowledged the current version. Those records matter to auditors and customers as much as the wording does.
What are the most common AI policy mistakes?
The most common mistakes are banning AI outright, copying a generic policy without naming your own tools, and forgetting AI features embedded in everyday software.
- No approved tools list, so every decision is left to the individual.
- Rules that only cover chat assistants and ignore note-takers, copilots and agents.
- Confusing the staff policy with the leadership AI policy that sets direction for the whole company.
- No owner and no review date, so the policy quietly goes out of date.
- Punishing people who report their own mistakes, which means you hear about the next one last.
Where can you get a ready-made AI acceptable use policy?
You can adapt a professionally written template in an afternoon instead of drafting from a blank page. Our AI Policy & Acceptable Use Policy Pack ($39) includes a leadership AI policy and a generative AI acceptable use policy with Green, Amber and Red data rules, an approved tools table and an employee acknowledgement form. See the AI acceptable use policy template page for a one-week rollout plan, or check where you stand overall with the free ISO 42001 Readiness Checklist. A template is a starting point, not legal advice; have it reviewed for your jurisdiction.
Last reviewed: 29 September 2026