AI Acceptable Use Policy Template for Employees (ChatGPT, Copilot and more)

An AI acceptable use policy tells employees which AI tools they may use, what information they may put into them, and how to check and disclose AI output. A good one fits on a few pages, uses a simple Green, Amber and Red rule for data, and can be rolled out across a small company in one week.

Key facts

  • What it covers: approved tools, data rules, checking outputs, disclosure, prohibited uses and how to report mistakes.
  • Who it applies to: every employee and contractor who uses AI for work, including AI features inside existing software.
  • ISO 42001 link: supports the responsible-use controls A.9.2 to A.9.4 and sits under the top-level AI policy (clause 5.2).
  • EU AI Act: Article 50 transparency obligations apply from 2 August 2026; check the current text if you serve EU users.
  • Our template: the AI Policy & Acceptable Use Policy Pack, $39, editable Word.

What should an AI acceptable use policy include?

A workable policy covers eight things: scope, approved tools, data rules, output checks, disclosure, prohibited uses, security and incident reporting. Anything longer tends to go unread.

  1. Scope. Who it covers and which tools count, including AI features added to software you already use.
  2. Approved tools. A named list, the data class each tool is cleared for, and how to request a new one.
  3. Data rules. A Green, Amber and Red classification that anyone can apply in five seconds.
  4. Checking outputs. The person who uses AI output owns it: facts, figures, code and citations are checked before use.
  5. Disclosure. When to tell customers or colleagues that AI helped, and how to label AI-generated content.
  6. Prohibited uses. For example, decisions about people without human review, impersonation and deepfakes, or bypassing security controls.
  7. Accounts and security. Work accounts only, no personal accounts for company data, and care with plugins and connectors.
  8. Mistakes and incidents. A no-blame route to report pasting the wrong thing, fast, so keys can be rotated and data recalled.

What can staff paste into ChatGPT or Copilot?

Staff can paste public information into any approved tool, internal information only into company-approved business tools, and confidential, personal or regulated data into none unless a tool is specifically cleared for it.

Class Examples Rule
Green: public or harmless Published web copy, public documentation, generic coding questions, your own rough drafts with no client details Any approved tool
Amber: internal Internal process notes, project updates, non-production code, anonymized figures Only tools approved for Amber, signed in with your work account, sharing the minimum needed
Red: confidential, personal or regulated Customer or employee personal data, health or financial records, passwords and API keys, unreleased financials, client confidential material, legal advice, controlled technical data Never, unless a named tool is approved in writing for that data

Map these three classes to any data classification you already have. For each approved tool, record whether the vendor may use your inputs for training and where data is stored, based on the vendor's current terms rather than assumptions.

How do you roll out an AI policy in one week?

Spend the first two days finding out what people already use, two days deciding and drafting, and the last day launching with a short briefing and acknowledgements.

  1. Day 1: Find the real usage. Send a three-question, no-blame survey: which AI tools do you use, for what, and with what kind of data?
  2. Day 2: Pick the approved tools. IT and the policy owner choose one or two business-grade tools and confirm their data terms.
  3. Day 3: Draft from the template. Fill in the placeholders, the approved tools table and examples from your own business.
  4. Day 4: Review and approve. HR, IT and a senior leader read it; leadership signs it off.
  5. Day 5: Launch. A 20-minute briefing, the one-page rules summary, and an acknowledgement from every employee.

Then add an exception request route and put a quarterly review of the tools list in the calendar. For the writing side, see how to write an AI acceptable use policy staff will follow.

What is in the AI Policy & Acceptable Use Policy Pack?

The $39 pack gives you two editable Word policies: an organization-level AI policy for leadership, and a generative AI acceptable use policy for staff.

  • Green, Amber and Red data rules with an approved tools table to complete.
  • Sections on coding assistants, AI meeting note-takers, AI agents and decisions about people.
  • An OK, Ask first and Never page of real-world examples, and an employee acknowledgement form.
  • [Square-bracket] placeholders and guidance notes, with ISO 42001 clause and control references.

Not ready to buy? Start with the free ISO 42001 Readiness Checklist. If you are building a full AI management system, the ISO 42001 AIMS Implementation Toolkit ($249) includes the policy pack. Templates help you set clear rules; they are not legal advice.

Last reviewed: 29 September 2026

Frequently asked questions

Should we just ban ChatGPT and similar tools?

A blanket ban rarely works. People keep using AI on personal phones and accounts, where you have no visibility and no data protection. A better approach is to approve one or two business-grade tools, set clear data rules and give staff a simple way to request new tools. That moves use into the open, where you can manage it.

Do we need both an AI policy and an AI acceptable use policy?

If you are pursuing ISO 42001, yes. The AI policy is a short leadership statement covering direction, principles and accountability for all AI the company builds or uses. The acceptable use policy is the practical rulebook for employees. Smaller companies not seeking certification can start with the acceptable use policy alone and add the top-level policy later.

Is Microsoft Copilot safe for confidential company data?

It depends on your license, configuration and the vendor's current terms, so do not assume. Business editions generally offer stronger data commitments than consumer versions, but Copilot can also surface any file a user already has access to. Tidy file-sharing permissions first, confirm the contract terms with IT, and treat it as an Amber tool until that is done.

Do employees need to sign the AI policy?

A signed or electronic acknowledgement is strongly recommended. It proves each person received the rules, which matters if something goes wrong and is useful evidence of awareness for an ISO 42001 audit. Collect acknowledgements through your HR system or an e-signature tool, and repeat the process whenever the policy changes in a meaningful way.

How often should an AI acceptable use policy be updated?

Review the approved tools list every quarter, because vendors change features and terms often. Review the full policy at least once a year, and straight away after an AI incident, a new regulation that affects you, or a major new tool rollout. Record each review, even when nothing changes, so you can show the policy is kept current.

Not ready to buy? Start with the free ISO 42001 readiness checklist

25 plain-English questions that show how ready you are for an ISO/IEC 42001 AI management system.