This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If staff are already experimenting with AI and nobody is certain what belongs in a written policy, that is a common starting point. An acceptable use policy provides shared rules for approved tools, business data, human review, disclosure, training and incident reporting. This page supplies copy-ready wording and explains why every clause is present.
In short: An AI acceptable use policy defines who may use AI, which tools and tasks are approved, what information stays out, where human review is required and how concerns are reported. Some clauses reflect regulator guidance or jurisdiction-specific law. Others are organisational controls that remain useful even where no authority requires this exact document.
How to read the clause labels in this AI policy
The labels distinguish a legal or regulatory connection from an editorial recommendation. They do not claim that one policy creates compliance across every jurisdiction.
| Label | What it means |
|---|---|
| Good practice | A sensible organisational control. No claim is made that a regulator requires this exact clause. |
| Guidance-backed | The clause reflects a recommendation or risk-management outcome published by a named authority, but the cited document may be voluntary or context-dependent. |
| Law-linked | A law contains a relevant obligation for some organisations or uses. Scope, exceptions and implementation require jurisdiction-specific review. |
The distinction matters. For example, the US National Institute of Standards and Technology describes its AI Risk Management Framework as voluntary, while its governance outcomes cover policies, inventories, training, responsibilities and human oversight. Those outcomes support the structure of a policy without turning every clause into law. NIST AI RMF Core
Copy-and-adapt AI acceptable use policy
The text below is the template itself. Bracketed fields require a business decision before adoption.
[COMPANY NAME] AI ACCEPTABLE USE POLICY Policy owner: [ROLE] Approved by: [ROLE OR GOVERNING BODY] Effective date: [DATE] Next review: [DATE] 1. PURPOSE This policy sets the conditions under which employees, contractors and other authorised workers may use artificial intelligence tools for [Company Name]. Its purpose is to support useful work while protecting confidential information, personal information, intellectual property, customers, workers and the quality of business decisions. 2. SCOPE This policy applies to every person using an AI system for company work, whether the tool is supplied by the company, included in existing software, accessed through a personal account or used by a service provider on the company’s behalf. “AI system” includes generative assistants, transcription and summarisation tools, image or audio generators, automated scoring systems, recommendation systems and AI features embedded in other software. 3. APPROVED TOOLS AND USES Workers may use only the AI tools and use cases recorded as approved in the company AI register. Approval applies to the named tool, account type, business purpose and permitted data category. A new tool, personal account, plug-in, integration or materially different use requires approval from [POLICY OWNER]. The current list of approved tools and uses is available at [LOCATION]. 4. PROHIBITED USES Workers must not use AI to: - impersonate a person or misrepresent the source of a communication; - create unlawful, discriminatory, deceptive, harassing or harmful material; - bypass security, access, copyright or contractual controls; - make a final decision about hiring, dismissal, credit, healthcare, insurance, eligibility, safety or another significant matter without the review specified in this policy; - submit AI-generated work as verified fact when it has not been checked; or - use an unapproved tool for company work. 5. BUSINESS DATA AND PERSONAL INFORMATION Workers must not enter confidential business information, credentials, security information, customer records, employee records, candidate information or other personal information into an AI tool unless that tool and data category are expressly approved. Before approved information is entered, the worker must use the company account and required privacy or security settings. Data should be minimised to what the approved task actually requires. Where practical, identifying details should be removed. 6. ACCOUNTS, ACCESS AND SECURITY AI tools used for company work must be accessed through approved accounts. Workers must not share passwords, disable required security controls or connect an AI tool to company systems without approval. Any plug-in, automated action or integration that can read, change, send or delete company data requires a separate review by [SECURITY OR SYSTEM OWNER]. 7. OUTPUT CHECKING AND HUMAN DECISIONS AI output is a draft or input to judgement, not evidence that a fact is correct. The person using the output remains responsible for checking factual claims, calculations, citations, instructions, tone and suitability before the material is used or shared. A named human decision-maker must review any AI-assisted recommendation that could materially affect a customer, worker, candidate, supplier or member of the public. That reviewer must have enough authority and information to question, change or reject the output. 8. DISCLOSURE AND COMMUNICATION AI involvement must be disclosed where [Company Name] has decided that disclosure is appropriate for the audience, context or applicable rule. Public-facing AI agents must not present themselves as human. Workers must not make unsupported claims about an AI system’s accuracy, neutrality, security or capabilities. External material remains subject to the company’s existing approval and record-keeping processes. 9. INTELLECTUAL PROPERTY AND THIRD-PARTY MATERIAL Workers must not assume that AI-generated material is free to use or that input material may be uploaded. Copyright, licence, confidentiality, attribution and brand checks remain part of the normal review process. Potentially infringing, confidential or improperly sourced output must not be published or reused until reviewed by [RESPONSIBLE ROLE]. 10. RECRUITMENT AND WORKFORCE USE Candidate or employee information may be processed with AI only through an approved workflow. AI must not be the sole basis for a hiring, promotion, performance, pay, disciplinary or dismissal decision. Questions about accessibility, discrimination, worker notice, monitoring or candidate rights must be referred to [HR OR ADVISER] before the use begins. 11. ERRORS, INCIDENTS AND CONCERNS Workers must promptly report suspected data exposure, harmful output, material inaccuracy, unauthorised access, unexpected automated action or policy breach to [CONTACT OR CHANNEL]. Reports made in good faith will be handled under the company’s existing incident and speak-up processes. The incident owner will preserve relevant records, assess the issue and decide whether legal, privacy, security, customer or regulator escalation is required. 12. TRAINING AND ACKNOWLEDGEMENT People covered by this policy must complete the training assigned to their role before using approved AI systems and when material changes are introduced. Training will cover approved uses, data handling, common output failures, human review, incident reporting and any role-specific risks. Completion and acknowledgement will be recorded by [POLICY OWNER OR HR]. 13. OWNERSHIP, MONITORING AND REVIEW [POLICY OWNER] owns this policy, the approved-tool register and the exception process. The company may review business use of AI in accordance with its workplace, privacy and monitoring rules. Exceptions require written approval, a defined purpose, an expiry date and any additional controls. This policy will be reviewed every [PERIOD] and after a material incident, regulatory change or significant change to an approved system. Breaches will be handled under existing employment, contractor, security and disciplinary procedures, with regard to the circumstances of the case.
Why each acceptable-use clause is present
Each clause solves a different control problem. Removing one may leave a gap even where the remaining wording still looks substantial.
| Clause | What it is for | Basis |
|---|---|---|
| Purpose | States the outcomes the policy protects, so approval decisions are not reduced to a list of brand names. | Good practice. |
| Scope | Captures personal accounts, embedded AI features and contractors, which are easy to miss if the policy covers only purchased chatbots. | Good practice. NIST treats third-party systems and data as part of AI governance. NIST AI RMF Core |
| Approved tools and uses | Separates approval of a product from approval of every possible use. It also connects the policy to an AI register that can change without rewriting the full document. | Guidance-backed. NIST Govern 1.6 describes mechanisms to inventory AI systems. NIST AI RMF Core |
| Prohibited uses | Establishes clear boundaries for predictable misuse, including impersonation, unsafe automation and unreviewed significant decisions. | Mostly good practice. Particular activities may be restricted by local law. |
| Business data and personal information | Prevents workers from treating every AI input box as an approved destination for sensitive material. | Guidance-backed and potentially law-linked. Canadian privacy authorities address necessity, openness and personal information throughout the AI lifecycle. Canadian privacy regulators’ generative AI principles |
| Accounts, access and security | Keeps business use within managed accounts and prevents an apparently minor integration from gaining broad system access. | Good practice, supported by general security and third-party risk management principles. |
| Output checking and human decisions | Assigns responsibility for verification and prevents “a person clicked approve” from being mistaken for meaningful oversight. | Guidance-backed. NIST includes defined human oversight, validation and contextual interpretation in its framework. NIST AI RMF Core |
| Disclosure and communication | Addresses situations where customers, workers or the public could be misled about whether content or an interaction is human-generated. | Good practice with jurisdiction-specific legal links. The US Federal Trade Commission states that unfair or deceptive practices law applies to AI-related conduct. FTC AI materials |
| Intellectual property | Stops users from assuming an AI output has a clean ownership history or that source material can be uploaded without permission. | Good practice. Applicable rights depend on the material, contract and jurisdiction. |
| Recruitment and workforce use | Creates a stop-and-escalate rule for a high-consequence use without attempting to reproduce every employment rule. | Law-linked in some settings. US EEOC technical assistance warns that algorithmic tools may disadvantage applicants or workers with disabilities. EEOC AI and disability guidance |
| Errors and incidents | Gives staff somewhere to report a harmful output or suspected disclosure before the issue is dismissed as merely a technology problem. | Good practice, with local breach-reporting rules potentially applying after assessment. |
| Training | Converts a document into role-based understanding and gives the policy owner a record of who received instruction. | Guidance-backed and law-linked in the EU. Current Article 4 of the EU AI Act requires providers and deployers to take measures supporting staff AI literacy, while not prescribing a specific individual proficiency level. Current consolidated EU AI Act |
| Ownership, monitoring and review | Names the decision-maker, creates a controlled exception route and prevents an obsolete tool list from becoming the real policy. | Good practice. NIST Govern 1.5 addresses defined responsibilities and periodic review. NIST AI RMF Core |
The recruitment clause deliberately remains narrow. Candidate-data rules, accessibility, discrimination tests and worker consultation vary too much for a general acceptable-use policy. A detailed hiring workflow belongs in an HR implementation document reviewed for the relevant location.
How the same clauses change across the EU, UK, US and Canada
The neutral template remains the same, but the legal review around it changes by location and use.
| Region | Clauses likely to need local review | What the authority says |
|---|---|---|
| European Union | Training, prohibited practices, human oversight, worker information and significant decisions | Article 4 of the EU AI Act addresses AI literacy, and was replaced by Regulation (EU) 2026/1744 so that providers and deployers “shall take measures to support the development of AI literacy”, with the amended text adding that the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. Article 26 sets deployer duties for high-risk systems, including competent human oversight, while the GDPR addresses solely automated decisions with legal or similarly significant effects. EU AI Act as amended by Regulation (EU) 2026/1744 and GDPR Article 22 |
| United Kingdom | Data handling, fairness, transparency, security and significant automated decisions | The Information Commissioner’s Office organises its AI guidance around accountability, transparency, lawfulness, accuracy, fairness, security and individual rights. The ICO currently notes that this guidance is under review following legislative change. ICO guidance on AI and data protection |
| United States | Consumer claims, employment, sector rules and state or local requirements | NIST provides a voluntary risk-management framework rather than a universal acceptable-use-policy mandate. FTC and EEOC materials illustrate how existing consumer-protection and employment laws can apply to AI conduct. NIST AI RMF, FTC AI materials and EEOC AI resources |
| Canada | Personal information, meaningful transparency, significant impacts and accountability | Federal, provincial and territorial privacy regulators say applicable obligations vary by organisation and activity. Their generative AI principles discuss necessity, openness, accountability, safeguards and meaningful explanations. Canadian privacy regulators’ generative AI principles |
Where this AI policy template stops
No regulator cited on this page has approved this template, and adoption does not establish compliance. An acceptable use policy is an internal control, not a substitute for contracts, privacy notices, impact assessments, security controls, employment procedures or advice about a particular use.
The uncertain part is usually not the wording. It is whether a particular law covers the organisation, data, decision, sector and location. That assessment belongs with the organisation’s regional authority or qualified adviser.
Questions for the policy owner
A usable final version records clear answers to these questions:
- Which tool, account type and use case has actually been approved?
- Which data categories may enter each tool, and where does that data go?
- Who can approve a new integration or exception?
- Which decisions require a named human reviewer with authority to reject the output?
- When is AI involvement disclosed to a customer, candidate, worker or member of the public?
- Where do staff report an incorrect, harmful or unexpectedly disclosed output?
- Which roles require general training, and which require task-specific training?
- Which jurisdiction-specific annexes apply to each office or workflow?
A separate AI register template can hold the changing list of tools, owners, purposes and approvals. Keeping that operational detail outside the main policy makes routine updates easier.
For Australian businesses: local annex
This annex belongs after the neutral policy and applies only where the organisation determines that Australian privacy rules cover the relevant activity. It is not a statement that every Australian business or every AI use is covered in the same way.
The Office of the Australian Information Commissioner says personal information entered into an AI system, and output containing personal information, can engage privacy obligations. Its commercial AI guidance recommends due diligence, human oversight and transparency, and recommends as best practice that personal information, particularly sensitive information, not be entered into publicly available generative AI tools. OAIC guidance on commercially available AI products
The OAIC’s APP 8 guidance describes the framework for disclosures of personal information to overseas recipients, including reasonable steps and accountability, subject to exceptions. OAIC APP 8 guidance
From 10 December 2026, APP 1.7 and 1.8 add privacy-policy transparency provisions for specified uses of personal information in automated decisions that could reasonably be expected to significantly affect a person’s rights or interests. The OAIC summarises the information covered, while the amending Act supplies the primary legislative text. OAIC APP 1 guidance and Privacy and Other Legislation Amendment Act 2024
Copy-ready annex text:
AUSTRALIAN PRIVACY ANNEX Personal information may be entered into an AI system only where the system, purpose and information category have been approved. Publicly available generative AI tools must not receive customer, worker, candidate or other personal information unless [PRIVACY OWNER] has approved a documented exception. The approval record must identify relevant overseas recipients and data flows. [PRIVACY OWNER] will determine whether the proposed handling is a cross-border disclosure and what assessment or safeguards apply. For automated decisions using personal information, [PRIVACY OWNER] will assess whether the company’s privacy policy requires information about the kinds of personal information used and the kinds of decisions made or materially assisted by a computer program. Suspected loss, unauthorised access or disclosure involving personal information must be reported through [INCIDENT CHANNEL]. The privacy incident owner will assess whether the event meets the Notifiable Data Breaches scheme criteria and what notifications are required.
The final incident sentence assigns assessment rather than declaring every AI incident notifiable. The OAIC says the Notifiable Data Breaches scheme concerns eligible data breaches and explains the notification process for affected individuals and the Commissioner. OAIC guidance on when to report a data breach
How this was researched
This guide is researched against primary regulatory sources and official regulator guidance, checked against those documents as of the date shown, and written for a business with no dedicated compliance function. We report what a named authority has published and link the document so you can read it yourself. We do not tell you what your legal obligations are.
Read our full methodology and independence and disclosure policy.
Related reading: shadow AI audit checklist, guide to assessing AI risk, AI data residency comparison, AI vendor due diligence checklist, AI vendor breach response plan template, guide to liability for AI-generated content, and AI governance by region.
Related reading: Claude AI Review: Pricing, Features, and Business Verdict and Is Claude Pro Worth It? An Honest Assessment for Business Users.
Free tools: AI Privacy Risk Scorer to score your current AI tool setup against data-privacy best practice | AI Policy Generator to generate a customised AI policy for your business.
Is an AI acceptable use policy legally required?
Not universally. Requirements depend on jurisdiction, sector, data and use case, while some authorities publish voluntary guidance. The policy is best treated as an internal control that can help organise applicable requirements, not proof that those requirements have been met.
Can this template cover tools used through personal accounts?
Yes. The scope clause expressly covers personal accounts used for company work. The approval clause then directs that business use into named tools, account types, purposes and data categories.
Does every AI output require human review?
The template requires checking before an output is used or shared, with stronger review for decisions that could materially affect a person. The depth of review can be adapted to consequence, such as a quick check for an internal draft and a named decision-maker for a hiring recommendation.
Should recruitment be covered in the general policy?
A short stop-and-escalate clause belongs in the general policy because hiring is a foreseeable high-consequence use. Detailed candidate-data, accessibility, discrimination and worker-notice procedures belong in an HR workflow reviewed for the applicable jurisdiction.
How often is an AI acceptable use policy reviewed?
The template leaves the interval for the organisation to decide and also triggers review after a material incident, regulatory change or significant system change. The approved-tool register may require more frequent updates than the policy itself.
Research method and date
Need to Know AI reviewed primary materials from NIST, the European Union, the UK Information Commissioner’s Office, the US Federal Trade Commission, the US Equal Employment Opportunity Commission, Canadian privacy regulators, Australian legislation and the Australian privacy regulator. Sources were checked on 4 September 2026. This was desk research, not legal review or regulator endorsement.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
This template is provided as a general starting point for internal business documentation. It is general information only and does not constitute legal or professional advice. Requirements vary by jurisdiction and business circumstance. We recommend reviewing any template with a qualified legal or privacy professional before use or distribution.
Use the free AI register template to record approved systems, owners, purposes and review dates alongside this policy.
Use the free AI register template