AI Safety, Privacy & Verification

How to Write an AI Acceptable Use Policy (Template)

The CourseFluent TeamFebruary 15, 20269 min read
BOFUai policy templateemployee ai use policycompany ai usage guidelines

An AI acceptable use policy is a short, plain-language document that tells employees which AI tools they can use, what data they can and can't put into them, and when a human needs to review AI-generated work before it goes anywhere important. If your team is already using ChatGPT, Copilot, or Claude without one, you don't have "no policy" - you have an unwritten policy that's different in every employee's head, which is the actual risk.

Writing one doesn't require a legal team or twenty pages nobody reads. It requires answering a handful of concrete questions and putting the answers somewhere people will actually see them. Here's a template you can adapt today.

Why You Need One Even for a Small Team

Companies often assume an AI policy is something you need only once you're large enough to have a compliance department. In practice, the risk shows up the moment more than one person is using AI tools for work, because:

  • Without guidance, employees improvise - some conservative, some not, with no consistency across the team.
  • "Common sense" isn't common - what one employee considers obviously sensitive, another doesn't think twice about pasting into a public chatbot.
  • Clients and partners increasingly ask. Many contracts and vendor security questionnaires now explicitly ask whether you have an AI usage policy - having none is a red flag, especially in regulated industries (see our AI compliance basics guide).

A short policy fixes all three, and it's genuinely a one-afternoon project for a company under a few hundred people.

What to Cover (The Template)

Below is a practical outline you can copy, adapt to your company's specifics, and ship. Keep the tone plain - this should read like guidance, not a legal disclaimer.

1. Purpose (2–3 sentences)

"This policy explains how [Company] employees can use AI tools like ChatGPT, Claude, and Copilot for work. Our goal is to get the benefit of these tools - faster drafting, research, and analysis - without putting customer data, company information, or our reputation at risk."

2. Approved tools

List the specific tools employees are cleared to use, and note the plan/tier (this matters - see is ChatGPT safe for company data for why consumer vs. business accounts differ). Example:

  • Approved: ChatGPT (Team plan, company account), Microsoft Copilot (included in our Microsoft 365 license)
  • Not approved without sign-off: personal ChatGPT/Claude accounts for anything involving customer or company data, browser extensions claiming AI features, any tool not on this list

3. What you can never paste into an AI tool

This is the section employees will actually reference. Keep it short and concrete rather than abstract:

  • Customer personal information (names + contact details, financial info, health info, anything covered by privacy law)
  • Employee personal or HR data
  • Unreleased financial results or figures
  • Legal matters, contracts under negotiation, or anything under an NDA
  • Login credentials, API keys, or security details of any kind
  • Anything a client has explicitly asked to be kept confidential

For the full reasoning behind this list, link to (or lift directly from) our guide on what not to share with AI.

4. Review requirements before AI content goes external

"AI-generated content - emails, proposals, social posts, code, reports - must be reviewed and edited by a human before it's sent to a client, published, or used in a decision that affects a customer or employee. AI drafts are a starting point, not a finished product."

5. Verification expectations for factual claims

"Any fact, statistic, quote, or claim generated by AI must be verified against a real source before it's used externally. AI tools can state incorrect information confidently - treat unverified AI output the same way you'd treat an unverified claim from any other source." (See how to verify AI output.)

6. Disclosure expectations

State whether and when employees need to disclose AI involvement - in client deliverables, published content, or internal reports. This varies by industry and client expectations, so be specific to your context rather than generic.

7. Consequences and who to ask

A short line on what happens if the policy isn't followed, and - importantly - who to contact with questions. A policy that dead-ends without a named contact gets ignored the first time someone's unsure.

8. Review cadence

State when the policy will be revisited (e.g., "reviewed every 6 months as tools and regulations change"). AI tooling moves fast; a policy that's never revisited becomes stale within a year.

Keep It Short and Actually Read It Out Loud

A genuinely good acceptable use policy fits on one or two pages. If yours is longer, it's probably trying to be a legal contract instead of an internal guide - split the legal language into a separate document your legal counsel owns, and keep the employee-facing version short enough that someone can read it in five minutes during onboarding.

Rolling It Out So People Actually Follow It

A policy that lives in a forgotten shared drive folder protects nobody. To make it stick:

  1. Fold it into onboarding, not a standalone email people archive unread.
  2. Walk through real examples - a redacted "before/after" of a prompt that should have been anonymized is worth more than a paragraph of rules.
  3. Pair it with a short knowledge check so you know people actually absorbed it, not just received it.
  4. Revisit it when tools change - a new AI feature or vendor should trigger a policy review, not silence.

This is exactly where most DIY policies fall apart: writing the document is the easy 20%; making sure eighty employees across five departments actually internalize it is the hard 80%.

Turn the Policy Into Actual Training

A written policy tells people the rules. Training is what makes the rules stick. CourseFluent builds safe, compliant AI use directly into every learner's course - with a knowledge check on data handling, examples tailored to your industry, and a dashboard so you can see, department by department, who's completed it. Combined with our safe AI use checklist, it turns a policy document into a habit.

Start your free CourseFluent account and get your acceptable use policy out of a shared drive and into your team's actual behavior - or see pricing to roll it out company-wide. Details on how policy and training fit together live on our features page.

FAQ

Does a small business really need a formal AI policy?

Yes, even at five employees. The moment more than one person uses AI tools for work, inconsistent judgment becomes a real risk. A one-page policy costs an afternoon and closes most of the gap.

Who should own the AI acceptable use policy?

Usually whoever owns IT, compliance, or HR policy generally - it doesn't need a dedicated "AI officer" at most company sizes. What matters more than the owner's title is that someone is named as the point of contact for questions.

How often should we update it?

At least every six months, or immediately after adopting a new AI tool, a client contract that mentions AI use, or a relevant change in privacy regulation. Treat it as a living document, not a one-time deliverable.

Written by The CourseFluent Team

Free AI training plan

Get your team fluent in AI

CourseFluent builds a free, personalised AI training plan for your business - sign up and invite your team in minutes.

Start free

Related reading

More on this topic