Intermediate Any tool Guide

Writing an AI acceptable-use policy

A short, usable policy people actually follow, not a document that gets ignored.

A good AI acceptable-use policy is short enough to read and clear enough to act on. Its job is to make the safe path obvious, so staff don’t fall into shadow AI by default. A twelve-page document nobody opens protects no one.

Cover the few things that matter

Name the approved tools first. People can’t choose the safe option if they don’t know what it is. Then be concrete about what never gets pasted in: client data, credentials, unreleased financials, personal data. Specifics beat “be careful” every time.

Two quieter sections earn their place. Say when AI-assisted work needs a heads-up, which is the disclosure question. And name a person or a channel for “can I use X for Y?”, so questions get answered instead of guessed at.

Make it livable

Write it in plain language, with examples. Pair every “don’t” with a “do this instead” that points at the sanctioned route. And review it on a schedule, because the tools change monthly and a policy that pretends otherwise loses its audience fast.

The test of an AI policy isn’t whether it’s comprehensive. It’s whether a busy person can remember the gist and make the right call without reading it again.

Back the words with real controls. Guidance plus DLP catches what guidance alone misses.

Search