Writing an AI acceptable-use policy
A short, usable policy people actually follow — not a document that gets ignored.
Updated 1 Jun 2026
A good AI acceptable-use policy is short enough to read and clear enough to act on. Its job is to make the safe path obvious, so staff don’t fall into shadow AI by default. A twelve-page document nobody opens protects no one.
Cover the few things that matter
- What’s sanctioned. Name the approved tools. People can’t choose the safe option if they don’t know what it is.
- What never to paste. Be concrete: client data, credentials, unreleased financials, personal data. Specifics beat “be careful”.
- When to disclose. Where AI-assisted work needs a heads-up — see disclosing AI use.
- Who to ask. A named person or channel for “can I use X for Y?” so questions get answered instead of guessed.
Make it livable
Write it in plain language with examples. Pair “don’t” with a “do this instead” — every prohibition should point to the sanctioned route. Review it on a schedule, because tools and risks shift monthly.
The test of an AI policy isn’t whether it’s comprehensive. It’s whether a busy person can remember the gist and make the right call without reading it again.
Back the policy with real controls; guidance plus DLP catches what words alone miss.