Resource
AI Acceptable Use Policy Framework
A 11-page working template with the drafting decisions left visible. Ten sections, suggested language you can adapt, and a note on the judgment call you actually have to make in each one.
Why this exists
Roughly 99% of the organizations we engage with have no AI policy at all.
That figure holds whether the organization is regulated or unregulated, which surprises people who assume this is a compliance-driven exercise. Regulated firms are no more likely to have a policy; they simply face steeper consequences when something goes wrong.
When a policy does exist, it is usually one or two pages assembled in an afternoon and composed almost entirely of prohibitions. Every statement in it is defensible. The document as a whole is nearly useless, because a list of prohibitions answers only half of the question an employee actually has — they do not want to know what is forbidden in the abstract, they want to know whether the specific thing in front of them is acceptable.
This framework is the one we apply to ourselves. We have operated under our own AI acceptable use policy for about two years, and several recommendations in it exist because our first version got them wrong.
What is inside
Purpose and scope
Including the scope gap that catches most organizations — contractors and vendors who handle your data while sitting outside a policy written for employees.
Definitions
Written deliberately broad, because most of your actual exposure now arrives as AI features inside software you already license rather than as a chatbot someone opened.
Data classification
Three tiers with suggested language, and the reason elaborate schemes fail: if an employee has to open the document to check, they will guess instead.
Good use
The section almost every policy omits, and the most valuable one. A list of prohibitions answers only half the question your staff actually have.
Approved tools
A maintainable table format, plus the eight configuration questions to verify before adding any tool — including whether training on your inputs is disabled in your settings rather than merely available on your plan.
Prohibited use
Side-by-side comparisons of vague versus actionable language, because "do not enter confidential information" has never once told anyone what to do.
Verification and accountability
What to check before AI-assisted work leaves the organization, and why fluent output is not evidence of accuracy.
Request workflow
The section that determines whether the policy works at all. Three components, including the deadline commitment most policies avoid making.
Existing usage
How to run a no-blame inventory of the AI use that already happened, and why a genuine amnesty is the only version that works.
Oversight and acknowledgment
Review cadence, named ownership, and an acknowledgment block — the part that makes the policy enforceable later.
The objective is not to eliminate AI use. It is to make the sanctioned path the easiest one available.
Prefer to read the argument first? The article this framework came from covers the reasoning without the template.
