Skip to content
Free · open page · no email gate

AI Policy Template

The whole policy is on this page: eight sections in plain language, with placeholders where your own details go. Copy it, change what does not fit your company, and have it signed off in an afternoon.

An AI policy, formally an AI usage policy, is a short internal document that says which AI tools staff may use, what data may go into them, who checks the output before it reaches a customer, and who to tell when something goes wrong. This page holds a complete AI policy for companies of any size, written by Oleg Sotnikov, a fractional CTO who runs AI systems in production: eight sections you can copy and adapt, covering purpose and scope, approved tools, data rules, human review, security and vendor checks, intellectual property, incident reporting, and review cadence. It is free and open, with no email address and no download form. It is a template rather than legal advice, so have your own counsel read it before you adopt it.

One Document, Three Names

An AI acceptable use policy, an AI usage policy and an AI policy are the same document under different names. Larger companies lean towards acceptable use policy because it mirrors the IT acceptable use policy their staff already sign.

The label settles nothing. The contents do: which tools are approved, what data may go into them, and who checks AI output before it leaves the company. The template below works under all three names.

There is also an interactive version: fill in the AI policy generator

How to Adapt This

1

Replace the placeholders

Every bracket in the text ([Company], [Owner], [contact]) marks a decision you need to make, and there are fewer than a dozen of them. Work through them top to bottom. Naming a real person as owner matters more than the wording around it.

2

Pick your approved tools

Section 2 is the one people actually read. List the AI tools you already pay for, name the account they must be used under (a company workspace, not a personal login), and say what someone should do when they want a new tool added.

3

Get it signed off and circulated

A policy nobody has seen is not a policy. Have the owner and whoever handles legal or HR approve it, send it out with a short note on why it exists, and store it where a new hire will find it in their first week.

The AI Policy Template

Eight sections, written for a company that has to adopt this next week rather than pass an audit next year. Select the text and copy it straight off the page.

This is a template, not legal advice. It is written as a sensible starting point for a small or mid-sized company; your actual obligations depend on your industry, your client contracts, and the countries you operate in. Have a lawyer review it before you adopt it.

Section 01

1. Purpose and scope

[Company] supports the use of AI tools where they make our work faster or better. This policy sets out how they may be used, so that the data we hold stays protected and the work we deliver stays accurate.

It applies to everyone who works for [Company] (employees, contractors, and freelancers) and to every AI tool used for company work, whether or not [Company] pays for it. That includes general assistants and chatbots, AI features built into software we already use, and AI we build into our own products.

Section 02

2. Approved tools and account rules

Staff may use the AI tools on the approved list maintained by [Owner]. Company work must be done in a [Company] account on a business or enterprise plan, never a personal account and never a free tier that trains on what we enter.

To add a tool to the list, send [Owner] the name of the tool, what you want to use it for, and what data it would see. [Owner] replies within [5] working days. Until a tool is approved, do not use it for company work.

Section 03

3. Data: what may and may never be entered

Never enter into an AI tool: personal data about customers or staff, anything a client gave us under an NDA, passwords and API keys, unreleased financial figures, source code from a private repository, or medical, payment, and identity-document data.

You may enter public information, our own published material, anonymised or invented examples, and text you wrote yourself that contains none of the above. If you are unsure, strip the identifying details or ask [Owner] first. Replacing a client's name with "a client" usually solves it.

Section 04

4. Human review and accountability

AI output is a draft, never a finished answer. Whoever asked the AI for it owns it: you are responsible for what you send, publish, commit, or act on, exactly as if you had written it yourself.

Anything that reaches a client, a regulator, the public, or production code must be read and corrected by a person who understands the subject. Check facts, figures, names, quotes, and citations before they leave [Company]. AI tools state wrong things confidently, and a plausible invented number is the most common way this policy gets broken.

Section 05

5. Security and vendor checks

Before a tool goes on the approved list, [Owner] establishes who the vendor is, where the data is stored, whether our input is used to train their models, how long they keep it, and whether they publish a security report such as SOC 2 or ISO 27001.

Access is granted through [Company]'s single sign-on where the vendor supports it, and removed on a person's last day along with their other accounts. Do not connect an AI tool to company email, files, calendars, or code repositories without written approval from [Owner].

Section 06

6. Intellectual property and attribution

Do not paste third-party material into an AI tool (licensed content, another company's code, or anything under a copyright we do not hold), and do not ask an AI to reproduce a named work or a recognisable style.

AI-generated material is not protected by copyright everywhere, so anything central to [Company]'s product should be written or substantially reworked by a person. Where a client contract, a publisher, or an app store requires you to disclose AI use, disclose it. Internal drafts need no label.

Section 07

7. Incident reporting

Tell [Owner] at [contact] the same working day you realise that restricted data went into an AI tool, that AI output with a serious error reached a client, or that an AI account or API key may have been exposed.

Reporting a mistake in good faith carries no penalty at [Company]; hiding one does. [Owner] records what happened, decides who else needs to know, and, where personal data is involved, follows [Company]'s existing data-breach procedure and its notification deadlines.

Section 08

8. Review cadence and ownership

[Owner] owns this policy and the approved-tools list, and reviews both every [six months], or sooner if a major tool, a vendor's terms, or the law changes.

Everyone at [Company] reads this policy when they join and again after each revision. Questions and suggested changes go to [Owner] at [contact]. This version was approved on [date] by [approver].

Frequently Asked Questions

What should an AI policy include?

At a minimum: which tools are approved and what account they must be used under, what data may never be entered, who reviews AI output before it goes out, and who owns the policy itself. Beyond that, vendor checks, intellectual property, incident reporting, and a review date are worth adding once the basics are in place. The eight sections on this page cover all of it, and a small company can adopt them close to as-is.

Is an AI acceptable use policy different from an AI policy?

No. The two names describe one document. Larger companies say acceptable use policy because it sits next to the IT acceptable use policy their staff already sign. Under either name it has to state which AI tools are approved, what data may never be entered, who reviews AI output before it reaches a customer, and who owns the policy.

Is this AI policy template legally binding?

On its own, no. It becomes binding on your staff once your company adopts it and communicates it, the same way an expenses or security policy does. It is a template rather than legal advice: your obligations depend on your industry, your client contracts, and the countries you operate in, so have a lawyer read it before you adopt it.

How do we roll out an AI policy so people actually follow it?

Name a real person as owner, keep the approved-tools list short and current, and answer requests for new tools within a few days. Where approval drags on for weeks, people route around the policy. Send it with a short explanation of why it exists instead of a bare attachment, cover it in onboarding, and revisit it every six months. The policies that get followed are the ones where the approved path is easier than the workaround.

When do we need more than a policy?

When customers start sending security questionnaires with an AI section, when AI is in the product itself rather than only in how you work, or when a contract or regulator asks how you govern it. At that point you need the layer underneath the document: an inventory of your AI systems, a risk assessment, controls with evidence behind them, and someone accountable for each, which is what ISO/IEC 42001 sets out. That readiness work is what I build with clients under AI governance.

From Policy to Governance

The document is the first layer. When buyers, auditors, or your own product need more than a document (an AI system inventory, a risk map, controls with evidence behind them), that is the governance work I do with clients.

Or just take the template. It stays free and open on this page, with no form in front of it.