The Ultimate Guide to AI Acceptable Use Policies for Companies


Artificial intelligence is already changing how employees research, write, analyze information, communicate with customers, and complete everyday tasks. Tools like ChatGPT, Microsoft Copilot, and Google Gemini can save time and improve productivity, but they can also create risks when employees do not know what information is safe to share or which tools they are allowed to use.

That is where an AI acceptable use policy comes in.

An AI acceptable use policy gives employees clear guidelines for using artificial intelligence at work. It defines which AI tools are approved, what employees can and cannot use them for, what company or customer information must be protected, and when human review is required.

For small and mid-sized businesses, the goal should not be to make AI harder to use. The goal is to give employees enough guidance to use it productively without unintentionally exposing sensitive data, creating compliance problems, or putting the business at unnecessary risk.

AI Acceptable Use Policies for Companies - Blog Hero Image

What Is an AI Acceptable Use Policy?

An AI acceptable use policy, sometimes called an AI use policy or generative AI policy, is a set of company rules that explains how employees, contractors, and other authorized users may use artificial intelligence tools for business purposes.

In plain English, it should answer questions such as:

  • Which AI tools can I use for work?
  • Can I use my personal ChatGPT account?
  • What information can I put into an AI tool?
  • What company, employee, or customer information is off-limits?
  • Can I use AI-generated work without checking it?
  • Who do I ask before trying a new AI platform?

An effective policy does not need to be full of technical or legal language. Employees are more likely to follow rules they can actually understand and apply to their daily work.

An AI acceptable use policy should also work alongside your company’s existing IT, cybersecurity, privacy, HR, and acceptable technology use policies rather than operating as a stand-alone document.

Why Companies Need an AI Acceptable Use Policy

If you have not officially introduced AI into your business yet, that does not necessarily mean your employees are not using it.

An employee might use ChatGPT to rewrite an email, ask Gemini to summarize a document, upload meeting notes to an AI assistant, or use an AI tool they found online to analyze a spreadsheet. These actions can seem harmless, especially when employees are simply trying to work more efficiently.

The problem is that an employee may not know where the information they enter goes, how long the AI provider keeps it, whether it may be used to improve the provider’s models, or whether the application has been approved for company information.

This unapproved use of artificial intelligence is often referred to as shadow AI.

A clear AI policy for companies gives employees practical boundaries before a simple productivity shortcut turns into a security, privacy, or compliance issue.

Protect Sensitive Business and Customer Data

One of the biggest concerns with workplace AI use is what employees enter into AI platforms.

Consider an employee who wants help analyzing customer complaints. Pasting a few anonymous examples into an approved AI system may be acceptable under company policy.

Uploading a spreadsheet containing customer names, email addresses, account information, purchase histories, and internal notes is very different.

Depending on the organization, information that may need additional protection can include:

  • Customer personally identifiable information (PII)
  • Employee records
  • Passwords and login credentials
  • Financial or banking information
  • Protected health information (PHI)
  • Contracts and legal documents
  • Proprietary business processes
  • Trade secrets
  • Nonpublic financial results
  • Source code
  • Controlled or regulated information
  • Internal strategy documents

The right rule is not always “never put business information into AI.” Some enterprise AI platforms may offer contractual, privacy, administrative, and security controls specifically designed for business use.

The more important question is: Has your company evaluated and approved that AI tool for that type of information? The Federal Trade Commission has also emphasized privacy and confidentiality concerns surrounding how AI companies collect and use data, reinforcing why businesses should understand a provider’s data practices before employees share company information with its tools. 

Reduce the Risk of Inaccurate AI Outputs

AI systems can generate answers that sound convincing even when the information is incomplete, outdated, or incorrect.

That means AI-generated information should not automatically become:

  • A final customer recommendation
  • A financial decision
  • A legal interpretation
  • A hiring decision
  • Production-ready computer code
  • A published company statement
  • A factual claim in a proposal or report

Employees should remain accountable for the work they produce, even when AI helped create it.

Your policy should clearly state when AI output must be reviewed, fact-checked, tested, edited, or approved by a qualified person before it is used. The NIST Generative AI Risk Management Framework provides additional guidance for organizations working to identify and manage risks associated with generative AI. 

This aligns with the broader risk-management approach recommended by the National Institute of Standards and Technology (NIST), whose voluntary AI Risk Management Framework is designed to help organizations manage AI risks while still benefiting from the technology.

Address Privacy and Compliance Requirements

Your AI policy should reflect the type of information your organization handles and the regulations or contractual requirements that apply to your business.

A healthcare organization, government contractor, accounting firm, manufacturer, and general professional services company may all use AI differently because their data and compliance obligations differ.

For example, organizations that handle protected health information, controlled government information, payment data, personally identifiable information, or other regulated information may require stricter controls over which AI platforms can access that data.

An AI acceptable use policy template should therefore be treated as a starting point, not a finished compliance policy.

Your final policy should reflect your actual technology environment, business processes, contracts, industry requirements, and risk level.

Protect Intellectual Property

AI also creates intellectual property questions in both directions.

Employees may unintentionally provide proprietary company information to an outside AI provider. They may also use AI-generated text, images, code, or other material without understanding whether the output includes protected third-party material or whether it is appropriate for the intended business use.

Your policy should tell employees not only what company information they may share but also how AI-generated content should be reviewed before it becomes part of a product, presentation, marketing campaign, software application, or other business deliverable.

What Should an AI Acceptable Use Policy Include?

The best AI policies are specific enough to protect the business but simple enough that employees can remember the rules.

At a minimum, an AI acceptable use policy should address the following areas.

1. Who and What the Policy Covers

Define who must follow the policy.

This could include:

  • Full-time and part-time employees
  • Contractors
  • Temporary workers
  • Consultants
  • Vendors with access to company systems or information

You should also define what you consider an AI tool. The policy may cover generative AI applications, AI assistants built into existing software, AI meeting tools, coding assistants, image generators, browser extensions, autonomous AI agents, and other AI-powered applications.

2. Approved AI Tools

Employees should know which AI tools the company has approved for business use.

Rather than saying “AI is allowed,” identify the approved platforms and, when necessary, the specific versions or accounts employees should use.

For example, your company may approve a business-managed Microsoft Copilot environment while prohibiting employees from copying the same information into an AI tool using an unapproved personal account.

Approved tools should be reviewed by whoever is responsible for your organization’s IT and cybersecurity.

Areas to evaluate can include:

  • How the provider stores and processes data
  • Whether prompts or company data are used for model training
  • Data retention settings
  • Encryption
  • Account and administrative controls
  • Access permissions
  • Available audit or logging capabilities
  • Vendor security practices
  • Relevant compliance requirements
  • Integration with existing business systems

3. Acceptable AI Uses

Employees also need examples of what they can do.

Depending on your company, acceptable uses might include:

  • Brainstorming ideas
  • Creating an initial outline
  • Improving grammar or readability
  • Summarizing public information
  • Drafting non-confidential internal communications
  • Generating meeting agendas
  • Researching general topics
  • Creating formulas or helping troubleshoot spreadsheets
  • Assisting with routine administrative tasks
  • Generating initial code for human review and testing

Giving employees useful approved scenarios makes the policy feel less like a list of restrictions and more like guidance for using AI effectively.

4. Prohibited AI Uses

Your AI acceptable use policy should also clearly define activities that are prohibited.

Examples might include:

  • Entering confidential information into an unapproved AI application
  • Sharing passwords, credentials, or authentication information
  • Uploading customer or employee data without authorization
  • Using AI to bypass company security controls
  • Installing unauthorized AI software or browser extensions
  • Allowing AI to make high-impact decisions without appropriate human oversight
  • Using AI-generated content without reviewing it
  • Using AI for illegal, discriminatory, deceptive, or unethical activities
  • Representing unverified AI output as established fact

The exact restrictions should reflect your organization, industry, and risk tolerance.

5. Rules for Sharing Data With AI

This may be the most important part of the policy for the average employee.

Instead of expecting everyone to understand complicated data classification terminology, give them clear examples.

Generally Lower Risk

Requires Approval or Should Not Be Shared

Publicly available information

Customer personal information

Generic brainstorming prompts

Employee records

Public product information

Passwords or credentials

General industry research

Bank, credit card, or financial account information

Content with identifying details removed

Medical or protected health information

Generic business scenarios

Confidential contracts

Public company information

Trade secrets or proprietary information

Non-sensitive templates

Confidential source code or internal system details

The specific rules should be adjusted to match your organization’s data and approved AI platforms.

A useful employee rule of thumb is:

If you would not be comfortable sending the information to an unknown person outside your organization, do not paste it into an unapproved AI tool.

When employees are uncertain, the policy should tell them exactly who to ask.

6. Human Review and Accountability

Artificial intelligence can assist employees, but it should not automatically replace human judgment.

Your policy should define when employees must verify:

  • Facts and statistics
  • Recommendations
  • Calculations
  • Citations and sources
  • Software code
  • Customer-facing information
  • Legal or compliance-related information
  • Financial information
  • Content that could affect another person’s employment, eligibility, access, or rights

NIST’s Generative AI Profile specifically provides organizations with actions for governing, measuring, mapping, and managing risks associated with generative AI. The broader principle is useful even for smaller organizations: AI risk management should be an ongoing business process rather than a one-time technology decision.

7. Security Requirements for AI Tools

Written rules are important, but policies work better when your IT infrastructure supports them. 

Depending on the organization and platform, appropriate safeguards may include:

  • Company-managed accounts
  • Multi-factor authentication (MFA)
  • Single sign-on (SSO)
  • Role-based access controls
  • Approved application lists
  • Logging and monitoring
  • Device management
  • Data loss prevention controls
  • Secure configurations
  • Regular access reviews

This is one of the areas where an experienced managed IT services provider can help turn an AI policy from a document into something that is actually reflected in your technology environment.

8. A Process for Approving New AI Tools

AI applications are appearing faster than most companies can evaluate them.

Simply giving employees a list of approved tools is not enough. Your policy should also explain what happens when someone wants to use a new one.

A basic approval process may ask:

  1. What tool do you want to use?
  2. What business problem will it solve?
  3. What type of information will you enter?
  4. Does it connect to any company systems?
  5. What permissions does it request?
  6. Has IT or security reviewed the provider?
  7. Are there legal, privacy, contractual, or compliance concerns?

The process does not have to be complicated. It simply needs to exist.

Otherwise, employees who encounter a useful new AI tool may make the security decision themselves.

9. AI Training and Employee Acknowledgment

Do not assume employees will read a policy once and remember it six months later.

Provide practical training around questions employees actually encounter, such as:

  • “Can I paste this email into ChatGPT?”
  • “Can I upload this customer spreadsheet?”
  • “Can I install this AI meeting assistant?”
  • “Can I use my personal AI account?”
  • “Can I trust the sources AI gave me?”
  • “Who approves a new AI app?”

Training should also explain why the rules exist. Employee security awareness is an important part of reducing technology risk because employees are more likely to follow policies when they understand the risks behind them. 

10. Policy Ownership and Review

AI tools, security risks, business processes, and regulations continue to change.

Your policy should name the person or group responsible for maintaining it and define when it will be reviewed. Organizations looking for a more structured approach can also use the NIST AI Risk Management Framework Playbook, which provides suggested actions for governing, mapping, measuring, and managing AI risks. 

At minimum, review the policy periodically and whenever there is a significant change involving:

  • Approved AI platforms
  • Company systems
  • Data-handling requirements
  • Business processes
  • Security risks
  • Applicable regulations
  • New AI capabilities

NIST itself continues to update its AI risk-management resources as the technology evolves, reinforcing why businesses should treat AI governance as an ongoing process rather than a one-time project.

How to Create an AI Acceptable Use Policy for Your Company

You do not need to create a complicated AI governance program before you can give employees useful guidance.

For many small and mid-sized businesses, a practical process looks like this.

Step 1: Find Out How Your Employees Are Already Using AI

Before writing rules, understand the current situation.

Ask department managers and employees:

  • Which AI tools are you using?
  • What are you using them for?
  • Are you using personal or company accounts?
  • Are you uploading documents or company data?
  • Are AI applications connected to company software?
  • Which AI tools would make your job easier if they were officially approved?

You may discover more AI usage than you expect.

Step 2: Identify Your Sensitive Information

Determine which information should receive the highest level of protection.

This may include customer information, employee data, financial records, intellectual property, credentials, contracts, regulated data, or other confidential business information.

Employees cannot protect information if nobody has explained what needs protecting.

Step 3: Evaluate and Approve AI Platforms

Decide which AI systems employees may use and for which purposes.

Your IT team or technology provider should help assess the security and privacy implications of each platform, particularly when the AI application connects to company accounts, cloud systems and services, files, email, or other business data. 

Step 4: Create Simple Rules Employees Can Apply

Avoid writing a policy that only your attorney or IT team understands.

Give employees concrete examples of:

  • Approved tools
  • Approved tasks
  • Prohibited tasks
  • Information they should never enter
  • When human review is required
  • What to do when they are unsure

Step 5: Put Technical Safeguards Behind the Policy

A written policy should be supported by your existing cybersecurity program.

For example, if employees are required to use company-managed AI accounts, appropriate identity and access controls should support that requirement.

If certain applications are prohibited, your IT environment may need application management or monitoring controls.

CSG Technologies’ managed IT services include proactive monitoring and security support for small and mid-sized businesses, providing an opportunity to align technology controls with broader company policies.

Step 6: Train Employees and Get Acknowledgment

Introduce the policy through employee training rather than simply emailing a PDF.

Walk through realistic scenarios and give employees an opportunity to ask questions.

Your company may also choose to have employees formally acknowledge that they have read and agree to follow the policy.

Step 7: Review and Update the Policy

AI will continue to change.

Schedule regular reviews and update the policy when new tools, risks, regulations, or business uses emerge.

Common AI Policy Mistakes to Avoid

Creating a policy is a good start. Creating one that employees actually follow is better.

Banning AI Completely

An outright ban may sound safer, but employees may continue using AI because it helps them get their work done.

If AI has legitimate business value, giving employees approved alternatives and clear boundaries can be more practical than pretending the technology does not exist.

Making the Policy Too Complicated

If employees need to interpret pages of technical jargon before asking ChatGPT to help rewrite a paragraph, the policy is unlikely to work as intended.

Make the most important rules easy to understand.

Failing to Define Approved Tools

“Employees may use AI responsibly” leaves far too much open to interpretation.

Employees should know which platforms and accounts are approved.

Focusing Only on the AI Tool

The AI application itself is only part of the risk.

Consider:

  • The information employees enter
  • The accounts they use
  • Connected applications
  • User permissions
  • Browser extensions
  • Data storage
  • Authentication
  • Vendor access
  • AI-generated output

AI security needs to fit into your broader cybersecurity strategy.

Relying on Policy Without Technology

You cannot solve every technology risk with an employee handbook.

Policies work best alongside controls such as MFA, access management, monitoring, approved applications, secure cloud environments, endpoint management, and employee security training.

Creating the Policy Once and Forgetting About It

An AI policy written today may not reflect how your company uses AI a year from now.

Make policy review part of your normal IT, security, and business planning process.

AI Acceptable Use Policy Template for Businesses

The following framework can help your organization begin building its own AI acceptable use policy.

Important: This AI acceptable use policy template is general educational information. Your company should adapt it to your business, technology environment, contracts, industry, and applicable legal or regulatory requirements.

Purpose

This policy establishes guidelines for the safe, responsible, and authorized use of artificial intelligence tools for company business.

Scope

This policy applies to employees, contractors, and other authorized individuals using AI tools to conduct company business or access company information.

Approved AI Tools

Employees may use only AI applications and accounts approved by the company for business purposes.

New AI tools must be submitted through the company’s technology approval process before being used with company information or systems.

Acceptable Use

Approved AI tools may be used for authorized business activities such as brainstorming, research using public information, drafting, summarization, administrative assistance, and other approved tasks.

Data Protection

Users must not enter confidential, sensitive, proprietary, regulated, customer, employee, financial, authentication, or other restricted information into an AI platform unless the company has specifically approved that platform for the applicable data.

Human Review

Employees are responsible for reviewing and verifying AI-generated information before using, sharing, publishing, or relying on it for business purposes.

AI output should not be treated as inherently accurate simply because it appears authoritative.

Security

Employees must follow all company cybersecurity requirements when using AI, including requirements involving approved accounts, authentication, passwords, devices, software, access permissions, and company data.

Prohibited Use

AI may not be used to violate company policy, applicable law, contractual obligations, intellectual property rights, privacy requirements, security controls, or ethical workplace standards.

Reporting and Questions

Employees should contact their supervisor, IT department, or designated policy owner when they are unsure whether a particular AI tool, use case, or type of information is permitted.

Potential security or privacy incidents involving AI should be reported promptly through the company’s established incident-reporting process.

Policy Review

The company will periodically review this policy and update it as AI technology, business requirements, risks, and applicable requirements evolve.

AI Acceptable Use Policy FAQs

Can Employees Use ChatGPT at Work?

Employees can use ChatGPT at work if their employer allows it and the way they use it complies with company security, privacy, data-handling, and AI policies.

Companies should specify whether employees may use personal ChatGPT accounts, company-managed accounts, specific business versions, or alternative approved AI platforms.

The important question is not simply whether ChatGPT is allowed. It is what employees may use it for and what information they may provide to it.

What Data Should Never Be Entered Into an AI Tool?

Employees generally should not enter sensitive, confidential, proprietary, regulated, customer, employee, financial, medical, credential, or other restricted information into an AI tool unless that specific application has been evaluated and approved to handle that type of data.

When in doubt, employees should stop and ask IT, security, or their manager before uploading the information.

Is Information Generated by AI Always Accurate?

No. Generative AI can produce incorrect, misleading, incomplete, or outdated information even when the answer sounds confident.

Employees should verify important facts, sources, calculations, recommendations, code, and other outputs before relying on AI-generated information for business purposes.

Is Information Entered Into AI Confidential?

Not automatically.

How information is stored, processed, retained, or used depends on the AI provider, product, account type, settings, and contractual terms.

Businesses should evaluate an AI platform’s privacy, security, data-retention, and data-use practices before approving it for company information.

Who Is Responsible for AI Governance in a Company?

Responsibility varies by organization, but AI governance commonly requires input from company leadership, IT or cybersecurity, HR, legal or compliance professionals, and the departments using the technology.

Smaller businesses may not need a formal AI governance committee. They do need someone who owns the policy, approves technology, answers employee questions, and makes sure security controls support the company’s rules.

How Often Should an AI Acceptable Use Policy Be Updated?

An AI acceptable use policy should be reviewed regularly and whenever significant changes occur in the company’s AI tools, technology environment, business processes, security risks, data requirements, contracts, or applicable regulations.

For many businesses, an annual review can serve as a minimum checkpoint, with additional updates made as needed throughout the year.

Is an AI Policy the Same as a Cybersecurity Policy?

No.

An AI acceptable use policy specifically addresses how employees and other users interact with artificial intelligence. A cybersecurity policy covers a much broader range of technology, information, systems, access, threats, and security requirements.

The two should work together. An AI policy tells employees what responsible use looks like, while cybersecurity controls help protect the systems and data surrounding that use.

Responsible AI Requires Both People and Technology

Artificial intelligence can help businesses work faster, automate repetitive tasks, analyze information, and give employees new ways to solve problems. Avoiding AI entirely may mean missing valuable opportunities.

But adopting AI without guardrails creates a different kind of risk.

A practical AI acceptable use policy gives employees clear answers about which tools they can use, which information they can share, when human review is required, and where to go when they are unsure.

The next step is making sure your technology supports those rules.

As a managed IT services provider, CSG Technologies helps small and mid-sized businesses manage the systems, cloud platforms, access controls, security measures, and ongoing IT support behind their day-to-day operations. A strong AI policy combined with the right technical safeguards can help your organization take advantage of AI without losing sight of data security, compliance, or business risk.

Need help evaluating whether your current IT environment is ready for secure AI adoption? Talk with CSG Technologies about your technology and cybersecurity needs.

Picture of Matt Parks

Matt Parks

About the Author: President & CEO, Matt has over 20 years building and leading high functioning teams
delivering exceptional results