Direct answer
Create a short core policy supported by examples and procedures. Define scope, approved tools and accounts, data classes, permitted and prohibited uses, required human review, disclosure and record rules, intellectual-property expectations, incident reporting, training, exceptions, ownership, and a review cadence. Have qualified legal, security, HR, and operational owners adapt it to the business.
Policy principles
Make the policy usable at the moment of action
- Plain language that employees can apply without translating legal jargon
- Specific examples from real company work
- Approved tools and accounts, not a generic permission to use AI
- Data classification connected to prompt and upload decisions
- Human accountability for claims, decisions, and communications
- A safe reporting path for mistakes and uncertain cases
- A named owner and material-change review process
Core structure
Cover the decision from purpose through incident response
| Section | What it should answer | Example |
|---|---|---|
| Purpose and scope | Who and which tools or work are covered? | Employees, contractors, embedded AI features, and external tools |
| Approved tools | Which products, accounts, and configurations may be used? | Business account only; consumer account prohibited for company work |
| Data | What may be entered, uploaded, retrieved, or generated? | Public, internal, confidential, and restricted handling |
| Permitted use | Which tasks are allowed under which review? | Brainstorming, drafting, classification, approved knowledge search |
| Prohibited use | Which actions are not allowed? | Credentials, unauthorized data, impersonation, unlawful or discriminatory decisions |
| Human review | Who verifies and approves output? | Qualified owner approves customer-facing claims |
| Records and disclosure | What must be retained or disclosed? | Decision trace, source verification, required notices |
| Incidents | How should mistakes or exposure be reported? | Named channel, prompt reporting, non-retaliation |
| Ownership | Who approves exceptions and updates the policy? | Cross-functional owner and review cadence |
Examples
Show employees the difference between allowed, controlled, and prohibited use
| Use | Policy treatment | Reason |
|---|---|---|
| Brainstorm from public information | Allowed in approved tool with review | Lower data risk; output can still be wrong |
| Draft a customer email from CRM context | Controlled use with approved integration and human approval | Customer data and external communication are involved |
| Summarize an employee medical document | Prohibited unless a specifically approved workflow exists | Highly sensitive information and employment context |
| Enter an API key to troubleshoot code | Prohibited | Credentials must not enter prompts |
| Use AI to rank applicants | Prohibited or subject to specialized legal and governance review | Material employment consequence and bias risk |
Rollout
A policy without training and approved alternatives creates shadow AI
Inventory current use
Ask what tools and embedded features employees already use and why.
Approve practical paths
Give people safe tools for common legitimate work.
Train with scenarios
Practice data, accuracy, rights, disclosure, and incident decisions.
Make help easy
Provide a clear owner or channel for uncertain cases and exceptions.
Observe and update
Use questions, incidents, vendor changes, and new workflows to improve the policy.
Important boundary
A general template is not a legal or security determination
Requirements depend on jurisdiction, industry, contracts, employee context, customer commitments, and the exact technology. Qualified legal, privacy, security, HR, and operational owners should review the policy and any high-impact use case.
The policy should connect to existing information security, privacy, records, acceptable-use, procurement, intellectual-property, employment, and incident-response policies rather than compete with them.
The value point
After this page, you should be able to decide:
Which AI uses the company permits, controls, prohibits, and reviews, and who owns exceptions and updates.Your working output should be a complete policy structure, decision examples, rollout checklist, reporting path, and ownership model.
Questions business leaders ask
Frequently asked questions
Does a small business need an AI policy?+
If employees use AI for company work, a proportionate policy is useful. It can be concise, but should still define approved tools, data, review, prohibited use, reporting, and ownership.
Should a company ban public AI tools?+
It may prohibit them for confidential work while allowing approved lower-risk uses. The decision should reflect data, contracts, controls, and available alternatives.
Who should own the AI acceptable-use policy?+
Executive leadership should approve risk boundaries. A cross-functional owner should maintain the policy with legal, security, privacy, HR, technology, and process input as relevant.
How often should the policy be updated?+
Review on a defined cadence and after material vendor, model, law, incident, data, or use-case changes. Update examples when employee questions reveal ambiguity.
Research anchors
Primary and authoritative sources
- NIST AI Risk Management Framework↗
- NIST AI RMF Playbook↗
- FTC: Privacy and confidentiality commitments for AI companies↗
- U.S. Small Business Administration: AI for small business↗
Examples and planning ranges are clearly labeled. Source terms, provider behavior, and regulations can change; verify current requirements for your organization and jurisdiction.
Prepared and reviewed by the Future Made Useful systems editorial team. Material guidance reviewed July 17, 2026.