An AI acceptable use policy people will actually read.
A policy that fits on two pages and answers real questions, which tools, which data, who checks and what to disclose, gets followed. A long list of prohibitions gets ignored and pushes use into personal accounts.
veridive6 min read
An employee has a customer complaint open in one window and an AI assistant in the other. The question in their head is simple: can I paste this in? If the company’s AI policy takes fourteen pages not to answer it, they will answer it themselves.
A policy that fits on two pages and answers the real questions, which tools, which data, who checks and what to disclose, gets followed. A long list of prohibitions gets skimmed, ignored and routed around through personal accounts. Below is a template for the first kind, with illustrative wording to adapt and to have counsel review.
Why do long AI policies fail?
They are written to cover every risk rather than to answer questions. They name specific products and features, so they go out of date quickly. They prohibit without offering an alternative, which moves use into personal accounts where nobody can see it, the pattern described in our note on shadow AI. And they are written in a register people read only after something has gone wrong.
If a policy doesn’t answer “can I paste this in?”, people will answer it themselves.
The fix is structural. Keep the rules short and stable, and move everything that changes, such as the list of tools, onto a separate page the owner can update. The two pages then need seven parts:
| Section | What it says | Length |
|---|---|---|
| 1. Purpose | Why the policy exists and who it covers | Three sentences |
| 2. Approved tools | Where the current list lives; no personal accounts | One paragraph |
| 3. Data | The traffic-light table | Half a page |
| 4. Checking output | Who owns what AI produces | One paragraph |
| 5. Disclosure | When to say AI was used | One paragraph |
| 6. Help and reporting | Who to ask, how to report a mistake | Two sentences |
| 7. Owner and review | Who keeps it current, and when | Two sentences |
Which tools are approved, and for what?
Point to the list rather than printing it, and say plainly why company accounts matter. Illustrative wording:
Use AI tools for work only through the company accounts listed on the approved tools page. Each tool is approved for the uses listed next to it. Don’t use personal accounts for work, even for tasks that seem harmless: company accounts come with an agreement on where data is processed, how long it is kept and whether it is used for training, and personal accounts don’t. If you need a tool that isn’t on the list, ask the policy owner.
The list says what each tool is for: a general assistant for drafting and summarizing, the AI features of your office suite for meeting notes, and workflow systems, such as an invoice drafting tool, for their own workflow under their own rules. Our note on assistants and custom systems explains why these are different tools for different jobs.
Which data may and may not go in?
This is the half page people will actually use, so make it a table, and map it to the data classification you already have rather than inventing a new one. Illustrative wording:
| Light | What it covers | Rule |
|---|---|---|
| Green: allowed | Public information, your own drafts, internal documents without personal or confidential data | Use in any approved tool |
| Amber: ask first | Customer or employee data, contracts, unpublished financial results, source code, anything under a confidentiality agreement | Only in tools approved for that data, or with the data owner’s approval |
| Red: never | Health and other special categories of personal data, passwords and access keys, payment card details, anything marked restricted | Never in a general-purpose tool; only in systems built and approved for it |
Add one line under the table: when in doubt, treat it as amber and ask.
Who is responsible for checking output?
The person who uses the output owns it. Illustrative wording:
You are responsible for anything you send, publish or decide using AI output, exactly as if you had written it yourself. Check facts, figures, names, quotes and sources before you use them. Don’t use AI output as the only basis for decisions about people, such as hiring, performance or access, or for commitments to customers, without a person’s review.
Managers carry part of this: asking for AI-assisted work only makes sense if people have time to check it. It is the same principle behind our guardrails, where a person decides on anything consequential.
When must AI use be disclosed?
Keep the rule short and tied to trust. Illustrative wording:
Say that AI was used when it wrote most of something that leaves the company under your name, when a customer is dealing with an automated system rather than a person, and whenever someone asks. Inside the company, say so when a reader will rely on the content, such as a summary of a meeting they missed.
Some disclosures may be required by law or by customer contracts, and the rules differ by country and sector. Counsel should confirm which apply to you and add them here.
How do you keep the policy current?
Give it a named owner and a review cycle, and update it when tools change, not only when the calendar says so. Good triggers for a review:
- a tool is added, withdrawn or changes its terms;
- a new kind of data or workflow starts using AI;
- an incident or a near miss shows a gap;
- the same question keeps reaching the help channel;
- counsel flags a change in law or regulation.
Have counsel review the final text before it is published and after every material change. Keep a short change log at the top, so people can see in three lines what is new.
Two pages, then counsel
Draft the two pages with three or four people who will use them, test the traffic-light table on their real questions, and send the draft to counsel. Then publish the tool list separately, name the owner, and launch the policy with a short session on real tasks rather than an email. Training by role is part of our AI enablement work, and our note on AI literacy covers what everyone should know first.
This note is general information, not legal advice.
Sources
- Guide on Generative Artificial Intelligence and the Protection of Personal Data (in 15 Questions), in Turkish Personal Data Protection Authority (KVKK) www.kvkk.gov.tr/Icerik/8547/uretken-yapay-zeka-ve-kisisel-verilerin-korunmasi-rehberi-15-soruda
- Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 National Institute of Standards and Technology (NIST) nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
Ask an assistant about this note