veridive is now an applied AI company. Looking for the answer engine?Looking for the answer engine? What happened

veridive TR Start a project Menu

Field notesGovernance & risk

An AI acceptable use policy people will actually read.

A policy that fits on two pages and answers real questions, which tools, which data, who checks and what to disclose, gets followed. A long list of prohibitions gets ignored and pushes use into personal accounts.

veridive6 min read

An employee has a customer complaint open in one window and an AI assistant in the other. The question in their head is simple: can I paste this in? If the company’s AI policy takes fourteen pages not to answer it, they will answer it themselves.

A policy that fits on two pages and answers the real questions, which tools, which data, who checks and what to disclose, gets followed. A long list of prohibitions gets skimmed, ignored and routed around through personal accounts. Below is a template for the first kind, with illustrative wording to adapt and to have counsel review.

Why do long AI policies fail?

They are written to cover every risk rather than to answer questions. They name specific products and features, so they go out of date quickly. They prohibit without offering an alternative, which moves use into personal accounts where nobody can see it, the pattern described in our note on shadow AI. And they are written in a register people read only after something has gone wrong.

If a policy doesn’t answer “can I paste this in?”, people will answer it themselves.

The fix is structural. Keep the rules short and stable, and move everything that changes, such as the list of tools, onto a separate page the owner can update. The two pages then need seven parts:

SectionWhat it saysLength
1. PurposeWhy the policy exists and who it coversThree sentences
2. Approved toolsWhere the current list lives; no personal accountsOne paragraph
3. DataThe traffic-light tableHalf a page
4. Checking outputWho owns what AI producesOne paragraph
5. DisclosureWhen to say AI was usedOne paragraph
6. Help and reportingWho to ask, how to report a mistakeTwo sentences
7. Owner and reviewWho keeps it current, and whenTwo sentences

Which tools are approved, and for what?

Point to the list rather than printing it, and say plainly why company accounts matter. Illustrative wording:

Use AI tools for work only through the company accounts listed on the approved tools page. Each tool is approved for the uses listed next to it. Don’t use personal accounts for work, even for tasks that seem harmless: company accounts come with an agreement on where data is processed, how long it is kept and whether it is used for training, and personal accounts don’t. If you need a tool that isn’t on the list, ask the policy owner.

The list says what each tool is for: a general assistant for drafting and summarizing, the AI features of your office suite for meeting notes, and workflow systems, such as an invoice drafting tool, for their own workflow under their own rules. Our note on assistants and custom systems explains why these are different tools for different jobs.

Which data may and may not go in?

This is the half page people will actually use, so make it a table, and map it to the data classification you already have rather than inventing a new one. Illustrative wording:

LightWhat it coversRule
Green: allowedPublic information, your own drafts, internal documents without personal or confidential dataUse in any approved tool
Amber: ask firstCustomer or employee data, contracts, unpublished financial results, source code, anything under a confidentiality agreementOnly in tools approved for that data, or with the data owner’s approval
Red: neverHealth and other special categories of personal data, passwords and access keys, payment card details, anything marked restrictedNever in a general-purpose tool; only in systems built and approved for it

Add one line under the table: when in doubt, treat it as amber and ask.

Who is responsible for checking output?

The person who uses the output owns it. Illustrative wording:

You are responsible for anything you send, publish or decide using AI output, exactly as if you had written it yourself. Check facts, figures, names, quotes and sources before you use them. Don’t use AI output as the only basis for decisions about people, such as hiring, performance or access, or for commitments to customers, without a person’s review.

Managers carry part of this: asking for AI-assisted work only makes sense if people have time to check it. It is the same principle behind our guardrails, where a person decides on anything consequential.

When must AI use be disclosed?

Keep the rule short and tied to trust. Illustrative wording:

Say that AI was used when it wrote most of something that leaves the company under your name, when a customer is dealing with an automated system rather than a person, and whenever someone asks. Inside the company, say so when a reader will rely on the content, such as a summary of a meeting they missed.

Some disclosures may be required by law or by customer contracts, and the rules differ by country and sector. Counsel should confirm which apply to you and add them here.

How do you keep the policy current?

Give it a named owner and a review cycle, and update it when tools change, not only when the calendar says so. Good triggers for a review:

  • a tool is added, withdrawn or changes its terms;
  • a new kind of data or workflow starts using AI;
  • an incident or a near miss shows a gap;
  • the same question keeps reaching the help channel;
  • counsel flags a change in law or regulation.

Have counsel review the final text before it is published and after every material change. Keep a short change log at the top, so people can see in three lines what is new.

Two pages, then counsel

Draft the two pages with three or four people who will use them, test the traffic-light table on their real questions, and send the draft to counsel. Then publish the tool list separately, name the owner, and launch the policy with a short session on real tasks rather than an email. Training by role is part of our AI enablement work, and our note on AI literacy covers what everyone should know first.

This note is general information, not legal advice.

Sources

  1. Guide on Generative Artificial Intelligence and the Protection of Personal Data (in 15 Questions), in Turkish Personal Data Protection Authority (KVKK) www.kvkk.gov.tr/Icerik/8547/uretken-yapay-zeka-ve-kisisel-verilerin-korunmasi-rehberi-15-soruda
  2. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 National Institute of Standards and Technology (NIST) nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf

Ask an assistant about this note

Governance & riskPolicyAdoption

veridive

Field notes are written and reviewed by veridive. How we write them

Questions

Questions about this note

What should an AI acceptable use policy include?

A short AI acceptable use policy answers four questions: which tools are approved and for what, which data may go into them (allowed, ask first, never), who is responsible for checking output, and when AI use must be disclosed. It also names an owner, a way to ask for help and a review cycle. Two pages is enough if the tool list lives on a separate page.

Should employees use personal AI accounts for work?

Not for company information. Personal accounts run under consumer terms between the provider and the individual, so the company has no agreement on retention, training use or where data is processed, and no admin control. The better answer is an approved company tool that is genuinely useful, plus clear rules about which data may go into any tool.