How-To / AI Consulting

Writing an AI Acceptable Use Policy Your Employees Will Actually Follow

Most AI policies are unreadable and unenforced. Here is a two-page structure that works, plus a free template you can adapt in an afternoon.

The short answer

A workable AI acceptable use policy fits on two pages and covers five things: a named list of approved tools and tiers, a concrete list of information that may never be entered, a named reviewer for each type of AI-assisted output, disclosure rules for clients and hiring, and a path to request new tools that gets answered within days.

A policy can be legally careful and operationally useless. I have watched employees click past pages of rules because the one question they needed answered was missing: can I put this customer document into this tool today?

The best AI policy I can hand a team is short enough to read during a coffee break and specific enough to settle that question. If the policy cannot do that, people will create their own answer under deadline pressure.

Sixty-five percent of organizations have no AI acceptable use policy. That number is from my book, and the chapter behind it explains why the other thirty-five percent mostly have a policy nobody follows.

"Here's something I've learned from watching dozens of organizations try to implement AI policies: They all hit a wall around week six. I call it the Valley of Despair, and it's as predictable as sunrise."

The wall is always the same shape: the policy was written to be defensible instead of followable. Two pages, plain language, and a fast approval path for new tools gets an organization through week six. A ten-page prohibition gets framed, ignored, and violated by your most productive people before lunch.

From The 3AM Test by Steve Copeland.

There are two kinds of AI policy in circulation right now. The first is a single line in the handbook saying employees must use AI tools responsibly, which means nothing and protects no one. The second is fourteen pages of adapted enterprise legal language that no bookkeeper in Tempe is going to read, let alone follow.

A working policy for a small business sits in between and fits on two pages. Here is what belongs on those pages.

Section one: the approved list

Name the tools. Actual product names, actual license tiers.

The distinction that matters most is between consumer and business versions of the same product. The free tier and the enterprise tier of a major AI assistant carry very different commitments about whether your inputs are retained and used for model training. Employees cannot be expected to know that. Your policy has to say it.

Write it as a short table: tool, approved for what, who pays for it, who to ask for access. Then add the sentence that does the real work: any tool not on this list requires approval before use with company information.

Section two: what never goes in

This is the section people actually reference, so make it concrete. Abstract categories like "confidential information" fail because everyone draws that line differently.

For a typical Arizona small business the never list looks something like this. Client records containing names paired with financial, medical, or legal detail. Anything covered by a signed NDA. Employee personnel files and payroll data. Passwords, API keys, or access credentials of any kind. Source code you do not own. Unreleased financial results.

Then add the practical test that catches the edge cases: if you would not email it to a vendor you have never met, do not paste it into a tool.

Section three: the human in the loop

Every piece of AI-assisted work that leaves the company needs a named reviewer. Not a general expectation of care, a role.

Write it as a rule with a subject: client-facing documents are reviewed by the account owner before sending. Code is reviewed by a second engineer before merge. Financial analysis is reviewed by the controller. Marketing copy is reviewed by the marketing lead for factual claims specifically, since fabricated statistics and invented citations are the most common failure mode.

The reason to write this down is not bureaucracy. It is that when something goes wrong, the difference between a mistake and negligence is often whether a review step existed.

Section four: disclosure

Decide three things and state them.

Do employees disclose AI assistance to clients, and in what circumstances. Some contracts and some professional obligations require it. Arizona attorneys in particular should be reading their own duty of competence and confidentiality obligations before assuming the answer is no.

Do you allow AI-generated likeness, voice, or images in marketing. If yes, under what labeling.

Do you allow AI in hiring. This one has real legal exposure attached and the safe default for a small business is no, or human-reviewed only, until you have counsel weigh in.

Section five: how to ask for more

Every policy that only says no gets routed around. Give people a path.

Two sentences will do it. Requests for new tools go to a named person. Include what you want it for and what information it would touch, and you will get an answer within a week.

The businesses with the worst shadow AI problems are almost always the ones where asking took a month and the answer was always no. People do not stop using useful tools. They stop telling you.

Making it stick

A policy nobody signs is a draft. Route it through whatever you already use for handbook acknowledgments, and re-acknowledge annually because available tools change faster than your handbook does.

Then do the one thing most companies skip: spend fifteen minutes at an all-hands walking through the never list with two real examples from your own business. Fifteen minutes of context beats twelve pages of prose.

Get the template

Our template is a fillable two-page policy with the approved tool table, the never list, the review matrix, the disclosure section, and an acknowledgment block. It is written in plain language and marked where you need to make a decision rather than copy ours.

Adapt it, run it past your employment counsel, and put it in front of your team. That is a good afternoon of work.

Frequently asked questions

What should an AI acceptable use policy include?

Five sections: approved tools with license tiers, a concrete list of information that may never be entered, a named reviewer for each category of AI-assisted output, disclosure rules covering clients and hiring, and a documented path to request new tools with a committed response time.

How long should an AI policy be?

Two pages. A twelve-page policy is a policy nobody reads, which is legally the same as not having one when a regulator asks. Depth belongs in the approved-tool table and the prohibited-data list, not in prose.

What data should employees never put into AI tools?

Client records pairing names with financial, medical, or legal detail; anything under NDA; personnel and payroll files; passwords and API keys; source code you do not own; and unreleased financial results. The practical test: if you would not email it to a vendor you have never met, do not paste it.

Can we use AI in hiring decisions?

This area carries real legal exposure, and the safe default for a small business is prohibition, or human-reviewed only, until employment counsel weighs in. Whichever you choose, state it explicitly in the policy rather than leaving it unaddressed.

Related reading

Put this into practice

AEGITz AI Acceptable Use Policy Template

Use the working resource connected to this guide. No sales gate and no dead-end file link.

View resource details

Related reading

Keep following the decision.

Need help applying it?

Bring the real operating problem.

Schedule a Discovery Conversation