Free Resource

Free AI-Usage Policy Template
for startups & small teams

Every AI and SaaS company needs an AI-usage policy to look credible to customers and investors — and to stay on the right side of data-privacy and AI-regulation laws. This ready-to-edit template covers the seven topics that matter most, and you can have it customised to your company in minutes.

AI-Usage Policy Template

Version 1.0 — Replace all [bracketed placeholders] with your company’s details before publishing.

This template is a professional starting point, not legal advice. Adapt it to your jurisdiction, industry, and risk profile. For a policy pack tailored to your company, see the upsell section below.

1

Approved AI Tools

Only AI tools explicitly approved by [Policy Owner / IT Lead] may be used for company work. Maintain an approved-tools list; review it quarterly. Using unapproved tools is a disciplinary matter.

ToolApproved UseRestrictions
[e.g. ChatGPT / Claude]Drafting, summarising, brainstormingNo confidential data; human review required
[e.g. GitHub Copilot]Code assistanceCode review + automated tests before merge
[e.g. Grammarly]Writing assistanceNo PII in pasted text
2

Data Handling — No Secrets or PII in Prompts

Never submit the following to any AI tool:

  • Customer names, contact details, or account data (PII)
  • API keys, passwords, tokens, or authentication credentials
  • Unreleased product plans, pricing, or contract terms
  • Health, financial, legal, or HR records of employees or customers
  • Any data classified as Confidential or Restricted

Safe-prompt rule: Before submitting, ask "Could this prompt identify a specific person or piece of confidential business information?" If yes, remove or replace it with a generic placeholder before pasting.

Most AI providers use submitted content to improve their models unless you have an enterprise data-processing agreement. Even with such agreements, anonymise prompts as a default practice.

3

PII & Customer Data Rules

  • Never paste customer emails, chat logs, or support tickets into a public AI tool, even to draft a response. Use anonymised summaries only.
  • Do not use AI to build profiles of individual customers, employees, or named persons without explicit legal basis and DPO/legal sign-off.
  • Automated decisions about individuals (credit scoring, HR decisions, content moderation affecting user accounts) require legal review before deployment under GDPR Art. 22 and equivalent laws.
  • If a customer asks whether AI was used to process their data, you must be able to answer accurately — maintain a log of AI tool usage in sensitive workflows.
4

Human Review of AI Output

AI tools hallucinate facts, misstate law, and produce biased or incorrect output. All AI-generated content used externally, or for important internal decisions, must be reviewed and approved by a qualified person before use.

  • Legal / compliance text — reviewed by a legal professional or qualified policy lead before publishing or sending.
  • Financial advice or projections — reviewed by the relevant finance team member.
  • Medical or health information — reviewed by a qualified healthcare professional.
  • Customer-facing copy — must pass standard editorial review.
  • AI-generated code — must pass code review and automated testing before merging to production.

Default rule: If AI helped write it, a human must own it before it goes out.

5

IP Ownership

  • Work product created with AI assistance remains the property of [Company Name], provided a human employee directed and materially revised the output.
  • Do not submit copyrighted material (books, articles, source code under restrictive licences) to an AI tool without confirming this is permitted under the relevant licence.
  • AI-generated content may not be protected by copyright in all jurisdictions. Do not claim copyright on purely AI-generated outputs — document the human creative contribution.
  • If you are unsure about IP ownership of a specific output, escalate to [Legal Contact] before use.
6

Disclosure to Customers

  • AI-assisted customer communications — if AI generated a substantive portion of a customer-facing document or report, add a disclosure note where required by contract or applicable law.
  • AI-generated marketing content — label images, copy, or video as AI-generated where required by platform policy or regulation (EU AI Act, FTC guidance, etc.).
  • Automated AI interactions with customers (chatbots, automated response systems) must be disclosed as automated when asked and must not impersonate a human employee.
7

Prohibited Uses

The following uses are prohibited regardless of the tool:

  • Generating content that is false, deceptive, or designed to mislead
  • Creating deepfakes, synthetic voices, or fabricated identities of real people without explicit consent
  • Using AI to bypass or circumvent security controls, access management, or audit processes
  • Generating, distributing, or storing illegal content of any kind
  • Using AI for decisions that must legally involve a human (formal disciplinary hearings, regulated financial or medical decisions)
  • Engaging AI tools to contact, respond to, or make commitments to customers or third parties without human oversight and approval
  • Using AI to automate tasks you are not personally authorised to perform

This template is provided as a starting point only and does not constitute legal advice. Consult qualified legal counsel before finalising any compliance policy. Template by Ruleset.

Download the Template

Get the editable .md file

Markdown format — open in any editor, paste into Notion, Confluence, or Google Docs. Free, no credit card required.

Enter your work email to download

We’ll send you no more than one follow-up email. Unsubscribe any time.

Need more?

Full policy pack, tailored to you

HR handbook, data handling, safety, AI-usage, and code of conduct — written for your industry, team size, and jurisdiction.

Starter Policy Pack$299Compliance Studio$79/mo

or tell us what you need →

Go further with Ruleset

Need the full policy pack — HR, data-handling, safety, code of conduct — tailored to you?

Ruleset drafts your full policy set — written for your industry, team size, and jurisdiction. No lawyers, no blank documents, no guesswork.

Starter Policy Pack — $299Compliance Studio — $79/mo

or start with a free intake form →