AI-Usage Policy Template
Version 1.0 — Replace all [bracketed placeholders] with your company’s details before publishing.
This template is a professional starting point, not legal advice. Adapt it to your jurisdiction, industry, and risk profile. For a policy pack tailored to your company, see the upsell section below.
1
Approved AI Tools
Only AI tools explicitly approved by [Policy Owner / IT Lead] may be used for company work. Maintain an approved-tools list; review it quarterly. Using unapproved tools is a disciplinary matter.
| Tool | Approved Use | Restrictions |
|---|
| [e.g. ChatGPT / Claude] | Drafting, summarising, brainstorming | No confidential data; human review required |
| [e.g. GitHub Copilot] | Code assistance | Code review + automated tests before merge |
| [e.g. Grammarly] | Writing assistance | No PII in pasted text |
2
Data Handling — No Secrets or PII in Prompts
Never submit the following to any AI tool:
- Customer names, contact details, or account data (PII)
- API keys, passwords, tokens, or authentication credentials
- Unreleased product plans, pricing, or contract terms
- Health, financial, legal, or HR records of employees or customers
- Any data classified as Confidential or Restricted
Safe-prompt rule: Before submitting, ask "Could this prompt identify a specific person or piece of confidential business information?" If yes, remove or replace it with a generic placeholder before pasting.
Most AI providers use submitted content to improve their models unless you have an enterprise data-processing agreement. Even with such agreements, anonymise prompts as a default practice.
3
PII & Customer Data Rules
- Never paste customer emails, chat logs, or support tickets into a public AI tool, even to draft a response. Use anonymised summaries only.
- Do not use AI to build profiles of individual customers, employees, or named persons without explicit legal basis and DPO/legal sign-off.
- Automated decisions about individuals (credit scoring, HR decisions, content moderation affecting user accounts) require legal review before deployment under GDPR Art. 22 and equivalent laws.
- If a customer asks whether AI was used to process their data, you must be able to answer accurately — maintain a log of AI tool usage in sensitive workflows.
4
Human Review of AI Output
AI tools hallucinate facts, misstate law, and produce biased or incorrect output. All AI-generated content used externally, or for important internal decisions, must be reviewed and approved by a qualified person before use.
- Legal / compliance text — reviewed by a legal professional or qualified policy lead before publishing or sending.
- Financial advice or projections — reviewed by the relevant finance team member.
- Medical or health information — reviewed by a qualified healthcare professional.
- Customer-facing copy — must pass standard editorial review.
- AI-generated code — must pass code review and automated testing before merging to production.
Default rule: If AI helped write it, a human must own it before it goes out.
5
IP Ownership
- Work product created with AI assistance remains the property of [Company Name], provided a human employee directed and materially revised the output.
- Do not submit copyrighted material (books, articles, source code under restrictive licences) to an AI tool without confirming this is permitted under the relevant licence.
- AI-generated content may not be protected by copyright in all jurisdictions. Do not claim copyright on purely AI-generated outputs — document the human creative contribution.
- If you are unsure about IP ownership of a specific output, escalate to [Legal Contact] before use.
6
Disclosure to Customers
- AI-assisted customer communications — if AI generated a substantive portion of a customer-facing document or report, add a disclosure note where required by contract or applicable law.
- AI-generated marketing content — label images, copy, or video as AI-generated where required by platform policy or regulation (EU AI Act, FTC guidance, etc.).
- Automated AI interactions with customers (chatbots, automated response systems) must be disclosed as automated when asked and must not impersonate a human employee.
7
Prohibited Uses
The following uses are prohibited regardless of the tool:
- Generating content that is false, deceptive, or designed to mislead
- Creating deepfakes, synthetic voices, or fabricated identities of real people without explicit consent
- Using AI to bypass or circumvent security controls, access management, or audit processes
- Generating, distributing, or storing illegal content of any kind
- Using AI for decisions that must legally involve a human (formal disciplinary hearings, regulated financial or medical decisions)
- Engaging AI tools to contact, respond to, or make commitments to customers or third parties without human oversight and approval
- Using AI to automate tasks you are not personally authorised to perform
This template is provided as a starting point only and does not constitute legal advice. Consult qualified legal counsel before finalising any compliance policy. Template by Ruleset.
Download the Template
Get the editable .md file
Markdown format — open in any editor, paste into Notion, Confluence, or Google Docs. Free, no credit card required.