An AI policy people can actually use.
An employee AI acceptable-use policy explains which tools and tasks are allowed, which information needs protection and where a person must check the result. It should answer the questions staff face at work.
Start with discovery, not a blank template
Ask staff which tools they use and what they do with them. Include personal accounts, AI features inside existing software and any connected systems. Identify the information involved and the consequences of an incorrect output. Those answers determine the policy you need.
Seven questions your policy should answer
- Which tools and accounts can I use? Name approved tools and the relevant account types or settings; explain how to request another.
- What information can I share? Define boundaries for customer, employee, commercially sensitive and other restricted information. An approved tool is not permission for every type of data.
- Which tasks need permission? Distinguish routine drafting from significant decisions, external commitments and automated actions.
- What must I check? Set verification expectations for facts, calculations, sources, code and claims before use.
- Who owns the result? Make clear who reviews, approves and remains accountable for consequential work.
- What if something goes wrong? Provide a reporting route and tell staff to preserve relevant information and seek help promptly.
- How do the rules change? Name the owner, review date and process for updates, exceptions and new starters.
Give people a usable route to yes
If a task is unsuitable for one tool, explain the approved alternative or the route to get advice. A blanket instruction to “be careful” leaves staff making inconsistent decisions. Pair boundaries with worked examples and practical training.
Test understanding, not just acknowledgement
Ask staff how they would handle a customer spreadsheet, an invented source or a request to connect a new tool. If their answers vary, the wording, training or process needs work. Ask the owner to walk through the same scenario and record any changes.
What this guide does—and does not—cover
This is an operational starting point, not a complete policy or legal advice. Specific data protection, employment, sector and contractual obligations require assessment for your circumstances. Technical controls and supplier checks need to support the written rules.
The policy sits within the broader six-check readiness framework. The Governance programme adapts that framework to your business.