Write an AI Acceptable Use Policy for Your Team in Under 30 Minutes

Your team is already using AI tools at work. Some of what they’re doing is fine. Some of it probably isn’t — not because they have bad intentions, but because nobody has told them where the lines are. An AI Acceptable Use Policy (AUP) fixes that. It takes the guesswork out of what’s appropriate, protects the business, and gives employees a clear framework to work within.

You don’t need lawyers, a lengthy compliance process, or a 20-page document. A one-to-two page policy, written clearly and shared with the team, is sufficient for most small businesses. Here’s how to write one in under 30 minutes, and what it needs to cover.

Why Your Business Needs One Now

Without a policy, every employee makes their own judgment calls about what’s appropriate. Those calls are often wrong — not maliciously, but because people don’t know what they don’t know. Common problems that a simple policy prevents:

Sensitive data being pasted into consumer AI tools. Customer PII, financial records, staff salaries, confidential client information — if employees don’t know this is off-limits for free-tier AI tools, some of them will do it. Not because they’re careless, but because the workflow is convenient and nobody told them not to.

AI-generated content published without review. Marketing copy, client proposals, social media posts generated by AI and published without a human checking for accuracy, tone, or hallucinated facts. The business owns the consequences of content published under its name regardless of how it was generated.

Confidential business strategy fed into shared AI sessions. Employees discussing unreleased product plans, M&A activity, or competitive strategy in AI tools that may log those conversations.

Copyright and IP issues. AI-generated content that incorporates training data in ways that create intellectual property exposure — particularly relevant for creative industries.

A policy doesn’t eliminate these risks entirely, but it establishes clear expectations and creates accountability.

The Five Things Your Policy Must Cover

1. Approved tools and plans

Specify which AI tools employees are authorised to use for work, and at what plan level. “ChatGPT free tier” and “ChatGPT Team” have meaningfully different data handling policies — your AUP should specify which is acceptable and under what circumstances. If you’ve standardised on Claude Team, say so. If personal accounts are not acceptable for work tasks, say that too.

2. What data must never go into AI tools

Be explicit. A general statement about “sensitive data” isn’t enough — people interpret “sensitive” differently. List the categories specifically:

  • Customer personally identifiable information (names, emails, phone numbers, addresses)
  • Financial data (bank details, payment information, salary information)
  • Health or medical information
  • Confidential client information shared under NDA
  • Unreleased product information, business strategy, M&A discussions
  • Login credentials, API keys, passwords

If there are tools where some of this data is acceptable (e.g. an enterprise AI tool with a signed DPA and zero data retention), note those exceptions explicitly.

3. Review requirements for AI-generated output

Specify that AI-generated content requires human review before use in any context that matters — client communications, published content, legal documents, financial analysis. The policy should be clear that the employee is responsible for the accuracy and appropriateness of anything they send or publish, regardless of whether AI was involved in producing it.

AI Acceptable Use Policy Template

[Company Name] — AI Tools Acceptable Use Policy
Effective date: [Date] | Review date: [Date + 12 months]

Approved tools: [List specific tools and plan tiers, e.g. “Claude Team, ChatGPT Team, GitHub Copilot Pro”]

Data restrictions: The following must never be entered into any AI tool, including approved tools unless a signed DPA is in place: customer PII, financial records, health data, credentials, confidential client information, unreleased business strategy.

Output review: All AI-generated content used in client communications, published materials, or business decisions must be reviewed and verified by a human before use. You are responsible for the accuracy of content you send or publish.

IP and copyright: Do not use AI tools to reproduce or closely paraphrase copyrighted material. Do not claim AI-generated content as entirely original work where disclosure is expected.

Reporting: If you believe you have accidentally shared restricted data with an AI tool, notify [designated contact] immediately.

Questions: Direct AI use questions to [designated contact or team].

4. IP and copyright expectations

Address whether employees should disclose AI use in their work, particularly in client deliverables. Some clients care, some don’t — but having a policy prevents inconsistency. Also note that employees shouldn’t use AI tools to reproduce copyrighted material or pass off AI-generated work as entirely their own in contexts where authenticity is expected (academic submissions, for example, or creative work sold as original).

5. What to do if something goes wrong

Include a short section on reporting. If an employee realises they’ve accidentally pasted restricted data into an AI tool, who do they tell? What happens next? A clear escalation path — without punitive language that discourages reporting — means incidents get caught and addressed rather than quietly ignored.

Tone Matters More Than Length

The most common mistake in writing an AI AUP is making it sound like a legal document nobody will read. Write it in plain language. Use short sentences. Avoid legalese. The goal is for every employee to understand it in five minutes, not to cover every conceivable edge case.

If your policy needs a lawyer to interpret it, it won’t be used. If it fits on one page and can be read in three minutes, people will actually follow it.

After You Write It: Making It Stick

A policy that sits in a shared drive unread is no better than no policy. Three things make AUPs actually influence behaviour:

A short team walkthrough. Not a lecture — a 15-minute conversation where you go through the key points, answer questions, and give people a chance to ask about grey areas. This is where most of the real learning happens, because people ask about their specific workflows.

Acknowledgement. Have employees sign or digitally confirm they’ve read it. This creates accountability and means you can reference it if something goes wrong later.

Regular updates. The AI tool landscape changes fast. Set a calendar reminder to review the policy every six months and update the approved tools list, data restrictions, and any new guidance that’s become relevant. A policy that was accurate when written but is now 18 months out of date creates more confusion than clarity.

When You Need More Than This

A simple internal AUP is sufficient for most small businesses. If you operate in a regulated industry — healthcare, finance, legal — you’ll want to layer in industry-specific requirements (HIPAA, FINRA, solicitor professional conduct rules) and may benefit from legal review. If you’re a larger business with significant client data or IP exposure, a more formal governance framework around AI use is worth the investment.

But for the majority of small businesses, 30 minutes spent writing a clear, plain-language policy and sharing it with your team is one of the highest-leverage things you can do to reduce AI-related risk this quarter.

Sample AI Use Categories to Include in Your Policy

One of the most useful additions to a plain-language AUP is a simple table of approved and prohibited use categories. This removes ambiguity faster than paragraphs of text and gives employees a quick reference they can actually use in the moment.

Generally approved uses: drafting and editing internal communications, summarising documents you’ve been provided, brainstorming ideas and generating options, writing marketing copy for human review, generating code for internal tools, analysing data from non-confidential sources, creating first drafts of training materials.

Requires manager approval: using AI in customer-facing communications sent without human review, generating legal or compliance documents, using AI to process any customer personal data, publishing AI-generated content under the company’s name without editorial review.

Prohibited: entering customer PII into any AI tool, sharing credentials or API keys, using personal free-tier accounts for business data, attempting to bypass AI tool safety features, representing AI-generated work as entirely human-created in contexts where authenticity is expected.

The One-Page Version That Gets Read

If you want a policy people actually refer to, the one-page version is more effective than a comprehensive document. Put the approved tools list, the prohibited data categories, and the review requirement on a single page. Link to a longer FAQ for edge cases. The goal is a document that fits on one screen and takes under three minutes to read — because that’s the version employees will check when they have a quick question, rather than searching a ten-page policy document for the relevant clause.

Pin it in your team’s Slack or Teams channel. Include it in new employee onboarding. Reference it when you run your quarterly AI tool audit. A policy that’s visible becomes a cultural anchor — the thing people point to when a colleague asks whether it’s okay to do a particular thing with AI. That’s the outcome worth designing for.

Leave a Comment