Skip to main content
51 days

Super Intelligence definition proposal due (60 days) · Nov 28, 2026 · See what changes

Templates

AI Acceptable Use Policy Template for Small Teams: 10-Section Copy-Paste

Free 10-section AI acceptable use policy template, copy-paste ready for teams of 5-50. Covers tools, data rules, incident reporting, sign-off.

10 min readBy Johnie T YoungUpdated todayLast reviewed
AI Acceptable Use Policy Template for Small Teams: 10-Section Copy-Paste

Image: Unsplash, used under the Unsplash License.

A complete AI acceptable use policy for teams of 5-50. Copy the sections below into your team wiki. Fill in the bracketed fields. Have every employee acknowledge it. That is all that is required to have a documented AI governance policy.

Use it as the policy document you point to in GDPR records of processing, SOC 2 reviews, and enterprise customer AI questionnaires. Most of the work is filling in the approved tools list and the data examples.

TL;DR: A complete AI acceptable use policy for small teams has ten sections, five of them required: approved AI tools list (what is allowed and under what conditions), prohibited uses, data classification rules (what data may and may not go into AI tools), incident reporting procedure, and employee acknowledgment. This template gives all ten sections in copy-paste form, plus a one-page employee summary and a filled-in example.


How to Use This Template

The policy has ten sections. Five are marked [REQUIRED]. Customize the bracketed fields. Sections marked [REQUIRED] must be completed before the policy is usable. Sections marked [OPTIONAL] can be kept, removed, or expanded based on your team's situation.

The version and date at the top of the document matter for audit purposes, every time you update the policy, increment the version number and update the date.


A hand ticking boxes on a handwritten checklist in a squared notebook, representing the sections of an AI acceptable use policy

Image: Unsplash, used under the Unsplash License.

THE POLICY (Copy Everything Below This Line)


AI Acceptable Use Policy

Company: [Company Name] Version: 1.0 Effective date: [Date] Policy owner: [AI Lead Name], [Title] Contact: [Email address for AI governance questions] Review cadence: Annual, or whenever a major AI vendor changes their data handling terms


1. Purpose

This policy establishes how [Company Name] employees may use artificial intelligence tools in their work. It defines which tools are approved, what uses are prohibited, and how to report incidents involving AI tools.

AI tools can accelerate work and improve quality. They also create risks, data exposure, inaccurate outputs, and regulatory non-compliance, when used without clear guidelines. This policy reduces those risks without eliminating the benefits.


2. Scope

This policy applies to all employees, contractors, and consultants of [Company Name] who use AI tools in connection with their work for the company, on company devices or personal devices.


3. Approved AI Tools [REQUIRED, customize this list]

The following AI tools are approved for use in the categories described. Use of any AI tool not on this list requires approval from [AI Lead Name] before use.

Tool Approved For Data Restrictions Notes
ChatGPT Business (company workspace) Drafting, summarizing, research No Class 4 data. Personal or free accounts are not approved for work data. OpenAI does not use ChatGPT Business content for training by default. Personal-account chats can be used for training while "Improve the model for everyone" is on.
Claude Team (company workspace) Drafting, analysis, coding No Class 4 data. Personal Free, Pro, and Max accounts are not approved for work data. Anthropic does not use commercial-plan inputs or outputs for training by default. Free, Pro, and Max users choose in Privacy Settings whether chats are used. Feedback (thumbs up or down) can be used for training on any plan.
GitHub Copilot Business or Enterprise Code completion, code review No code containing hardcoded secrets, credentials, or PII GitHub does not use Copilot Business or Enterprise data for training. Since April 24, 2026, GitHub may use Free, Pro, Pro+, and Max interactions for training unless the user opts out.
Grammarly Grammar, spelling, editing May be used with business documents. Avoid pasting full customer emails or PII-containing text.
[Add additional approved tools]

Tools requiring separate approval before use: Any AI tool not listed above. Contact [AI Lead Name] with the tool name, intended use case, and data that would be processed. Approval turnaround: 5 business days.


4. Prohibited Uses [REQUIRED]

The following uses of AI tools are prohibited regardless of which tool is used:

4.1 Data prohibitions

  • Inputting customer personal data (names, emails, addresses, payment information, health data, or any data subject to GDPR, CCPA, or HIPAA) into any AI tool that does not have a signed Data Processing Agreement (DPA) with [Company Name]
  • Inputting employee personal data into AI tools for HR, performance evaluation, or hiring decisions without explicit approval from [AI Lead Name] and legal counsel
  • Inputting code containing hardcoded credentials, API keys, passwords, or secrets into any AI tool
  • Inputting confidential business information (M&A plans, unreleased product details, financial projections) into consumer-tier AI tools with data retention

4.2 Output prohibitions

  • Publishing or sending AI-generated content to external parties (customers, regulators, courts) without human review and verification of accuracy
  • Using AI tools to generate professional advice (legal, medical, financial, accounting) for clients without expert human review and sign-off
  • Using AI tools to create content that impersonates a real person
  • Using AI tools to generate fake reviews, testimonials, or endorsements
  • Representing AI-generated content as human-authored when authenticity matters to the recipient

4.3 Decision prohibitions

  • Using AI tools to make final hiring decisions, performance ratings, or disciplinary decisions without documented human review
  • Using AI tools to make credit or financial decisions affecting customers without documented human oversight and an adverse action process

5. Data Classification Rules [REQUIRED, adjust categories for your data types]

Before using any AI tool with company data, classify the data:

Class 1, Public: Information that is or can be publicly disclosed. AI tools may process this data without restriction. Examples: Published blog posts, public product documentation, publicly available competitor analysis.

Class 2, Internal: Non-public business information. Approved AI tools may process this data. Do not use consumer-tier tools (free ChatGPT, etc.) unless they contractually do not retain or train on input data. Examples: Internal meeting notes, draft documents, engineering design docs not containing secrets, sales strategies.

Class 3, Confidential: Sensitive business information. Only AI tools with signed DPAs and zero-retention commitments may process this data. Requires [AI Lead] approval for each use case. Examples: Unreleased product roadmaps, M&A activity, financial data, vendor contracts, employee performance reviews.

Class 4, Restricted: Personal data subject to GDPR, CCPA, HIPAA, or similar laws; payment card data; credentials and secrets. AI tools may NOT process this data unless a DPA is in place AND legal counsel has reviewed the use case. Examples: Customer names and emails, employee records, health information, passwords and API keys, payment card numbers.

When in doubt: Treat the data as one class higher than you think it is.


6. Incident Reporting [REQUIRED]

An AI incident is any event in which:

  • Customer, employee, or other personal data was inputted into an AI tool without authorization or a signed DPA
  • An AI tool produced an output that was sent to a customer, regulator, or third party and contained material factual errors
  • An AI tool produced content that violates this policy and was published or shared externally
  • Credentials, API keys, or secrets were inputted into an AI tool

How to report:

  1. Stop the activity immediately
  2. Contact [AI Lead Name] at [email] within 24 hours of discovering the incident
  3. Do not delete the evidence, preserve the conversation, output, or log
  4. Complete the incident report form at [link to incident report form or doc]

What happens after you report: [AI Lead Name] will assess the incident within 48 hours. If personal data was exposed to a vendor without a DPA, the legal and compliance team will determine whether breach notification is required under GDPR (72-hour deadline to notify the supervisory authority), CCPA, or applicable state laws. You will not be penalized for good-faith reporting.


7. AI-Generated Content Disclosure [OPTIONAL, required if you publish AI-generated content externally]

[Company Name] may use AI tools to assist in creating content for external audiences. The following disclosure standards apply:

  • Marketing content: AI may be used to draft content; human review and editing is required before publication. AI-generated content does not require a disclosure label unless it is clearly AI-generated and presented as human-authored expert opinion.
  • Customer communications: AI may assist in drafting responses; a human must review and approve before sending. Automated AI responses to customer queries must disclose that a response was generated or reviewed by AI if the customer explicitly asks.
  • Legal or regulatory filings: AI may not generate final content for legal or regulatory filings without explicit attorney review and sign-off.
  • Amazon KDP and publishing platforms: Follow the platform's specific AI disclosure requirements. See KDP AI disclosure policy if applicable.

8. Employee Responsibilities

Every employee is responsible for:

  1. Reading this policy before using any AI tool for work purposes
  2. Following the data classification rules, when in doubt, ask [AI Lead Name] before proceeding
  3. Reporting incidents promptly using the procedure in Section 6
  4. Completing AI governance training as scheduled by [AI Lead Name]
  5. Not approving AI tools for team use without [AI Lead Name] authorization

9. Enforcement

Violations of this policy may result in disciplinary action up to and including termination of employment, depending on severity and intent. Unintentional violations that are promptly reported and handled in good faith will be treated as learning opportunities, not disciplinary matters.


10. Employee Acknowledgment [REQUIRED]

By signing below [or clicking the acknowledgment checkbox in [HR system]], I confirm that:

  1. I have read and understood the [Company Name] AI Acceptable Use Policy
  2. I understand which AI tools are approved and under what conditions
  3. I understand the data classification rules and which data types may not be processed by AI tools
  4. I understand how to report an AI incident
  5. I agree to comply with this policy

Name: ________________________________ Signature / Acknowledgment date: ________________________________ Department: ________________________________


END OF POLICY TEMPLATE


Customization Guide

Minimum required customizations:

  • Company name throughout
  • Approved tools list (Section 3), audit which tools your team actually uses
  • AI Lead name and contact email
  • Effective date
  • Incident report form link (can be a Google Form to start)
  • Data classification examples that match your actual data

Optional additions for regulated industries:

  • HIPAA: Add a Section 11 covering AI and PHI handling, BAA requirements for AI vendors
  • Financial services: Add automated decision disclosure obligations under ECOA and CFPB guidance
  • EU operations: Reference the EU AI Act high-risk classification and your conformity assessment status

Vendor data terms in the Section 3 table were re-checked on October 8, 2026 against OpenAI's, Anthropic's, and GitHub's own help pages. Personal plans for all three can use your inputs for training depending on a setting or choice, while the business plans listed do not by default. Re-verify before you publish, because these terms change.

A terminal prompt with the sudo command typed in green and white text on a black screen, representing the rule that credentials never go into AI tools

Image: Unsplash, used under the Unsplash License.

What to do if you have no AI lead yet: Assign one before publishing the policy. It can be a part-time role. The AI lead does not need to be a compliance specialist; a senior engineer or operations manager with a few hours a week can run it.


One-Page Version for Employees

Most people will not read ten sections. Give staff this one-page summary and keep the full policy as the reference document. Search terms vary, so call it whatever your team says: an AI usage policy, an employee AI policy, or a ChatGPT policy. The content is the same.

AI USE AT [COMPANY NAME]: 8 RULES

1. Use only the tools on the approved list. Need another tool? Ask [AI Lead] first.
2. Never paste customer or employee personal data into an AI tool unless the
   tool is approved for that data class.
3. Never paste passwords, API keys, or secrets into any AI tool.
4. On a free or personal account, assume anything you type can be used for
   training. Use the company workspace account instead.
5. A human checks every AI output before it reaches a customer, regulator,
   or court.
6. No AI-generated legal, medical, financial, or accounting advice goes to a
   client without expert sign-off.
7. Pasted something you should not have? Tell [AI Lead] within 24 hours.
   Good-faith reports are never penalized.
8. Sign the acknowledgment once a year.

For a longer employee-facing rule set with three risk tiers, see the ChatGPT usage policy for employees. To generate a first draft from a short questionnaire, use the AI acceptable use policy generator.


Worked Example: Sections 3 and 5 Filled In

The bracketed fields are where most teams stall. Here is how a fictional 15-person design agency, "Northwind Studio", might complete them. The company is illustrative. Adapt the choices, not the names.

Section 3, approved tools

Tool Approved for Data limits
ChatGPT Business (company workspace) Copy drafts, research, meeting summaries Classes 1 to 3 only
Claude Team (company workspace) Long-document review, analysis Classes 1 to 3 only
GitHub Copilot Business Code completion for the web team Class 1 and 2 code, no secrets
Grammarly Business Editing Classes 1 and 2 only

Section 5, data classes with agency examples

  • Class 1, Public: published case studies, the public portfolio site.
  • Class 2, Internal: draft brand guidelines, internal process docs, pitch outlines without client names.
  • Class 3, Confidential: signed client contracts, unreleased campaign work, pricing sheets.
  • Class 4, Restricted: client customer lists, payment details, employee records, any credentials.

Ownership and process

  • AI Lead: the operations manager, about 2 hours a week.
  • Approval turnaround for new tools: 5 business days.
  • Incident form: a shared form that alerts the AI Lead by email.
  • Rollout: 30-minute all-hands, acknowledgment collected through the HR onboarding checklist, personal AI accounts removed from the work tool list.

The choice that matters most is naming the company workspace, not just the vendor. That is what turns rule 4 in the one-page version into something a person can follow.

A woman smiling as she shakes hands with a man across a desk, representing an employee signing the policy acknowledgment

Image: Pexels, used under the Pexels License.

What small business owners say

In a January 2026 r/smallbusiness thread, "Concerns with employees using AI?", the owner who asked said "my main concern is people uploading something accidentally that they shouldn't." The top practical answer was blunt: "Train them on it." The same commenter added, "If they dont know the answer make a better training." Another, working in a regulated medical business, described the approach this template takes: "policy prohibits anything except MS Copilot."

Our take

Based on the vendor terms cited in the Section 3 table, the riskiest line in most AI policies is not a prohibited use. It is the gap between a company workspace and a personal account on the same product. OpenAI, Anthropic, and GitHub all keep business data out of training by default and all three let personal-plan data be used depending on a setting. A policy that names the workspace, blocks personal accounts for work data, and makes reporting a mistake painless will do more than a long list of prohibitions.

How we checked this

On October 8, 2026 we re-checked the vendor training terms in Section 3 against OpenAI's ChatGPT data controls page, Anthropic's Privacy Center, and GitHub's Copilot documentation, and the 72-hour breach notice rule against Article 33 of the GDPR on EUR-Lex. We corrected the Claude consumer description (it is a user choice, not an opt-out), added Copilot Max to the plans GitHub may train on, and fixed the summary that said the policy had five sections when it has ten. Time values in the template (24 hours to report, 48 hours to assess, 5 business days for approvals) are suggestions you should set yourself, not legal requirements.

Last reviewed: October 8, 2026.


Use the AI Governance Checklist to verify you have all six governance areas covered beyond just the policy document. For tracking which AI tools your team uses, the AI Tool Register Template gives you a Notion-ready database with the right fields.


Legal disclaimer

This article is published for informational and educational purposes only. It does not constitute legal, regulatory, or professional compliance advice and should not be relied upon as such. AI governance requirements vary by jurisdiction, industry, and organizational context. Always consult a qualified legal or compliance professional before implementing policies or making decisions with regulatory implications.

About the author

Johnie T Young

AI expert and governance practitioner helping small teams implement responsible AI policies. Specialises in regulatory compliance and practical frameworks that work without a dedicated compliance function.

  • AI governance practitioner
  • EU AI Act and GDPR specialist
  • AI risk management expert
  • Compliance frameworks for small teams