AI Acceptable Use Policy Template: Copy All 8 Sections
Josh Bertini
In March 2023, Samsung’s semiconductor division let engineers use ChatGPT to work faster. Within twenty days, employees had pasted proprietary source code into the chatbot twice and uploaded an internal meeting recording to generate minutes, and by May, Samsung hadbanned generative AI tools across the company. The engineers were debugging code and writing meeting notes with the best tool they could find; the company had approved the tool and written down nothing about the data. That gap is what an AI acceptable use policy template closes: written rules on which AI tools employees may use, what data may go into them, and who checks the output, in place while the stakes are still hypothetical.
An AI acceptable use policy is a company-wide document that sets the rules for how employees use AI at work: which tools are approved, what data may go into them, when a human must review the output, who owns what the AI produces, and what happens after a violation. The full eight-section policy on this page is drafted inline for in-house counsel and ready to copy, with the legal reasoning behind each section spelled out, from the privilege problem in consumer chatbots to the AI-literacy duty the EU AI Act put on the books. The cheap time to write an AI policy is before the incident.
One “AI Policy” Request, Three Different Documents
When the board asks for “an AI policy,” three different documents answer to that name, and they do different jobs:
AI acceptable use policy (company-wide). Governs how all employees use AI across the business, from the marketer drafting copy to the engineer generating code. This is the document this page covers and templates.
AI legal ethics policy (the legal team). Governs how lawyers meet their professional-responsibility duties when using AI, including verification of citations and confidentiality. We cover that separately in ourAI legal ethicsguide, which walks throughABA Formal Opinion 512and the cases that set verification duties.
AI governance policy (the program level). Governs how the organization vets, approves, monitors, and audits AI systems, including model risk and regulatory frameworks like the EU AI Act. Our guide toAI regulation and governancemaps that layer.
You may end up owning all three. Keep them separate documents; stapling them together produces something nobody reads. The acceptable use policy is the one your CEO wants every employee to follow, so it has to be short, concrete, and written in plain English.
Why the AI Acceptable Use Policy Lands on Legal’s Desk
Only 38% of organizations have a formal, comprehensive AI policy, up from 28% in 2025, perISACA’s 2026 AI Pulse Pollof more than 3,400 digital trust professionals. The other 62% field enterprise procurement questionnaires, cyber-insurance renewals, and board questions with nothing to point to. Meanwhile the use arrived years ago: 78% of AI users bring their own AI tools to work, per the2024 Microsoft and LinkedIn Work Trend Indexof 31,000 workers, and Microsoft’s October 2025 UK research found71%of employees using unapproved consumer AI tools on the job, half of them weekly.
Where those prompts travel afterward is its own problem; our guide to whetherChatGPT is privatetraces the path.
IT can pick the tools. The failure modes are legal ones: privilege waived in a consumer chat, confidential data in a training set, an employment decision nobody reviewed.Bjarne Tellmann, a former general counsel of Pearson and a guest on CZ and Friends, GC AI’s podcast hosted by CEOCecilia Ziniti, framed the same shift from the GC’s seat:
“There’s a third engine that’s come on board now, and that isgovernance. We need to add value in an AI era by helping businesses to accelerate safely, putting guardrails in place: When are humans in the loop? What human is accountable?”
The acceptable use policy is the shortest possible answer to his two questions, signed by the CEO and read by everyone.
What the Law Already Requires
No federal statute yet orders every US company to adopt an AI use policy. The obligations arrive from the sides, and three are already on the calendar:
The EU AI Act’s AI-literacy duty is live.Article 4has applied since February 2, 2025: organizations that deploy AI must ensure the people using it have “a sufficient level of AI literacy,” measured against their roles and context. National enforcement begins August 3, 2026. A written use policy plus a training program is the compliance artifact a regulator will ask to see.
States regulate AI in employment decisions. Illinois amended its Human Rights Act, effective January 1, 2026, to coverAI in employment decisions, New York City requires bias audits for automated hiring tools, and Colorado’s comprehensive AI framework, revised in 2026, phases in next. If anyone in your company screens resumes with AI, the human-review section of your policy is already doing legal work.
The frameworks buyers audit against expect one. TheNIST AI Risk Management Frameworkputs written policy at the center of its GOVERN function: legal requirements documented, trustworthy-AI principles integrated into organizational policies, and an inventory of the AI systems in use. Expect to meet its vocabulary again the next time a security questionnaire asks about AI governance.
The duties in every one of these belong to the company and its lawyers; no template discharges them for you. What the template does is give the duties somewhere to live.
The Eight Sections Every AI Acceptable Use Policy Needs
A workable policy has eight parts, and they track the governance work the NIST framework above assigns to written policy. The copy-and-adapt template later on this page drafts all eight; here is what each one does, and the legal reason it earns its place.
Scope and definitions
Approved and prohibited tools
Confidential and personal data rules
Human review and verification
Intellectual property and ownership
Disclosure and labeling
Prohibited uses
Enforcement and reporting
Scope and Definitions
State who the policy covers, what counts as an “AI tool,” and how this document relates to the general IT acceptable use policy you already have: the IT policy governs systems access, and this one governs what happens when company information meets a generative model. Cover employees, contractors, and anyone acting on the company’s behalf. Define “AI tool” broadly enough to catch the chatbot, the AI features inside software the company already licenses, and the tool nobody has heard of yet; a definition that names only today’s products is stale by next quarter. This section exists because enforcement fails at the definition. An employee who used an AI feature the policy never mentioned has an argument, and HR knows it.
Approved and Prohibited Tools
This is the section employees read first, so make it a list. Sort tools into three tiers: approved for general use, approved for specific data classes only, and prohibited. Name the products. “ChatGPT Enterprise is approved for non-confidential work; the free consumer version is prohibited for any work data” is a rule an employee can follow at a glance.
The tier that carries the real risk is the one for confidential work. For legal, contract, and other sensitive workflows, name a platform that carries enterprise security terms in writing; GC AI publishes its full controls list on itssecurity page. In practice, this tier is the difference between a lawyer pasting a vendor contract into a browser tab and dropping it into GC AI, where the chat runs under zero-data-retention terms wherever feasible, backed by SOC 2 Type II certification, and the output comes back with character-level citations the reviewer can check against the document. People will paste confidential text into something. The tier list decides whether that something has a contract behind it.
Confidential and Personal Data Rules
Tie this section to your existing data classification, and make the restricted list concrete. A three-row mapping covers it:
| Data Class | Examples | AI Rule |
|---|---|---|
| Public | Published marketing copy, public filings, open documentation | Any approved tool |
| Confidential | Contracts, customer lists, personal data, internal financials | Tools with contractual data protections only |
| Restricted | Source code, trade secrets, material nonpublic information, privileged material | No AI entry, or one named platform at the designated owner’s direction |
Samsung’s leak was source code, the crown jewels of a semiconductor business.
Molly Abraham, VP of Legal at Coinbase and a CZ and Friends guest, shared the underlying risk:
“Anon-lawyerasking an LLM for legal advice, that LLM is not necessarily their lawyer. If something ingests yourconfidential informationand can spit it out, even in a transformed state, that’s still your confidential information.”
The discovery risk is now measurable. InNew York Times v. OpenAI(S.D.N.Y.), the newspaper’s copyright case over model training, a federal judge in January 2026 affirmed an order requiring OpenAI to hand plaintiffs a sample of20 million ChatGPT conversation logs. What employees type into consumer chatbots can be preserved, produced, and read by strangers withsubpoenapower. Write the data rules for that world.
Human Review and Verification
Require a person to review AI output before it is relied on, sent externally, or used in any decision that affects an individual. Be specific about the high-stakes cases: anything going to a customer, anything in a legal or financial document, and anything touching hiring, credit, or a person’s rights, the same decisions Illinois and New York City already regulate. Write the division of labor down and it stays simple. The AI produces the draft, and a named person owns the decision.
Intellectual Property and Ownership
Address two ownership questions. First, work employees create with AI on company time and systems belongs to the company, the same as any other work product. Second, AI output may not be fully protectable and may carry third-party material, which is why human authorship and review matter for anything the company wants to own, publish, or enforce. Send people to the legal team before AI-generated material goes into anything customer-facing or filed.
Disclosure and Labeling
Set when AI involvement must be disclosed. Internally, label AI-generated drafts so reviewers know what they are checking. Externally, disclose where law, contract, or platform rules require it, and wherever silence would mislead a customer, a court, or a counterparty.
Varun Anand, co-founder of the sales platformClay, announced the company’s version of that internal rule in August 2026. Engineer Sophie Alpert wrote the policy for the engineering team first, and other departments adopted it on their own until it covered the whole company. The policy allows brainstorming, drafting, and proofreading with AI, but draws one hard line: verbatim AI text can go out only if it is marked as AI’s own words.
“If a reviewer asks, ‘What did you mean by this line?’, it’s not acceptable to reply with ‘Oh sorry,AI wrote that, just ignore it.’”
Clay built that rule for internal memos and specs. The same two requirements fit an acceptable use policy directly: mark unedited AI output, and hold the author to every line a reviewer flags.
David Schellhase, a former general counsel of Salesforce and Slack argued for making this a default:
“I’d be an advocate of a really simple law: allcontent generated by AImust be labeled as such. A very big thing in the future is being able to tell the difference between what’s real and what’s not.”
Both examples make the same point: a labeling rule costs almost nothing to adopt, and it settles the trust question before a reviewer or a customer has to ask.
Prohibited Uses
List the bright lines: no confidential or personal data in non-approved tools, no final decisions about a person without human review, no presenting AI output as human-authored where the difference matters, nothing unlawful or discriminatory, and no end-runs around the approved-tools list. Employees follow a short list of bright lines. They skim a page of principles.
Enforcement and Reporting
Close with consequences and a reporting path. Violations may draw disciplinary action, and good-faith reports of mistakes will not. The engineer who pasted the source code should be in your office an hour later telling you about it, because your policy made that the obvious move. Name the owner and the review cadence; quarterly fits the current pace of tool churn.
The Privilege Clause Only a Lawyer Would Add
Conversations with a public AI chatbot are not protected by attorney-client privilege. InUnited States v. Heppner(S.D.N.Y. 2026), a criminal defendant used a consumer AI platform to draft his own defense-strategy memos after retaining counsel, and the court ordered the chats produced. The reasoning came in three parts:
The chatbot is not a lawyer. Communications with a non-attorney generally sit outside attorney-client privilege.
The chats were never confidential. The platform’s consumer terms allowed the exchanges to be used for model training and disclosed to third parties, and privilege dies on disclosure.
No lawyer directed the use. Self-directed AI research is different in kind from work an attorney directs an agent to perform.
The third point is the one your policy can act on. Courts have long extended privilege to non-lawyers working at counsel’s direction, accountants and translators under theKovelline of cases, and theHeppnercourt signaled the same logic could reach AI used at a lawyer’s direction on a platform with contractual confidentiality. The policy line that follows is that legal-adjacent AI work happens inside platforms the legal team designates. OurHeppner rulingexplainer covers the full holding, and theNew York State Bar Association’s analysisis the sharpest outside read. This is the clause a lawyer adds because a lawyer knows what discovery does with loose prompts, and it is the difference between a policy that manages productivity and one that protects the company in litigation.
The AI Acceptable Use Policy Template (Copy This)
Here is the full policy, all eight sections. Copy it into your own document, swap the bracketed placeholders for your tool names and data classes, run it past your CISO and HR, and send it. It is drafted for in-house counsel to adapt before it goes out to employees.
**Scope and Definitions:**This policy applies to all employees, contractors, and anyone acting on behalf of [Company]. An “AI tool” means any software that generates text, code, images, audio, or decisions using machine learning, including standalone chatbots, AI features inside software [Company] already licenses, and tools adopted in the future.
**Approved and Prohibited Tools:**AI tools fall into three tiers. Approved for general use: [list, e.g., ChatGPT Enterprise]. Approved for confidential work only: [list tools carrying enterprise security terms, e.g., a legal AI platform for contract and legal workflows]. Prohibited: [list, e.g., free consumer chatbots for any work data]. Use a tool only within its tier. When in doubt, ask [owner].
**Confidential and Personal Data Rules:**Map every input to [Company]‘s data classification. Public data may go into approved AI tools. Confidential and personal data may go only into tools with contractual data protections. Restricted categories (source code, trade secrets, material nonpublic information, regulated personal data, and privileged material) may not be entered into any AI tool, or only into [named approved tool]. Work connected to legal advice or anticipated litigation happens only in tools [legal team] designates, at legal’s direction. If you are unsure how data is classified, treat it as confidential.
**Human Review and Verification:**A person must review AI output before it is relied on, sent outside [Company], or used in any decision affecting an individual. High-stakes outputs (customer-facing material, legal or financial documents, and anything affecting hiring, credit, or a person’s rights) require sign-off by a named reviewer. The AI produces the draft; a named person owns the decision.
**Intellectual Property and Ownership:**Work employees create with AI on [Company] time and systems belongs to [Company]. Because AI output may not be fully protectable and may include third-party material, anything [Company] intends to own, publish, or file must be reviewed and meaningfully authored by a person. Consult [legal team] before using AI-generated material in customer-facing or filed work.
**Disclosure and Labeling:**Label AI-generated drafts internally so reviewers know what they are checking. Disclose AI involvement externally where law, contract, or platform rules require it, and wherever not disclosing would mislead a customer, a court, or a counterparty.
**Prohibited Uses:**Do not enter confidential or personal data into non-approved tools. Do not use AI to make a final decision about a person without human review. Do not present AI output as human-authored where that distinction matters. Do not use AI to generate anything unlawful or discriminatory. Do not circumvent the approved-tools list.
**Enforcement and Reporting:**Violations may result in disciplinary action up to termination. If you make a mistake, report it to [owner] promptly; good-faith reports will not be penalized. [Owner] maintains this policy, reviews it [cadence, e.g., quarterly] as tools and law change, and runs the AI training [Company] provides under applicable AI-literacy requirements.
The two placeholders that decide whether this policy holds up are the tier list in Section 2 and the data-class map in Section 3. Fill both in with your CISO before anything circulates.
What Changes by Industry
The eight sections hold across industries; what changes is the data-class map and how much work the prohibited tier does. Four adaptations come up again and again:
Healthcare: Patient information regulated under HIPAA belongs in the restricted row, and business-associate terms decide which AI platforms can touch it at all.
Financial services: Communications-retention rules reach new channels fast. Treat AI chats about client business as records and fold them into the retention schedule.
Government contractors: Data residency, export-controlled technical data, and CUI handling rules can bar cloud AI tools outright, so the prohibited tier does more work here than anywhere else.
Public companies: Material nonpublic information already sits in the restricted row; add a Regulation FD reminder for anyone using AI to draft investor-facing material.
How to Roll It Out in 30 Days
A policy that goes unread protects nobody, and thirty days is enough to get from draft to adopted. Three moves, in order:
Week one: build the tier list with your CISO. The approved-tools section is the one employees act on and the one that decides where confidential data goes. Draft it first, with the person who owns the security review.
Weeks two and three: run the all-hands and name the safe harbor. A ten-minute explainer beats a long email, and the “use this instead” half of the message needs a sanctioned secure tool attached to be believable.
By day thirty: set the training, the review cadence, and the reporting channel. Training is the piece with a legal deadline behind it; the EU AI Act’s Article 4 literacy duty is enforced starting August 2026. GC AI’sfree legal AI classesare California CLE-eligible and cover prompting, verification, and playbook workflows.
Ekumene Lysonge, Chief Legal Officer of NerdWallet and a CZ and Friends guest, described the scale problem the rollout has to solve:
“When anyone in the company can vibe code an idea within minutes, you have to also have a scaledgovernance modelthat supports the level of creativity that exists.”
The acceptable use policy is that governance model in its smallest workable form: one document, three tiers, one reporting channel.
Where GC AI Fits in Your Approved-Tools Tier
GC AI is an enterprise-grade legal AI platform built for in-house counsel, and it is the kind of named platform Section 2’s confidential tier exists for. It is SOC 2 Type II and SOC 3 certified, GDPR compliant, with zero data retention agreements with OpenAI and Anthropic, and AES-256 encryption. Deployed at the legal team’s direction under contractual confidentiality, it is also the arrangement theHeppnercourt pointed toward for keeping privilege intact.
2,100+ legal teams across 53 countries use GC AI (August 2026), including the legal departments at TIME,Liquid Death,Arc’teryx,Tipalti, Riot Games, SKIMS, andSnyk, plus 200+ public companies.
Exact Quoteis the feature behind those character-level citations, and it is what the reviewer your policy’s Section 4 names uses to sign off line by line.
Ourcustomer storiesshow what adoption looks like when the approved tier points somewhere lawyers want to work, and our guide to thebest legal AI tools for in-house counselcompares the platforms in-house teams shortlist.
Write the Policy Before the First Incident
Samsung’s twenty days are the timeline to beat, and the drafting is already done: the template above is the policy. What remains is two decisions and one announcement, and none of it needs a second month. Point the confidential tier at a platform under contract, and circulate the policy while the stakes are still hypothetical.
[
Start Your 14-Day Trial
](https://app.gc.ai/auth/sign-up?cta=inline-platform)






