1. Purpose and scope
Explain why the policy exists and cover employees, contractors, personal devices and business accounts. Policy scope removes the “I thought this rule did not apply to me” problem.
2. Approved tools and permitted uses
List approved tools by name. Then state what they can be used for: drafting, summarising, translation, research or internal workflow support. Make approval for new tools simple and explicit.
3. Data rules
State exactly what staff must never paste into public tools: credentials, confidential business information, client records, payment data and regulated personal information. Avoid legal jargon; people follow rules they can recognise in the moment.
4. Human review and accountability
AI can prepare work, but a person must own final external outputs and decisions. Require review for customer-facing, employment, legal, financial or safety-related work.
5. The remaining sections
- Transparency and disclosure
- Copyright and source checking
- Incident reporting and escalation
- Training, review date and policy owner
Use the template as a starting point
A concise policy is more likely to be read and used. Generate a draft, replace placeholders, test it with the team and have it reviewed where your work is regulated or handles sensitive data.