AI policy template

A usable AI policy answers eight questions.

This template is for a team that needs practical guardrails, not a vague “use AI responsibly” statement.

Short answer: an AI policy should name who it covers, which tools are allowed, what data is prohibited, when human review is required and who owns incidents and updates.

1. Purpose and scope

Explain why the policy exists and cover employees, contractors, personal devices and business accounts. Policy scope removes the “I thought this rule did not apply to me” problem.

2. Approved tools and permitted uses

List approved tools by name. Then state what they can be used for: drafting, summarising, translation, research or internal workflow support. Make approval for new tools simple and explicit.

3. Data rules

State exactly what staff must never paste into public tools: credentials, confidential business information, client records, payment data and regulated personal information. Avoid legal jargon; people follow rules they can recognise in the moment.

4. Human review and accountability

AI can prepare work, but a person must own final external outputs and decisions. Require review for customer-facing, employment, legal, financial or safety-related work.

5. The remaining sections

  1. Transparency and disclosure
  2. Copyright and source checking
  3. Incident reporting and escalation
  4. Training, review date and policy owner

Use the template as a starting point

A concise policy is more likely to be read and used. Generate a draft, replace placeholders, test it with the team and have it reviewed where your work is regulated or handles sensitive data.

Sources