AI usage policy checklist

Before you publish an AI policy, check these nine things.

Use this checklist to spot missing rules before you ask the team to follow them.

  1. Scope: does it cover employees, contractors, personal devices and business accounts?
  2. Approved tools: have you named allowed tools and the process for approving new ones?
  3. Data: have you named credentials, confidential information and sensitive records as prohibited from public tools?
  4. Permitted uses: do staff know which everyday tasks are allowed?
  5. Human review: are customer-facing, legal, financial and employment outputs reviewed?
  6. Accuracy: does the policy require checking claims, citations, calculations and source material?
  7. Transparency: does it address disclosure where a client, platform or law requires it?
  8. Incidents: is there one person and one clear route for reporting a mistake?
  9. Training: is there a review date and simple onboarding for people who join later?
Pass condition: a staff member should be able to answer “can I use this tool, can I paste this information, and who checks this output?” without guessing.

Turn the checklist into a policy

The free generator turns these controls into a concise draft. It is a starting point, not a guarantee that your business meets every legal or contractual requirement.