AI acceptable-use policy template for SMEs
A practical policy that gives employees clear boundaries for using generative AI at work.
What is included
- Editable acceptable-use policy
- Roles and approval workflow
- Incident reporting checklist
- Quarterly review checklist
Complete preview
This preview can be used immediately. The editable DOCX adds fillable organization fields, approval tables, and a review record.
Purpose and scope
This policy applies to employees, contractors, temporary workers, and anyone using an AI system for company work. It covers public assistants, enterprise copilots, embedded AI features, automated agents, transcription tools, image generators, and internally developed systems.
Approved use
- Use only tools approved by the designated owner.
- Use AI to draft, summarize, translate, classify, brainstorm, or retrieve information when the employee remains accountable for the result.
- Follow the tool's approved data classification and retention rules.
- Keep a human decision-maker for legal, employment, safety, financial, medical, or other material decisions.
Prohibited use
- Do not paste credentials, secrets, unpublished financial data, special-category personal data, customer confidential information, or privileged material into an unapproved tool.
- Do not allow AI to make final hiring, dismissal, promotion, credit, health, safety, or disciplinary decisions.
- Do not present generated content as verified fact without checking it.
- Do not bypass access controls, licensing restrictions, security review, or procurement.
Confidential and personal data
Before entering information into AI, identify its owner and classification. Minimize personal data, remove unnecessary identifiers, and use approved enterprise settings. If the task cannot be completed without restricted data, stop and ask the policy owner or data-protection contact.
Human review and evidence
The person using AI remains responsible for accuracy, completeness, bias, tone, permissions, citations, and downstream impact. Material outputs must be checked against authoritative sources and the review should be recorded when the decision has legal, financial, employment, safety, or customer consequences.
Intellectual property
Use only inputs the organization is entitled to process. Review output for copied material, protected brands, confidential information, and licensing obligations before external use. Record the human contribution when ownership matters.
Incidents
Immediately report accidental disclosure, suspicious output, prompt injection, unauthorized access, discriminatory recommendations, unsafe instructions, or repeated factual failures. Preserve the prompt, output, tool, date, affected data, and actions taken without circulating the incident further.
Training, ownership, and review
The policy owner maintains the approved-tool register and coordinates security, privacy, HR, legal, and employee training. Staff receive role-appropriate AI literacy before using approved systems. Review this policy at least quarterly and whenever a new tool, material use case, incident, or legal requirement appears.
Minimum adoption checklist
- Name the policy owner and escalation contacts.
- Inventory the AI tools already in use.
- Classify allowed data for each tool.
- Define decisions that always require human approval.
- Train staff and record completion.
- Run an incident exercise and schedule the next review.