AI Acceptable Use & Governance Policy Template

Customize this template for your organization. Click below to print or save as PDF.

← Back to AI Readiness

AI Acceptable Use &
Governance Policy

Template for [Your Organization Name]

Provided by
TotalCare IT

1. Purpose & Scope

This policy establishes guidelines for the acceptable and responsible use of Artificial Intelligence (AI) tools and services within [Your Organization].

Purpose

Scope

This policy applies to:

2. Approved AI Tools

The following AI tools have been approved for business use after security and compliance review:

Tool Version Approved Use Cases Status
Microsoft 365 Copilot Enterprise Productivity, document creation ✓ Approved
[Add your tools]
⚠️ Prohibited: Using unapproved AI tools with company data is strictly forbidden. Request approval from IT department before using new AI tools.

3. Acceptable Use Guidelines

✅ ALLOWED Uses

General Productivity

Research & Learning

Creative Work

❌ PROHIBITED Uses

Never Input Into AI Tools:
  • Customer personal information (PII, PHI, financial data)
  • Proprietary company information (trade secrets, financials, strategic plans)
  • Confidential employee information
  • Intellectual property (source code, patents, designs)
  • Login credentials, API keys, or passwords
  • Contract terms or pricing information
  • Legal documents or attorney-client privileged information
  • Information marked as "Confidential" or "Internal Only"

Never Use AI For:

4. Data Classification

Level Description AI Usage
Public Information intended for public disclosure ✓ Allowed
Internal Non-sensitive business information ⚠️ Approved tools only
Confidential Sensitive business or customer data ✗ Prohibited
Restricted Highly sensitive (PII, PHI, trade secrets) ✗ Strictly Prohibited
Before Using AI Tools, Ask:
  1. Is this information public knowledge?
  2. Would disclosure harm the company or our customers?
  3. Am I legally allowed to share this information?
  4. Is this covered by an NDA or confidentiality agreement?

When in doubt, don't input it. Ask your manager or IT department.

5. Security Requirements

Account Security

Data Protection

Incident Reporting

Report these incidents immediately to IT Security:

Reporting Contact: [security@yourcompany.com] or [IT Help Desk]

6. Compliance & Industry Requirements

Healthcare (HIPAA)

Financial Services (GLBA, SOX)

Government Contractors (ITAR, DFARS)

[Add your industry-specific requirements here]

7. Monitoring & Enforcement

Monitoring

The company reserves the right to:

Violations & Consequences

Offense Consequence
First Offense Written warning and mandatory retraining
Second Offense Loss of AI tool access and performance review
Serious Violations Suspension or termination of employment
Legal Violations Civil or criminal prosecution

8. Employee Acknowledgment

I acknowledge that I have read, understood, and agree to comply with this AI Acceptable Use & Governance Policy. I understand that violations may result in disciplinary action up to and including termination of employment.

Employee Name (Print):
Employee Signature:
Date:

Quick Reference Guide

AI Tool Usage Quick Reference
🚫 NEVER put these in AI tools:
  • Customer data (names, emails, addresses)
  • Financial information (credit cards, SSNs, bank accounts)
  • Trade secrets or proprietary information
  • Passwords, API keys, or credentials
  • Confidential contracts or legal documents
✅ ALWAYS:
  • Use approved AI tools only
  • Verify AI outputs before using
  • Report security incidents immediately
  • Complete required AI training
  • Ask IT if unsure
IT Security Contact: [security@yourcompany.com] | [Phone]