Generative AI Acceptable Use Policy: A Template for Your Company
Updated · EraseAI
A good AI policy fits on one page and answers three questions: which tools can I use, what must I never put into them, and who do I ask? Use the template below as a starting point, adapt it to your organization and have it reviewed by your legal or compliance team.
1. Purpose and scope
This policy explains how employees, contractors and anyone working on behalf of [Company] may use generative AI tools, including chat assistants, writing and coding assistants, transcription tools, image generators and AI features inside other software, on any device used for work.
2. Approved tools
- Use only the AI tools listed on [intranet link], signed in with your work account.
- Don't use personal AI accounts for work.
- Ask [team/email] before installing AI browser extensions, apps or connecting AI tools to company email, drives or systems.
3. Data you must never enter into any AI tool
- Passwords, API keys, tokens, private keys or other credentials.
- Payment card numbers, bank account details and government ID numbers.
- Health information and other special category personal data.
- Customer, patient or employee personal data, unless the tool is approved for that data and identifiers are removed first.
- Information marked Confidential or Restricted, unreleased financial results, and source code from [repositories], unless the tool is approved for it.
4. Using AI output
- You are responsible for anything you publish, send or ship, whether or not AI helped.
- Check facts, figures, citations and code before use.
- Say when AI produced substantial parts of client-facing work if a client or regulator requires it.
- Don't use AI to make final decisions about people (hiring, credit, discipline) without human review.
5. Safeguards
- Company browsers and phones run an AI firewall that checks messages and files before they are sent to AI tools and may redact or block sensitive data.
- Report any accidental sharing of restricted data to [security contact] within [24 hours]. Reporting quickly is what matters; honest mistakes are not punished.
6. Review
[Owner] reviews this policy every six months and when tools or regulations change. Questions go to [contact].
Making the policy stick
Policies fail when they rely on memory. Pair this one with a check at the point of use: EraseAI's browser extension and Android app catch the data listed in section 3 in any AI tool, and IT can roll them out across the organization through Chrome policy or Android managed configuration. See AI data loss prevention for the full rollout.
Check every message before it reaches AI
EraseAI stops API keys, passwords, card numbers and personal data in ChatGPT, Claude and Gemini. Free in Chrome, no account needed.
Frequently asked questions
Do small companies need an AI policy?
Yes, and it can be short. A one-page policy that names approved tools and forbidden data prevents most incidents and is often asked for by enterprise customers and insurers.
Should we ban AI tools instead?
Bans tend to push AI use onto personal devices. Approving tools, setting data rules and checking what is sent usually reduces risk more.