Adoption advisor

AI usage policy template

One page your team will actually read: which tools are approved, what may never be pasted in, who reviews output, and what happens when something goes wrong. Copy it, change the bracketed parts, and it is done.

Back to your adoption plan

Written to be adapted rather than adopted word for word. It is a starting point, not legal advice — have whoever owns risk in your organisation read it before you publish it.

1. Purpose and scope

This policy covers every use of generative AI tools for work, on any device, including personal accounts used for work tasks.

  • It applies to all employees, contractors and interns.
  • It covers text, image, audio, video and code generation, and any assistant built on top of them.
  • Where a client contract sets stricter rules, the contract wins.

2. Approved tools

Only tools on the approved list may be used with company information. Anything else needs a short review first.

  • The approved list names the tool, the plan we pay for, the owner and what it may be used for.
  • Requesting a new tool means naming the task it solves and the data it would see; the owner responds within five working days.
  • Free personal accounts may not be used for company work, because the data terms differ from our paid plans.
  • Browser extensions and unofficial clients that proxy our data through a third party are not approved.

3. What may never go into a tool

Treat every prompt as if it could be read by someone outside the company.

  • Never paste in: customer records or personal data, health or ID data, credentials, keys or tokens.
  • Never paste in: unreleased financials, salary or HR case detail, legal advice, or anything under NDA.
  • Never paste in: source code from repositories marked restricted, or third-party code we are not licensed to share.
  • Anonymise examples instead: replace real names, account numbers and addresses with placeholders.
  • Where a tool offers a setting to exclude your input from model training, it must be switched off and the decision recorded per tool.

4. Human review

AI drafts. People remain accountable for what leaves the company.

  • Anything that reaches a customer, a regulator, a contract or a public channel needs a named human reviewer before it goes out.
  • Facts, figures, quotes, citations and legal or medical statements must be checked against a primary source.
  • Generated code must pass the normal review and test process; no exceptions for speed.
  • Decisions about people — hiring, performance, discipline, credit or access — may not be made by a tool, only informed by one.

5. Transparency and attribution

Colleagues and customers should be able to tell where AI was involved.

  • Label AI-assisted drafts internally so reviewers know to check harder.
  • Disclose AI use to customers where they would reasonably expect a person, such as support conversations.
  • Do not present generated images or voices as real people, events or endorsements.
  • Respect third-party rights: do not prompt for a living artist's style or a competitor's protected material for published work.

6. Accounts, access and spend

AI tools are treated like any other business system.

  • Accounts use company email with single sign-on where the plan supports it, and are removed when someone leaves.
  • Seats are reviewed monthly; unused paid seats are cancelled.
  • API keys live in the company secret store, never in code, documents or chat messages.
  • Each approved tool has one named owner who answers questions and watches for pricing or terms changes.

7. When something goes wrong

Mistakes are expected. Hiding them is the problem.

  • Report a suspected data disclosure to the policy owner the same day; there is no penalty for reporting promptly.
  • Report material errors that reached a customer so the correction and the cause can be recorded.
  • The policy owner keeps a short log of incidents and what changed as a result.
  • Repeated deliberate breaches are handled under the normal disciplinary process.

8. Ownership and review

This policy is short on purpose so it can stay current.

  • Owner: [name, role]. Approved by: [name, role]. Version 1.0, dated [date].
  • Reviewed every quarter alongside the approved tool list and the spend review.
  • Every employee confirms they have read it at onboarding and after each material change.

AI policy questions, answered

Do we need an AI usage policy if only a few people use AI?

Yes, and that is the cheapest time to write one. A one-page policy set before the first rollout prevents the two common failures: company data pasted into personal accounts, and unchecked output reaching customers.

How long should an AI policy be?

One to two pages. Anything longer is not read, and unread rules are not followed. Keep the detail in the approved tool list, which changes more often than the policy itself.

Can employees use free versions of AI tools for work?

Most policies say no, because free plans usually have different data-retention and training terms than the paid plan you reviewed. Approve a paid plan for the work you want done, and the free-account problem largely disappears.

Who should own the policy?

One named person with authority to approve tools — often an operations, security or legal lead. Shared ownership between departments is the main reason requests for new tools go unanswered.

How often should it be reviewed?

Quarterly. Tool terms, prices and features change fast, so review the policy at the same time you review the approved tool list and the monthly spend.

Next steps