In March 2023, Samsung’s semiconductor division let engineers use ChatGPT to work faster. Within twenty days, employees had pasted proprietary source code into the chatbot twice and uploaded an internal meeting recording to generate minutes, and by May, Samsung had banned generative AI tools across the company. The engineers were debugging code and writing meeting notes with the best tool they could find; the company had approved the tool and written down nothing about the data. That gap is what an AI acceptable use policy template closes: written rules on which AI tools employees may use, what data may go into them, and who checks the output, in place while the stakes are still hypothetical.
An AI acceptable use policy is a company-wide document that sets the rules for how employees use AI at work: which tools are approved, what data may go into them, when a human must review the output, who owns what the AI produces, and what happens after a violation. The full eight-section policy on this page is drafted inline for in-house counsel and ready to copy, with the legal reasoning behind each section spelled out, from the privilege problem in consumer chatbots to the AI-literacy duty the EU AI Act put on the books. The cheap time to write an AI policy is before the incident.
One “AI Policy” Request, Three Different Documents
When the board asks for “an AI policy,” three different documents answer to that name, and they do different jobs:
AI acceptable use policy (company-wide). Governs how all employees use AI across the business, from the marketer drafting copy to the engineer generating code. This is the document this page covers and templates.
AI legal ethics policy (the legal team). Governs how lawyers meet their professional-responsibility duties when using AI, including verification of citations and confidentiality. We cover that separately in our AI legal ethics guide, which walks through ABA Formal Opinion 512 and the cases that set verification duties.
AI governance policy (the program level). Governs how the organization vets, approves, monitors, and audits AI systems, including model risk and regulatory frameworks like the EU AI Act. Our guide to AI regulation and governance maps that layer.
You may end up owning all three. Keep them separate documents; stapling them together produces something nobody reads. The acceptable use policy is the one your CEO wants every employee to follow, so it has to be short, concrete, and written in plain English.
Why the AI Acceptable Use Policy Lands on Legal’s Desk
Only 38% of organizations have a formal, comprehensive AI policy, up from 28% in 2025, per ISACA’s 2026 AI Pulse Poll of more than 3,400 digital trust professionals. The other 62% field enterprise procurement questionnaires, cyber-insurance renewals, and board questions with nothing to point to. Meanwhile the use arrived years ago: 78% of AI users bring their own AI tools to work, per the 2024 Microsoft and LinkedIn Work Trend Index of 31,000 workers, and Microsoft’s October 2025 UK research found 71% of employees using unapproved consumer AI tools on the job, half of them weekly.
Where those prompts travel afterward is its own problem; our guide to whether ChatGPT is private traces the path.
IT can pick the tools. The failure modes are legal ones: privilege waived in a consumer chat, confidential data in a training set, an employment decision nobody reviewed. Bjarne Tellmann, a former general counsel of Pearson and a guest on CZ and Friends, GC AI’s podcast hosted by CEO Cecilia Ziniti, framed the same shift from the GC’s seat:
“There’s a third engine that’s come on board now, and that is governance. We need to add value in an AI era by helping businesses to accelerate safely, putting guardrails in place: When are humans in the loop? What human is accountable?”
The acceptable use policy is the shortest possible answer to his two questions, signed by the CEO and read by everyone.
What the Law Already Requires
No federal statute yet orders every US company to adopt an AI use policy. The obligations arrive from the sides, and three are already on the calendar:
The EU AI Act’s AI-literacy duty is live. Article 4 has applied since February 2, 2025: organizations that deploy AI must ensure the people using it have “a sufficient level of AI literacy,” measured against their roles and context. National enforcement begins August 3, 2026. A written use policy plus a training program is the compliance artifact a regulator will ask to see.
States regulate AI in employment decisions. Illinois amended its Human Rights Act, effective January 1, 2026, to cover AI in employment decisions, New York City requires bias audits for automated hiring tools, and Colorado’s comprehensive AI framework, revised in 2026, phases in next. If anyone in your company screens resumes with AI, the human-review section of your policy is already doing legal work.
The frameworks buyers audit against expect one. The NIST AI Risk Management Framework puts written policy at the center of its GOVERN function: legal requirements documented, trustworthy-AI principles integrated into organizational policies, and an inventory of the AI systems in use. Expect to meet its vocabulary again the next time a security questionnaire asks about AI governance.
The duties in every one of these belong to the company and its lawyers; no template discharges them for you. What the template does is give the duties somewhere to live.
The Eight Sections Every AI Acceptable Use Policy Needs
A workable policy has eight parts, and they track the governance work the NIST framework above assigns to written policy. The copy-and-adapt template later on this page drafts all eight; here is what each one does, and the legal reason it earns its place.
Scope and definitions
Approved and prohibited tools
Confidential and personal data rules
Human review and verification
Intellectual property and ownership
Disclosure and labeling
Prohibited uses
Enforcement and reporting
Scope and Definitions
State who the policy covers, what counts as an “AI tool,” and how this document relates to the general IT acceptable use policy you already have: the IT policy governs systems access, and this one governs what happens when company information meets a generative model. Cover employees, contractors, and anyone acting on the company’s behalf. Define “AI tool” broadly enough to catch the chatbot, the AI features inside software the company already licenses, and the tool nobody has heard of yet; a definition that names only today’s products is stale by next quarter. This section exists because enforcement fails at the definition. An employee who used an AI feature the policy never mentioned has an argument, and HR knows it.
Approved and Prohibited Tools
This is the section employees read first, so make it a list. Sort tools into three tiers: approved for general use, approved for specific data classes only, and prohibited. Name the products. “ChatGPT Enterprise is approved for non-confidential work; the free consumer version is prohibited for any work data” is a rule an employee can follow at a glance.
The tier that carries the real risk is the one for confidential work. For legal, contract, and other sensitive workflows, name a platform that carries enterprise security terms in writing; GC AI publishes its full controls list on its security page. In practice, this tier is the difference between a lawyer pasting a vendor contract into a browser tab and dropping it into GC AI, where the chat runs under zero-data-retention terms wherever feasible, backed by SOC 2 Type II certification, and the output comes back with character-level citations the reviewer can check against the document. People will paste confidential text into something. The tier list decides whether that something has a contract behind it.
Confidential and Personal Data Rules
Tie this section to your existing data classification, and make the restricted list concrete. A three-row mapping covers it:
Data Class | Examples | AI Rule |
Public | Published marketing copy, public filings, open documentation | Any approved tool |
Confidential | Contracts, customer lists, personal data, internal financials | Tools with contractual data protections only |
Restricted | Source code, trade secrets, material nonpublic information, privileged material | No AI entry, or one named platform at the designated owner’s direction |
Samsung’s leak was source code, the crown jewels of a semiconductor business.
Molly Abraham, VP of Legal at Coinbase and a CZ and Friends guest, shared the underlying risk:
“A non-lawyer asking an LLM for legal advice, that LLM is not necessarily their lawyer. If something ingests your confidential information and can spit it out, even in a transformed state, that’s still your confidential information.”
The discovery risk is now measurable. In New York Times v. OpenAI (S.D.N.Y.), the newspaper’s copyright case over model training, a federal judge in January 2026 affirmed an order requiring OpenAI to hand plaintiffs a sample of 20 million ChatGPT conversation logs. What employees type into consumer chatbots can be preserved, produced, and read by strangers with subpoena power. Write the data rules for that world.
Human Review and Verification
Require a person to review AI output before it is relied on, sent externally, or used in any decision that affects an individual. Be specific about the high-stakes cases: anything going to a customer, anything in a legal or financial document, and anything touching hiring, credit, or a person’s rights, the same decisions Illinois and New York City already regulate. Write the division of labor down and it stays simple. The AI produces the draft, and a named person owns the decision.
Intellectual Property and Ownership
Address two ownership questions. First, work employees create with AI on company time and systems belongs to the company, the same as any other work product. Second, AI output may not be fully protectable and may carry third-party material, which is why human authorship and review matter for anything the company wants to own, publish, or enforce. Send people to the legal team before AI-generated material goes into anything customer-facing or filed.
Disclosure and Labeling
Set when AI involvement must be disclosed. Internally, label AI-generated drafts so reviewers know what they are checking. Externally, disclose where law, contract, or platform rules require it, and wherever silence would mislead a customer, a court, or a counterparty.
Varun Anand, co-founder of the sales platform Clay, announced the company’s version of that internal rule in August 2026. Engineer Sophie Alpert wrote the policy for the engineering team first, and other departments adopted it on their own until it covered the whole company. The policy allows brainstorming, drafting, and proofreading with AI, but draws one hard line: verbatim AI text can go out only if it is marked as AI’s own words.
“If a reviewer asks, ‘What did you mean by this line?’, it’s not acceptable to reply with ‘Oh sorry, AI wrote that, just ignore it.’”
Clay built that rule for internal memos and specs. The same two requirements fit an acceptable use policy directly: mark unedited AI output, and hold the author to every line a reviewer flags.
David Schellhase, a former general counsel of Salesforce and Slack argued for making this a default:
“I’d be an advocate of a really simple law: all content generated by AI must be labeled as such. A very big thing in the future is being able to tell the difference between what’s real and what’s not.”
Both examples make the same point: a labeling rule costs almost nothing to adopt, and it settles the trust question before a reviewer or a customer has to ask.
Prohibited Uses
List the bright lines: no confidential or personal data in non-approved tools, no final decisions about a person without human review, no presenting AI output as human-authored where the difference matters, nothing unlawful or discriminatory, and no end-runs around the approved-tools list. Employees follow a short list of bright lines. They skim a page of principles.
Enforcement and Reporting
Close with consequences and a reporting path. Violations may draw disciplinary action, and good-faith reports of mistakes will not. The engineer who pasted the source code should be in your office an hour later telling you about it, because your policy made that the obvious move. Name the owner and the review cadence; quarterly fits the current pace of tool churn.
The Privilege Clause Only a Lawyer Would Add
Conversations with a public AI chatbot are not protected by attorney-client privilege. In United States v. Heppner (S.D.N.Y. 2026), a criminal defendant used a consumer AI platform to draft his own defense-strategy memos after retaining counsel, and the court ordered the chats produced. The reasoning came in three parts:
The chatbot is not a lawyer. Communications with a non-attorney generally sit outside attorney-client privilege.
The chats were never confidential. The platform’s consumer terms allowed the exchanges to be used for model training and disclosed to third parties, and privilege dies on disclosure.
No lawyer directed the use. Self-directed AI research is different in kind from work an attorney directs an agent to perform.
The third point is the one your policy can act on. Courts have long extended privilege to non-lawyers working at counsel’s direction, accountants and translators under the Kovel line of cases, and the Heppner court signaled the same logic could reach AI used at a lawyer’s direction on a platform with contractual confidentiality. The policy line that follows is that legal-adjacent AI work happens inside platforms the legal team designates. Our Heppner ruling explainer covers the full holding, and the New York State Bar Association’s analysis is the sharpest outside read. This is the clause a lawyer adds because a lawyer knows what discovery does with loose prompts, and it is the difference between a policy that manages productivity and one that protects the company in litigation.
The AI Acceptable Use Policy Template (Copy This)
Here is the full policy, all eight sections. Copy it into your own document, swap the bracketed placeholders for your tool names and data classes, run it past your CISO and HR, and send it. It is drafted for in-house counsel to adapt before it goes out to employees.
Scope and Definitions: This policy applies to all employees, contractors, and anyone acting on behalf of [Company]. An “AI tool” means any software that generates text, code, images, audio, or decisions using machine learning, including standalone chatbots, AI features inside software [Company] already licenses, and tools adopted in the future.
Approved and Prohibited Tools: AI tools fall into three tiers. Approved for general use: [list, e.g., ChatGPT Enterprise]. Approved for confidential work only: [list tools carrying enterprise security terms, e.g., a legal AI platform for contract and legal workflows]. Prohibited: [list, e.g., free consumer chatbots for any work data]. Use a tool only within its tier. When in doubt, ask [owner].
Confidential and Personal Data Rules: Map every input to [Company]‘s data classification. Public data may go into approved AI tools. Confidential and personal data may go only into tools with contractual data protections. Restricted categories (source code, trade secrets, material nonpublic information, regulated personal data, and privileged material) may not be entered into any AI tool, or only into [named approved tool]. Work connected to legal advice or anticipated litigation happens only in tools [legal team] designates, at legal’s direction. If you are unsure how data is classified, treat it as confidential.
Human Review and Verification: A person must review AI output before it is relied on, sent outside [Company], or used in any decision affecting an individual. High-stakes outputs (customer-facing material, legal or financial documents, and anything affecting hiring, credit, or a person’s rights) require sign-off by a named reviewer. The AI produces the draft; a named person owns the decision.
Intellectual Property and Ownership: Work employees create with AI on [Company] time and systems belongs to [Company]. Because AI output may not be fully protectable and may include third-party material, anything [Company] intends to own, publish, or file must be reviewed and meaningfully authored by a person. Consult [legal team] before using AI-generated material in customer-facing or filed work.
Disclosure and Labeling: Label AI-generated drafts internally so reviewers know what they are checking. Disclose AI involvement externally where law, contract, or platform rules require it, and wherever not disclosing would mislead a customer, a court, or a counterparty.
Prohibited Uses: Do not enter confidential or personal data into non-approved tools. Do not use AI to make a final decision about a person without human review. Do not present AI output as human-authored where that distinction matters. Do not use AI to generate anything unlawful or discriminatory. Do not circumvent the approved-tools list.
Enforcement and Reporting: Violations may result in disciplinary action up to termination. If you make a mistake, report it to [owner] promptly; good-faith reports will not be penalized. [Owner] maintains this policy, reviews it [cadence, e.g., quarterly] as tools and law change, and runs the AI training [Company] provides under applicable AI-literacy requirements.
The two placeholders that decide whether this policy holds up are the tier list in Section 2 and the data-class map in Section 3. Fill both in with your CISO before anything circulates.
What Changes by Industry
The eight sections hold across industries; what changes is the data-class map and how much work the prohibited tier does. Four adaptations come up again and again:
Healthcare: Patient information regulated under HIPAA belongs in the restricted row, and business-associate terms decide which AI platforms can touch it at all.
Financial services: Communications-retention rules reach new channels fast. Treat AI chats about client business as records and fold them into the retention schedule.
Government contractors: Data residency, export-controlled technical data, and CUI handling rules can bar cloud AI tools outright, so the prohibited tier does more work here than anywhere else.
Public companies: Material nonpublic information already sits in the restricted row; add a Regulation FD reminder for anyone using AI to draft investor-facing material.
How to Roll It Out in 30 Days
A policy that goes unread protects nobody, and thirty days is enough to get from draft to adopted. Three moves, in order:
Week one: build the tier list with your CISO. The approved-tools section is the one employees act on and the one that decides where confidential data goes. Draft it first, with the person who owns the security review.
Weeks two and three: run the all-hands and name the safe harbor. A ten-minute explainer beats a long email, and the “use this instead” half of the message needs a sanctioned secure tool attached to be believable.
By day thirty: set the training, the review cadence, and the reporting channel. Training is the piece with a legal deadline behind it; the EU AI Act’s Article 4 literacy duty is enforced starting August 2026. GC AI’s free legal AI classes are California CLE-eligible and cover prompting, verification, and playbook workflows.
Ekumene Lysonge, Chief Legal Officer of NerdWallet and a CZ and Friends guest, described the scale problem the rollout has to solve:
“When anyone in the company can vibe code an idea within minutes, you have to also have a scaled governance model that supports the level of creativity that exists.”
The acceptable use policy is that governance model in its smallest workable form: one document, three tiers, one reporting channel.
Where GC AI Fits in Your Approved-Tools Tier
GC AI is an enterprise-grade legal AI platform built for in-house counsel, and it is the kind of named platform Section 2’s confidential tier exists for. It is SOC 2 Type II and SOC 3 certified, GDPR compliant, with zero data retention agreements with OpenAI and Anthropic, and AES-256 encryption. Deployed at the legal team’s direction under contractual confidentiality, it is also the arrangement the Heppner court pointed toward for keeping privilege intact.
2,000+ legal teams across 53 countries use GC AI (August 2026), including the legal departments at TIME, Liquid Death, Arc’teryx, Tipalti, Riot Games, SKIMS, and Snyk, plus 200+ public companies.
Exact Quote is the feature behind those character-level citations, and it is what the reviewer your policy’s Section 4 names uses to sign off line by line.
Our customer stories show what adoption looks like when the approved tier points somewhere lawyers want to work, and our guide to the best legal AI tools for in-house counsel compares the platforms in-house teams shortlist.
Write the Policy Before the First Incident
Samsung’s twenty days are the timeline to beat, and the drafting is already done: the template above is the policy. What remains is two decisions and one announcement, and none of it needs a second month. Point the confidential tier at a platform under contract, and circulate the policy while the stakes are still hypothetical.
Frequently Asked Questions
What Is an AI Acceptable Use Policy?
An AI acceptable use policy is a company-wide document that governs how every employee may use AI tools at work. It names approved and prohibited tools, sets rules for what data may go into AI, requires human review before output is relied on, assigns ownership of AI-generated work, and defines consequences for misuse. It applies across the whole organization, from marketing and engineering to HR and legal.
Is There a Free AI Acceptable Use Policy Template?
Yes. GC AI publishes this free AI acceptable use policy template: all eight sections in plain English, with the legal reasoning behind each clause and bracketed placeholders for your approved-tools tiers and data classes. Adapt the tool lists and disclosure rules to your industry before it goes live.
What Happens If a Company Does Not Have an AI Acceptable Use Policy?
Without a written policy, employees decide for themselves which AI tools to use and what to type into them, which is how confidential source code ended up inside ChatGPT at Samsung in 2023. It also leaves the company with nothing to show a regulator, court, cyber insurer, or enterprise customer who asks how AI use is controlled.
How Is an AI Acceptable Use Policy Different From a General Acceptable Use Policy?
A general acceptable use policy governs IT systems broadly: email, internet access, and company devices. An AI acceptable use policy is narrower and covers the risks specific to generative AI, including what data may go into a chatbot, which AI tools are approved or prohibited, and when AI output needs human review. Companies keep both, with the AI policy adding the rules the general policy predates.
How Often Should an AI Acceptable Use Policy Be Updated?
Review an AI acceptable use policy quarterly while AI tooling moves this fast, and on trigger events: a new enterprise AI purchase, a vendor changing its data terms, or a new law taking effect, like the EU AI Act obligations phasing in through 2027. Each review re-checks the approved-tools tiers against the tools employees are asking to use.
Can Employers Monitor How Employees Use AI at Work?
Yes, within limits. Employers can generally monitor AI use on company systems and networks, and several states require advance notice of workplace electronic monitoring, so route any monitoring plan through employment counsel. The stronger play is prevention: a policy that names approved tools and gives employees a no-blame channel to report mistakes surfaces problems earlier than surveillance does.
This guide and the template it includes are for general informational purposes and do not constitute legal advice. Laws and AI tools change fast; have counsel who knows your company, your data, and your jurisdictions review your adapted policy before it goes live.







