Business

How to Write an AI Acceptable Use Policy for Your Team

Your employees are already using AI, with or without rules. A short, clear policy protects your data and lets people use these tools with confidence.

Laptop on a work desk
Photo: Markus Spiske via Rawpixel (CC0)

Surveys consistently find that many employees use AI tools at work, and a significant share do so without telling their manager or using company-approved accounts. In Microsoft and LinkedIn’s 2024 survey of 31,000 people in 31 countries, 75% of knowledge workers said they used AI at work, and 78% of those users brought their own AI tools. Banning AI rarely works; it just pushes use out of sight. A clear acceptable use policy does better: it tells people what is allowed, protects sensitive information and removes the anxiety of guessing.

Updated September 2026: we added survey data on unofficial AI use at work and training, and an example of a local rule on AI in hiring.

Keep it short

The best policies fit on one or two pages. People read and remember short documents. You can link to detailed guidance for specific roles later.

What to include

1. Purpose

One or two sentences: the company supports responsible use of AI to improve work, and this policy explains how to do that safely.

2. Approved tools

List the AI tools employees may use for work, and which accounts, such as the company’s business plan rather than personal free accounts. Explain how to request a new tool.

3. Data rules

This is the most important section. Define clearly what may and may not be entered into AI tools:

Data typeApproved business toolsPersonal or unapproved tools
Public informationYesYes
Internal, non-sensitiveYesNo
Customer personal dataOnly where approvedNever
Confidential or regulated dataOnly where approvedNever
Passwords, keys, credentialsNeverNever

4. Human review

People are responsible for anything they produce with AI. Outputs must be checked for accuracy before being shared externally or used in decisions. See our guide to spotting AI hallucinations for why this matters.

5. Prohibited uses

For example: making final hiring, firing or credit decisions without human review; generating content that impersonates real people; uploading others’ work in breach of confidentiality or copyright.

6. Disclosure

State when AI use should be disclosed, for instance in client deliverables, published content or customer-facing chat, and how.

7. Legal and regulatory context

Note any regulations that apply, such as data protection law, local rules like New York City’s audit requirement for AI hiring tools, or, in Europe, the EU AI Act.

8. Who to ask

Name a person or team responsible for questions and updates.

One-paragraph version for your intranet Use approved AI tools with your work account. Never enter passwords, customer personal data or confidential information into unapproved tools. Check everything AI produces before you share or act on it; you are responsible for the result. Ask [contact] if you are unsure.

Roll it out properly

  • Explain the why, with examples of what can go wrong.
  • Provide training on the approved tools, including good prompting and verification. The same Microsoft survey found that fewer than 40% of workers had received AI training from their employer.
  • Make the approved path easy: if the sanctioned tool is harder to use than a personal account, people will drift.
  • Review it regularly, since AI tools and regulations change quickly.

Make safe use the default

An AI policy is not about restricting your team; it is about making safe use the easy default. Short rules, approved tools, clear data boundaries and human accountability cover most of what small and mid-sized organizations need. For a broader starting point, see our small business AI guide.

Sources

  1. Microsoft and LinkedIn release the 2024 Work Trend Index on the state of AI at work, Microsoft, May 2024
  2. Automated Employment Decision Tools, NYC Department of Consumer and Worker Protection

Token & Tell Staff

The Token & Tell editorial desk covers artificial intelligence for everyday users and professionals: the tools, the research and the policy questions behind them. Every piece is researched, edited and checked for accuracy before publication.

Read our editorial standards